Guide · updated 2026-10-05

What bitchat keeps private, and what it cannot

The honest summary is short. Message content in a private mesh chat is encrypted. The fact that your phone is a particular phone on the mesh is not a secret from radios that can hear you. If you only remember one paragraph, remember that one.

What the encryption is

The Android project documents private mesh messages with the Noise Protocol, XX handshake, using X25519 and ChaCha20-Poly1305. Noise is a published pattern, not a private cipher. XX means the two peers authenticate each other as part of the handshake. A phone that is only relaying the packet is not a party to that handshake, so it is not supposed to be able to read the plaintext.

Password-protected channel chats are documented separately, with Argon2id for the password and AES-256-GCM for the payload. A channel password is only as good as the way you share it. Saying it out loud in the same room you are trying to exclude defeats the construction.

This site does not audit the implementation. “Documented construction” and “proven on your phone by a third-party review” are different claims. The maintainers also ship a reproducible build path so a researcher can rebuild the signed release’s unsigned bytes. That path is in the v2.0.1 notes, and it is the right next step if you need more than a hash match.

What a nearby radio can still learn

The project’s own privacy note says the mesh uses a persistent per-device identifier derived from the identity key. A radio that hears you today can recognize the same device tomorrow, even though it cannot read a private message and even though you never typed a phone number. Rotating a nickname does not automatically rotate that identifier.

Traffic timing is also visible. A mesh that goes quiet, then busy, then quiet again, tells a listener in the room that people are talking. Encryption does not pad the world into silence. If your threat model includes someone standing next to you with a radio, read the project whitepaper on identity and metadata before you rely on the app. The README points at it for this exact reason.

Online features change the audience

Nostr relays are computers run by other people. They are not the Bluetooth peer beside you. Public geohash rooms are readable by anyone in the room. Tor, included in the Android app through Arti, is a way to reach the internet path with less exposure of your home IP to those relays. Tor does not wrap the Bluetooth packets. Turning it on is not a disguise for the mesh.

Mutual favorites can receive private messages over Nostr when the mesh cannot see them. That fallback is convenient and it is also a different network. Know which path a thread is using when the content matters.

The wipe

The project documents an emergency wipe that clears local data, described as a triple-tap. Confirm the gesture in the version you installed. A wipe is local. Messages already displayed on another phone stay there. A public room does not forget because one participant’s phone forgot. The v2.0.1 notes also mention a more complete wipe of in-memory networking state during a panic clear. That still describes the phone in your hand.

This website is a separate privacy story

Downloading the APK from bitchat.cc creates a normal server log line. It does not create a bitchat account, because the app has none to create. Our privacy policy covers logs, the contact form, and ads. It does not cover what the app does after install. Install only a file whose SHA-256 matches the download page. A tampered build can ignore every promise in this article.