Every feature in Phantom Chat was engineered with a single question: what would a privacy absolutist demand?
Among the few messengers that combine the Signal Protocol with NIST's post-quantum algorithm (ML-KEM-768, the FIPS 203 standard). Every conversation is encrypted with both classical and post-quantum keys at once — if either holds in 20 years, your messages stay safe. WhatsApp doesn't have post-quantum encryption; Signal added it in 2024 and Apple added PQ3 to iMessage the same year.
Every message is encrypted on your device before transmission using the Signal Protocol's Double Ratchet — the same forward-secrecy standard used by Signal, WhatsApp, and Google Messages. Only the recipient's device holds the keys to decrypt. We can't see your messages. Our servers can't see your messages. No one in transit can see your messages.
Your long-term identity key is generated inside the iPhone's Secure Enclave — a tamper-resistant chip isolated from iOS itself. The private key cannot be extracted, even by malware or jailbreaks.
If you still have your phone and it's at risk of being seized or compromised, you can instantly delete your account and all data. The Lock Screen widget trigger is free for everyone; two more triggers — a shake gesture and a separate reset PIN — are part of the Personal plan. All resets use a secure multi-pass overwrite so deleted data cannot be recovered. Note: these triggers require physical access to your device — there is no remote wipe from a different phone, by design.
No phone number, no email, no real name. Sign up with just a username (plus acceptance of the Terms and Privacy Policy). There's no public directory and no username search — the only way to connect is an invite code or QR. The account isn't tied to your SIM, your carrier, or any leaked identity database.
Choose from 76+ custom app icons, set themes, and make Phantom Chat feel like yours. Contacts are added through expiring invitation codes (single-use up to 500 joins; duration from 1 day to never — your choice).
Open standards, hardware trust, and quantum-resistant cryptography — layered so that breaking one layer still leaves your messages protected by everything else.
Crypto core tests passingSignal Protocol Double Ratchet, NIST FIPS 203 ML-KEM-768, and FIPS 202 SHA-3 — all peer-reviewed, industry-standard cryptographic building blocks. Our own implementation of them hasn't yet had an independent third-party audit; that's a funded item on our roadmap.
Encryption keys are generated on your device and never leave it. Your identity key lives inside Apple's Secure Enclave hardware — physically isolated from iOS and inaccessible to any software.
Compare security fingerprints with each contact in person or over a separate channel. Phantom Chat surfaces key changes automatically so you can re-verify whenever needed.
Our servers route and store encrypted message blobs we cannot read. They hold only what's needed to run the service — your username, an opaque push token, and subscription status. We can't read your messages. Encrypted blobs are removed when a disappearing-message timer expires or when you delete your account. Push notifications carry zero message content.
Phantom Chat is funded entirely by subscribers and Founders. No VC. No data harvesting. No ads. The numbers below are what it costs to keep the servers running and the promises kept.
All prices in US dollars. Apple converts to your local currency at the App Store checkout — Australian customers see GST-inclusive AUD totals at the point of purchase. The amount you're billed in AUD may vary with prevailing exchange rates.
Pay once. Use Phantom Chat forever. We're capping Founders at 500 seats because that's how much runway it gives us to refuse VC money. After that, Founder closes for good.
Subscription revenue funds the running and improvement of Phantom Chat — directly, not by way of a marketing or advertising department. No executives cashing out. No shareholders to satisfy. Just the work that keeps the service running and your messages private.
Revenue funds our managed server infrastructure: encrypted-at-rest storage, hardened access controls, and the end-to-end encryption that means even with full server access, we cannot decrypt the messages we route.
We don't invent crypto and we don't ask you to trust us with secret algorithms. Your subscription pays the engineering work to integrate peer-reviewed standards correctly — the Signal Protocol, NIST FIPS 203 ML-KEM-768, AES-256-GCM, and Apple's Secure Enclave.
As revenue grows, your subscription will fund the next priorities: independent third-party security audits, formal cryptographic review, and an Android client. These are roadmap items today, not delivered features — we'll publish progress as each one ships.
You evaluate messengers on what they actually do. Phantom Chat uses ML-KEM-768 for post-quantum key exchange, FIPS 202 SHA-3, and per-device keys that never leave the device — auditable, not aspirational.
Journalists, organisers, researchers, lawyers. When the person on the other end of a chat could be compromised by their phone number being known, "no phone number required" stops being a feature and starts being the point.
Dating apps, side projects, marketplace listings, anyone you're not ready to give your real number to yet. Talk like a normal person without handing over the keys to your real identity.
Family, friends, group chats. You don't need a threat model to deserve a messenger that isn't quietly profiling you in the background.
I'm not a tech founder. My background is in mining — I came to this from the other side, as a user who got tired of every messaging app I trusted turning out to be a quiet data broker.
Phantom Chat started as a proof of concept. I wanted to see whether one person, working seriously, could build a messenger that was actually private — not "private when convenient" or "private until the next policy update," but cryptographically private in a way the developer themselves couldn't undo. The answer turned out to be yes.
Veilus Digital, the company behind Phantom Chat, is registered in Western Australia. It's not VC-backed, it's not for sale, and there are no investors waiting for the day we monetise your behaviour. Subscription revenue funds the service directly — server costs, engineering, future audits — and nothing else. Selling your data isn't a temptation we're resisting; it's a business model we structurally don't have access to.
The product is built around a single commitment that won't change: your messages, your contacts, and your activity are not the product. We can't read what you send. We don't profile what we can see. We don't sell, share, or rent any of it.
The goal is simple: to build one of the most private messengers you can install, by someone who isn't being paid to look the other way. Privacy isn't a feature here. It's the entire reason this exists, and it's the one thing that will never change.
If we ever stop being the kind of company that can say all of that honestly, this page will say something different — and the warrant canary in our Privacy Policy will be the first place you find out.
Download Phantom Chat and send your first encrypted, self-destructing message in under a minute. No setup complexity. Just security, by default.