Zero service setup: by default this page uses ntfy.sh, but you can enter another compatible NTFY server. No account is required when that server permits anonymous publish/subscribe.
End-to-end encrypted content: your display name and message are encrypted locally. NTFY receives only an opaque encrypted envelope on a pseudorandom topic derived from the random room secret.
Not permanent storage: ntfy caches messages temporarily to support reconnects. This client asks for up to the recent 12-hour cache when joining.
Metadata still exists: the relay can observe IP/network metadata, the derived topic, message times and ciphertext sizes. The public ntfy.sh relay is not an anonymous or access-controlled channel; confidentiality comes from this app's encryption and the secrecy of your invite/password.
Security boundary: message contents are end-to-end encrypted in the browser, but no browser app can honestly promise “100% security.” A compromised device/browser, leaked invite/password, malicious extension, weak password, or denial-of-service at the relay can still defeat privacy or availability.
Best effort: the free public relay has rate limits and no uptime guarantee. This is ideal for lightweight private chat, not a replacement for a production messenger.
If you open this HTML locally, both users need a copy of the same file. If you host it on any HTTPS static website, the invite-link button becomes the easiest way to join from another device.