Skip to content

Latest commit

 

History

282 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Statim

An encrypted messenger whose account is a key you hold. Twelve words, generated on the device. No sign-up, no phone number, no email, and no backend of ours for anyone to subpoena, sell or breach. The same phrase is also an Ethereum, Bitcoin and Solana wallet.

iOS, Android and macOS, from one Expo SDK 57 / React Native 0.86 / React 19.2 codebase. The desktop app is the web export of that codebase running in a Tauri window.

Statim takes its logo from the 2018 Status app. It is not affiliated with or endorsed by Status.

The promo film: a twelve-word account, five protocols in one chat list, and an AI agent paying a friend back while you approve on the phone

Welcome screen: create an account, restore a phrase or connect a hardware wallet The Statim chat, with slash command chips above the composer Long-pressing a message: reactions, reply, copy and forward Plugins screen: assistant, names, bots, wallet, browser and markets

User guide · Contributing · Security · Privacy · Disclaimer

Five protocols, one chat list

Every chat says which protocol it is on and what that protocol actually protects, because the honest answers differ:

Protocol Confidentiality Reach someone by Runs on
XMTP MLS, forward secret Ethereum address or ENS name Your recovery phrase
Nostr NIP-17 sealed DMs; relays never learn the sender npub… public key Your recovery phrase
Status Status's chat protocol, through Status's nodes or a Status node you run zQ3sh… chat key Your recovery phrase
Telegram None. Telegram holds and can read it @username, t.me link, phone number Your Telegram account, over TDLib
Matrix Olm/Megolm in chats with encryption on @user:server Your Matrix account, over matrix-rust-sdk

Telegram and Matrix are real client implementations, not bridges we operate: sign in with your own credentials and those chats land in the same list. A Matrix homeserver running a mautrix bridge brings WhatsApp, Signal, Slack, iMessage or Discord along with it, with no code for any of them in this app.

What else is in it

  • Requests, folders, search, replies, reactions, forwarding, pin, archive and mute. Photos, files, GIFs and voice notes. Groups where the protocol has them.
  • Links unfurl into cards fetched by your device, not a server. Phone numbers, email addresses, map coordinates, wallet addresses and ENS names are tappable with no request at all.
  • Per-account SQLCipher history. Several accounts per device, each from a recovery phrase or a hardware wallet (Ledger, Trezor, Keystone), with optional biometric unlock and key protection.
  • A fresh install is a messenger and nothing else. Wallet, dapp browser, market alerts, bots and name lookups are plugins that ship switched off, each declaring its permissions before you enable it.

Everything a plugin does is a slash command. / in any chat opens a picker scoped to that chat; the chips above the composer run the same slash commands. /chains switches chains on and off, /send and /request move money inside the chat where it came up, /trade (also /swap, /bridge) quotes through LI.FI, /scan reads a WalletConnect code. Anything that signs shows a review step first.

Platforms

iOS, Android, macOS, Windows and Linux. The iPhone app is in beta on TestFlight, and Android in testing on Google Play. Telegram on the phone needs TDLib in modules/tdjson first: ./scripts/tdlib.sh ios or ./scripts/tdlib.sh android.

One tag releases the desktop apps, through .github/workflows/release.yml.

Quick start

Node.js 22.13+, Xcode 26.3 with an iPhone simulator, and CocoaPods. Rust as well for the desktop app, and for Android its SDK and a JDK from 17 to 21. Expo Go cannot run this: XMTP, TDLib, SQLCipher and the hardware wallet transports are all native modules.

npm install                 # also applies patches/
./scripts/tdlib.sh ios
npx expo run:ios
npm start            # Metro
npm run desktop      # Metro on 8082 plus a Tauri window that reloads on save
npm run typecheck && npm run lint && npm test
npm run test:e2e     # Maestro, against a booted simulator with Metro running
npm run test:all     # all four, in that order

Keys and configuration

Nothing secret ships in the repository, and the app works without any of it.

What Where Needed for
WalletConnect project id expo.extra.walletConnectProjectId in app.json connecting dapps
Telegram API id and hash Settings → Protocols → Telegram, per account Telegram sign-in (my.telegram.org)
Matrix homeserver and ID Settings → Protocols → Matrix, per account Matrix sign-in
LI.FI key Settings → Trades, per account optional; raises the quote rate limit
KLIPY key Settings → GIFs, per account GIF search

Token balances need no key at all. src/lib/evm/token-list.json is the Uniswap Labs Default list trimmed to the five chains the wallet sends on (829 entries), read with one multicall against the endpoint already in use; /tokens add <contract> covers anything it misses. Solana enumerates its own holdings through getTokenAccountsByOwner, with Jupiter's verified list bundled only to put a name to a mint.

Documentation

For Where
Using the app statim.laibe.cc (docs/)
Working on the code CONTRIBUTING.md
Reporting a vulnerability SECURITY.md
What leaves your device PRIVACY.md
What the developer is not responsible for DISCLAIMER.md
Why each dependency is patched patches/README.md
End-to-end tests e2e/README.md
Running your own bots Your own bots

License

MIT. See LICENSE.

About

Self-custodial messenger. Your account is twelve words on your device: encrypted chats over XMTP, Nostr and Waku, Telegram and Matrix in the same inbox, and a wallet in the conversation. iOS, macOS, Windows, Linux, Android.

Topics

Resources

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages