Mynah: private chat that never asks for your phone number
Every mainstream messenger makes your phone number your identity. Mynah does not have that field. You sign up with a username, and anyone can open a disposable chat room with just a code — no account at all. Every message, photo, voice note and call is sealed on your device before it leaves.
The problem
A phone number is not an identity — it is a permanent link back to a real person.
- Your number is your account. Change apps, change phones, it follows you — and so does anyone who has it.
- Group chats leak it. Joining a room with strangers usually means handing every one of them a way to reach you forever.
- “Encrypted” often stops at the server. Plenty of apps encrypt in transit and then store readable messages at rest.
What Mynah does
You sign up with a username. There is no phone-number field to fill, so there is nothing to leak. Friends, groups, photos, voice notes and calls all work the way you expect.
Separately, anyone can spin up a chat room that needs no sign-up at all — share a code, people join, and the room deletes itself. It is built for the conversation you want to have once and not keep.
- End-to-end encrypted chats and calls — text, photos and voice notes alike.
- No phone number — a username is the whole identity.
- Rooms without sign-up that join by code and delete themselves.
- Scheduled and disappearing messages.
- Admin panel with two-step login and abuse reporting.
How it is built
This is the part that makes it a real privacy product rather than a privacy claim.
Mynah is a React + TypeScript PWA on Supabase — Postgres with row-level security, Realtime for delivery, and Storage for media. The interesting work is what Supabase never gets to see.
Every message, photo, voice note and call is encrypted in the browser using Web Crypto — ECDH to agree a key and AES-GCM to seal the payload. The server only ever relays ciphertext, and it only holds it for 24 hours. Message history lives on your device, not in a database someone could be compelled to open.
Rooms work without accounts because the room’s key is derived from the room code itself. Nobody registers, nothing is stored against a person, and when the room goes, the key goes with it. Calls run peer-to-peer over WebRTC.
The hard part
Privacy and speed pull against each other. If you seal every message on the device, you cannot let the server index, search or fan out anything for you — it has no idea what it is holding.
The answer was to keep the sealing on the phone and make delivery do the work: messages go out over per-user realtime channels and are decrypted on arrival, so the app feels instant while the server stays blind. Deriving room keys from the room code is the same trick applied to access — it removes the sign-up step instead of securing it.
FAQ
Is Mynah really end-to-end encrypted?
Yes. Messages, photos, voice notes and calls are encrypted in the browser with Web Crypto (ECDH for key agreement, AES-GCM for the payload) before anything is sent. The server relays ciphertext only, and holds it for 24 hours; history stays on your device.
Do I need a phone number?
No. You sign up with a username. There is no phone-number field. For a one-off conversation you do not even need an account — open a chat room and share the code.
What happens to a chat room afterwards?
It deletes itself. The room key is derived from the room code, so once the room is gone there is nothing left to decrypt and nothing stored against a person.
Who built Mynah?
Vansh Kashyap, a developer in New Delhi — full design and build. The app’s own footer credits it: “Built in New Delhi by Vansh Kashyap.”
Need a product where privacy is the feature?
Encryption, access control and data that stays where it should — tell me what you are building.