Skip to content

Pre-release · Post-quantum security

Keep communication going—securely.

Nudge is built for people who can’t afford leaks, outages, or “harvest now, decrypt later.” We treat censorship as an engineering problem to route around, and security as the baseline: encrypt everything—messages, documents, voice, and video.

Planned platformsiOSiPadOSmacOSAndroid
Security model
End‑to‑end encryption
Crypto
PQXDH (post‑quantum)
Server posture
Non‑caching by default
Nudge contact list on iPhone in dark mode

Available on iOS, iPadOS, macOS, and Android

See Nudge in action

A polished, privacy-first experience on every screen—from your pocket to your desktop.

Android

Light mode that feels native

Filter conversations by personal, direct, channels, unread, or pinned—with a clean interface built for everyday use.

Nudge contact list on Android in light mode
iOS

Dark mode, refined

Pin, archive, block, or hide chats. Group DMs and channels stay organized with powerful list controls.

Nudge contact list on iPhone in dark mode
macOS

Secure conference rooms in seconds

Spin up one-time rooms with unique IDs, passwords, and QR codes. Pick your camera and mic before you join.

Nudge conference room setup on macOS
Rich media, reactions, and calls
Encrypted chat

Rich media, reactions, and calls

Photo collages, voice notes, read receipts, and inline video calls—always protected with end-to-end encryption.

  • Photo collages
  • Reactions
  • Video calls
  • Voice notes
  • E2EE

What Nudge is

Nudge is a post‑quantum secure messaging and calling app. It combines a PQXDH handshake (ML‑KEM‑1024 + Curve25519) with Double Ratchet for forward secrecy and post‑compromise security—then wraps it in transports designed to survive real networks.

End‑to‑end encrypted by default

Messages are encrypted on your device and decrypted only by intended recipients. The goal is simple: keep what matters “in the box”—and keep everyone else out.

Transport resilience

Built with multiple transports and fallbacks in mind (e.g., P2P + relays) so communication can keep moving across hostile or unstable networks.

Public + private options

Use the public posture—or deploy a private Nudge community when you need governance, compliance boundaries, and operational accountability.

Voice & video calling

Realtime communication built for sensitive contexts. Nudge is designed so calling is not an afterthought—security and reliability are treated as first‑class requirements.

Operational confidence

Clear responsibility boundaries and a path to private infrastructure. For organizations, NeedleTails can implement and deploy servers for your own Nudge community.

Built for hard regions

Designed with censorship and transport fallbacks in mind—tested across multiple countries.

Why choose Nudge

When communication is sensitive, you need more than a chat app. Nudge is built to protect content with end‑to‑end encryption, hold up against “harvest now, decrypt later,” and keep working across real‑world networks.

🏥
A strong fit for healthcare

Healthcare conversations can include PHI and high‑stakes decisions. Nudge is a good choice because it’s designed around end‑to‑end encryption, post‑quantum session establishment, and practical reliability—so clinical teams can coordinate while reducing exposure of sensitive content.

🔐
Privacy by design

Post‑quantum PQXDH + Double Ratchet foundations, with a non‑caching public posture. Deploy privately (self‑host or managed) when you need governance and stricter boundaries.

🌍
Cross‑platform + multi‑device

Use Nudge across iOS, iPadOS, macOS, and Android. It’s designed to support modern teams that communicate across multiple devices—without lowering the security bar.

Where Nudge is valuable
  • Sensitive conversations (clinical coordination, on‑call teams, and incident response).
  • Secure sharing of documents and media between devices—without leaving content sitting in consumer cloud inboxes.
  • Teams operating in regions with unstable networks or censorship pressure.

Security & privacy

Transparent, technical answers about what Nudge protects—and what no app can promise.

Is Nudge end‑to‑end encrypted (E2EE)? What does that actually mean?

Nudge is designed around end‑to‑end encryption for messages and calling: plaintext is encrypted on the sender’s device and decrypted only on intended recipients’ devices. The server can relay encrypted packets, but it shouldn’t have the keys needed to read message content.

What cryptography does Nudge use?

At a high level: Nudge’s building blocks use a hybrid PQXDH session establishment (ML‑KEM‑1024 / Kyber + Curve25519), then a Double Ratchet design for message key evolution (forward secrecy + post‑compromise security). Symmetric encryption is done with authenticated encryption (e.g., AES‑GCM) and keys are derived using standard KDFs (e.g., HKDF). See the Cryptography page for the deeper protocol walkthrough.

What can servers or networks still observe (metadata)?

Even with E2EE, networks can still observe things like IP endpoints, message timing, and traffic volume. Some systems also expose identifiers depending on transport. Nudge aims to minimize and encrypt sensitive metadata where supported (for example, encrypted headers can reduce what an intermediary learns about message counters and key identifiers), but no messaging system can eliminate all metadata in every network environment.

What does “non‑caching public server” mean—and what changes with a private deployment?

The public posture is intended to avoid retaining message content on the server side. If your organization needs governance, audit boundaries, or stricter operational controls (e.g., compliance requirements, incident response workflows), a private deployment is the right model. NeedleTails can implement and deploy Nudge servers for your community for a price.

What does Nudge NOT protect you from?

E2EE protects message content in transit, but it can’t prevent endpoint risks: screenshots, screen recording, someone with physical access to an unlocked device, malware on an endpoint, insecure device backups, or a compromised OS. Also, push notification systems and networks may leak metadata. If you need stronger anonymity or tighter operational controls, consider a private deployment and follow secure-device best practices.

Is encryption perfect? Can Nudge make me 100% safe?

No. Strong encryption dramatically reduces risk, but no app can guarantee absolute safety. Security depends on your threat model and the weakest link—devices, accounts, backups, and human factors. Protect yourself by keeping devices updated, using strong passcodes/biometrics, enabling full‑disk encryption, avoiding untrusted links/files, verifying contact identities when it matters, and assuming screenshots/recordings are always possible on endpoints. If you face a high‑risk adversary, consider operational security, private deployments, and expert guidance.

Ready to keep communication going?

Nudge is preparing for public release. Contact NeedleTails for release updates, private deployments, or security review conversations.

Donate