Sendant
Private messenger with nothing to hand over.

Private messenger with no phone number, no email, no account — and no app to install.

Updated 11 July 2026

Sendant is an end-to-end encrypted messenger where identity is a cryptographic key, not a SIM card. Your keys stay on your device, the browser uses the same crypto through WebAssembly, and encrypted mailbox delivery helps conversations continue when networks are intermittent.

Free.No accountNo phone numberNo emailNo ads

X3DH + Double Ratchet WASM crypto path device-held keys no tracking SDKs

On iPhone or desktop? Use Sendant right in your browser — no install.·Compare private messengers·On a de-Googled phone? Get the direct APK·How it works ↓

Why Sendant

Four distinct reasons Sendant is different.

Not just “encrypted.” Sendant separates access, key custody, identity, and verification so you can see exactly what protects you.

Real private chat in a browser tabAccess

Open Sendant on desktop or iPhone without installing an app, creating an account, or linking a phone number. The web client still uses the same end-to-end encryption path, compiled to WebAssembly instead of watered down for convenience.

Keys stay on your device

Encryption starts before delivery. Message keys are generated and stored locally, so Sendant infrastructure forwards sealed envelopes instead of holding the power to read conversations. Servers see opaque ciphertext, not message text.

Your identity is a key, not your SIM

You start private: your account is a cryptographic identity on your device, not a phone-number profile. That means less personal data at signup, less account surface to expose, and a cleaner trust boundary from the first conversation.

Security states you can audit

Security should be visible, not vibes. Sendant uses plain labels like “Verified,” “End-to-end encrypted,” “New device added,” and “Safety number changed,” then lets you verify contacts with a QR code or safety number.

How it's built

A simple trust model you can understand at a glance.

Your device does the sensitive work. Sendant's infrastructure moves sealed envelopes and can be useful without being trusted with message contents.

Sendant rudimentary architecture diagram Sender device holds keys locally, sends an encrypted envelope through an untrusted relay or mailbox, and the recipient device decrypts locally. Safety numbers and QR codes let both people verify who is on the other end. Sender device Keys never leave Message is encrypted locally before it touches the network. Untrusted infrastructure Relay / mailbox Forwards or stores sealed ciphertext envelopes. Useful for delivery. Not trusted for content. Recipient device Decrypts locally Only the intended device can open the conversation. Sealed envelope Ciphertext only Verify, don't just trust Safety numbers and QR codes let people confirm who is on the other end.
Private keys stay local Servers move ciphertext Offline delivery uses sealed mailboxes People can verify contacts

Built for

People who need their conversations to stay theirs.

Everyday privacyPeople who want a mainstream-easy messenger without centralized trust in their message history.
Journalists & NGOsCivil-society teams who need confidential coordination and resilience to account takedowns.
Communities & operatorsPeople who can run relay and storage nodes to strengthen the network for everyone.

Trust model

Claims you can check today.

Privacy claims are only worth what you can check. Sendant is built around standard, well-studied cryptography, explicit trust states, and a server model designed to move encrypted data without owning your conversations.

One crypto, everywhere

The same X3DH + Double Ratchet runs in the app, the browser (compiled to WebAssembly), and the CLI — one implementation, no second version to drift. Try the web client →

No ads, no analytics by default

We don't sell ads, targeting, or behavioral data. The product is built without a tracking SDK quietly profiling how you use the app.

Local-first

Your message history lives on your device and is removed when you clear data or uninstall. Your private keys are held in the platform's secure store.

Questions

Straight answers.

Does Sendant need a phone number?
No. Sendant creates a private identity on your device — no phone number, email, or account required. For services outside Sendant that still ask for email, Emcognito lets you use a private alias instead of your primary inbox.
Is Sendant end-to-end encrypted?
Yes, by default. Only you and the people you're messaging can read your messages; Sendant's servers only handle encrypted ciphertext.
Is Sendant free?
Yes. Sendant is free on Android, with no ads.
Can I use Sendant without installing an app?
Yes. Open app.sendant.io in any modern browser to message from your computer or iPhone — no install required. The same end-to-end encryption runs locally in your browser via WebAssembly, and your keys stay on your device. See how that compares to every other no-install option: encrypted messaging without installing an app.
How is Sendant different from Signal?
Signal is excellent but requires a phone number, and it has no web app — the desktop app must be installed and linked to a phone. Sendant needs no phone number and runs in any browser with nothing to install. Today Sendant delivers through an encrypted store-and-forward mailbox; direct peer-to-peer paths are on the roadmap. Full breakdown: Sendant vs Signal and the no-phone-number comparison.
What happens if my contact is offline?
Your message is encrypted and waits in a store-and-forward mailbox, then delivers when their device next connects — so you don't both have to be online at once. Direct peer-to-peer and relay delivery paths are on the roadmap.
Can I install Sendant without Google Play?
Yes. For de-Googled phones, GrapheneOS, or anyone without the Play Store, we publish a direct Android APK you can install and verify yourself — check the signing-certificate fingerprint and SHA-256 hash before you trust it. Two honest caveats: it's a separate app with its own identity (it installs alongside the Play version rather than updating it, so pick one build per device), and it still uses Firebase Cloud Messaging for push, so a fully de-Googled device may need the app open to get messages promptly.

Technology-led privacy. Calm in practice.

Start a conversation with device-held keys, no phone-number identity, and no tracking-driven business model.