End-to-end encrypted · Zero-knowledge server · Open source

Private messaging
for the whole family.

Stars 2.0 is a ground-up rebuild of secure messaging, voice, and video — engineered so a full breach of the backend reveals nothing. Per-conversation keys. Zero-knowledge server. On-device safety. Built for families.

100%on-device keys
0plaintext on server
E2EEincl. A/V calls
Stars 2.0 welcome screen on iPhone
🔒 Per-conversation keys

Three promises, in order.

The three things every Stars user is told on the first screen — and that the app's architecture is built to keep, not just claim.

Private by design

Messages are end-to-end encrypted on your device. Our servers only ever route scrambled data — a breach reveals nothing.

Family-aware, not surveilled

Kids approve which guardians can follow along. Monitoring only happens with consent — it can't be turned on secretly.

Safe on this device

Harm is detected on your phone before anything is sent. What you type never leaves the device to be scanned.

Stars 2.0 account creation — keys generated on device

Engineered, not marketed

Your keys never leave your phone.

A device keypair and one-time prekeys are generated and published so people can message you even when you're offline. Every conversation has its own key. The server holds ciphertext and minimal routing metadata — that's it.

  • No plaintext ever reaches a server. If a feature seems to require it, the design is wrong — solve it client-side.
  • Private keys never leave the device. Sealed by the Secure Enclave / StrongBox / TPM. No export, no key backup.
  • End-to-end encrypted A/V calls. The SFU forwards opaque encrypted frames; the call key is derived client-side.
  • Private contact discovery via RFC 9497 VOPRF. A leaked directory can't be brute-forced.
  • Open source, reproducible builds, signed dependencies (SBOM + cosign + provenance).

Built for families

Child-safe and compliant — without breaking E2EE.

Most "safe messengers" for kids either scan messages on a server (privacy-broken) or pretend the problem doesn't exist. Stars 2.0 does neither. Safety happens on the device, before the message is encrypted and sent. Guardians get cryptographically-enforced visibility their child has approved — and can stop approving at 18.

Consent, not surveillance

Guardian access is a cryptographic capability the child grants. There's no hidden monitoring mode — if a guardian is reading along, the child knows it.

On-device safety

Threats and self-harm are detected on the phone before anything is sent. The server never sees a message — so it never sees a flagged one either.

COPPA, GDPR-K, CSAM reporting

Regulatory obligations are met by design, on the client, without breaking end-to-end encryption.

Guardians removable at 18+

When a child becomes an adult, the system stops being a child-safety system. The cryptographic relationship terminates — by them.

Ready to switch?

Available on iOS and Android. A live web demo runs the exact same on-device safety + sealed-box crypto the apps ship.

Store links arrive with public beta. The web demo runs today — same crypto, same on-device safety.