Arveil

Open source · End-to-end encrypted

A messenger for the people you trust, on a server you run.

Arveil is a private messenger for families and small circles. One person runs a small relay at home or on a server they rent; everyone else only needs the app and an invitation. The relay carries sealed envelopes. It never reads what you write.

Experimental. Arveil works, but it has not had an independent security review yet. Use it with test profiles for now, and read the threat model before trusting it with anything that matters.

Arveil on a phone: the chat list, with two verified contacts and a group conversation.

How it works

Three steps, and only one of them is technical.

There is no Arveil company server to sign up to. Each circle has its own relay, called a realm, and whoever runs it decides who may join. KaiCorp Labs does not run a public realm.

Someone runs a relay

A single program with its own small database. It runs on a Raspberry Pi, a home server or a small rented server, reachable over your home network, a private network or a public address.

They invite you

You receive the server details and a one-time invitation. The invitation works once and is not stored in the app.

You install the app

Paste both, and your identity is created on your device. Then you chat, share files and add your other devices. Step-by-step guide.

What the relay sees

Your messages stay yours, and the limits are written down.

Every conversation, even between two people, is an encrypted MLS group. The server stores opaque mailboxes and envelopes. It has no table of conversations to look at.

What it cannot see

  • What you write, and the files you send
  • File names and file types
  • Group names, titles and who is in each group
  • Your private keys and recovery secrets

What it can see

  • Who is registered, and their devices
  • IP addresses, times and message sizes
  • Which mailbox a message is delivered to, so who talks to whom can be worked out

Arveil does not promise anonymity. The threat model spells out each guarantee, the conditions it depends on, and what is still open.

What makes it different

Built around a few deliberate bets.

Your identity is yours

A key created on your device signs each of your devices. The person running the relay decides who may use it, never who you are.

Every device counts

Adding a phone or removing a lost one is a visible, verifiable change that the people in your chats can see, not a hidden account setting.

Works when the server doesn't

Read and write with the relay down; messages go out when it comes back. Nothing is lost silently.

Recovery you can plan

An encrypted identity kit, linking another device and history archives are separate and explicit, so you know which one to use.

Any route to the relay

An encrypted channel runs inside whatever connects you: home network, private network, tunnel or public address. A tunnel sees traffic, not content.

Small enough for a homelab

One program and a folder of data. No separate database server, message broker or cluster. Back it up by copying a directory.

The app

Made to be used by people who don't care how it works.

The interface is in English and Spanish, follows the system's light or dark theme, and supports large text and screen readers. The captures below are in Spanish and use made-up conversations.

Arveil on macOS: chat list, an open group conversation and its details, showing one verified and one unverified participant.
On the desktop: chats, the conversation and who is in it.
Arveil on Android: a group conversation with message bubbles and delivery ticks.
On Android.

Download

The first public beta is here.

Arveil is in beta: try it with people you trust. It is not in Google Play or the App Store. Releases are published on GitHub with SHA-256 checksums. Install from here or from GitHub, nowhere else.

Android

Android 7.0 or later, on a 64-bit ARM phone (nearly every phone from the last several years).

Download for Android (.apk, 36 MB)

macOS

macOS 12 or later, on a Mac with Apple silicon (M1 or newer). Intel Macs are not supported.

Download for Mac (.zip, 22 MB)

Version 0.1.0 beta 6. Release notes and SHA-256 checksums are on GitHub. New to Arveil? Follow the installation guide.

Windows, Linux and iPhone are planned but not built yet. Want to try it today? The code builds from source: installation guide.

Run a realm

For the person who sets it up.

The relay is a single Go program that stores its data in SQLite and a folder. It ships as a container image and runs with Docker Compose, rootless Podman or systemd, with health checks, limits, backups and a tested restore.

You choose how people reach it: your home network, a private network such as Tailscale, or a public address through a tunnel. The relay signs its list of addresses, so the route can change without anyone having to trust it.

Running a realm · Rootless Podman guide · Architecture

git clone https://github.com/Ulzuhan/arveil.git
cd arveil
docker compose -f relay/compose.yaml up -d --build
docker compose -f relay/compose.yaml exec \
  arveil-relay /arveil-relay invite -data-dir /data

What it is not

Small on purpose.

No federation between servers, no voice or video calls, no bots or bridges to other messengers, no web version, and no anonymity network. Arveil does one thing: private conversations inside a circle of people who know each other.