Case study / Privacy

Building a Serverless End-to-End Encrypted Messenger

Gumnam joins a Rust messaging core, Tor transport, end-to-end encryption and a cross-platform desktop client.

Product
Private desktop messenger
Role
Systems & Cryptography Engineer
Period
2025–present
Status
Open-source project
Stack
Rust, Tor, Flutter, SQLite, libp2p, Ed25519, X25519

Privacy goals and constraints

Gumnam is a serverless messenger designed to reduce reliance on a centralized messaging backend. The product has to establish peer identity, deliver messages over Tor hidden services and protect message content end to end.

A privacy-focused messenger still has to work when peers are intermittently available. It also needs a usable desktop interface, local state and clear reject-on-fail behavior for invalid protocol messages.

Architecture

I built the Rust systems core and connected it to a Flutter/Dart desktop client with flutter_rust_bridge. The desktop application handles chat, media, reactions, pinning and notifications; the Rust core handles the messaging protocol and Tor runtime.

The design uses Tor hidden services for communication and onion-address identity verification. Local-first SQLite persistence keeps client state on the device. An embedded libp2p Kademlia DHT provides a fallback path for offline message delivery when peers are not simultaneously online.

Encryption and identity

The protocol combines Ed25519/X25519-based identity and key exchange with HKDF and ChaCha20-Poly1305 for encrypted messages. Protocol messages are signed and invalid data is rejected rather than partially accepted.

Encryption protects content, while identity checks and transport choices address different risks. The system still depends on endpoint security and careful local data handling; a private transport alone does not provide complete anonymity.

My contribution and technical challenges

I engineered Tor bootstrap and runtime management, message validation, secure local state and data-clearing workflows. The main challenge is coordinating a responsive UI with a privacy-sensitive asynchronous core while peers and network paths may be unavailable.

The public repository is the best place to inspect the implementation. I do not claim an independent security audit or publish unverified user metrics.

Related services

Have a project in mind?

Let’s talk about a privacy-focused product.

Share your goals, current system and timeline. I can help scope the architecture and implementation.