A network observer on the same Wi-Fi
Sees TLS to Livara and nothing else. No message content, direct or group.
HeldA threat model that only lists strengths is a brochure. This one names the relevant adversaries, says exactly what each gets, and then prints the list of things Livara does not claim.

Some get more than you might hope. They are listed anyway, in the same type size as the rest.
Sees TLS to Livara and nothing else. No message content, direct or group.
HeldReads channel content and routing metadata. It cannot directly open compatible private text/media, but it can substitute a first-contact key or insert a private-group member until key transparency and MLS replace those trust points.
Not heldCannot restore your direct-chat keys — the encrypted backup needs the recovery phrase as well.
HeldReads everything you can read. No messenger survives this one.
Not heldCurrent direct sessions use Livara's unaudited hybrid-PQ LVR1; LGS1 sender keys and attachment keys travel inside those sessions. This is not equivalent to Signal's reviewed Triple Ratchet, and DTLS-SRTP call media is not itself post-quantum.
HeldDetectable before install. The SHA-256 is published and the Proof Lab hashes your file locally.
HeldThis table is printed identically on the home page, on the security page and here, because the answer should not depend on which page you landed on.
LVR1 closes compatible direct content before upload. LGS1 does the same for compatible private-group text and attachment-key messages; channel and metadata cells show what remains visible.
The cryptographic detail ↗| What it is | Direct 1:1 | Groups | Channels |
|---|---|---|---|
| Message text | Sealed on your device | LGS1 sender-key sealed | Server can read it |
| Text edits | Sealed on your device | LGS1 sender-key sealed | Server can read them |
| Photos, video, files, captions | Encrypted before upload | Encrypted before upload | Server can read them |
| Who you talked to | Server knows | Server knows | Server knows |
| When you talked | Server knows | Server knows | Server knows |
| Your password | Never leaves your device | Never leaves your device | Never leaves your device |
| Your private keys | Never leave your device | Never leave your device | Never leave your device |
Each of these is a real limitation with a real consequence. They are here because a boundary you can only discover by being disappointed is not a boundary, it is a trap.
Ordinary delivery stores sender, destination, group membership, timing, ciphertext size and delivery state. LSS1 code exists but is not integrated into normal sends. Multi-device sync is not a proof that this metadata must be retained in this form.
LGS1 covers compatible private-group text and media, but it encrypts to the member list supplied by Livara. A compromised service can insert an account before redistribution. Channels remain server-readable.
Android supports 2–6-person group audio/video and screen sharing. Every peer link uses WebRTC DTLS-SRTP and pairwise-sealed signaling, but there is no MLS-bound SFrame layer, call media is not post-quantum, the server still sees participant/timing metadata, and browser clients do not join group rooms yet.
Clients pin a complete identity after a successful message and detect later changes. Until a witnessed key-transparency directory exists, a malicious server can substitute the first key shown to two new devices.
Keys live on the device. Malware with your unlocked device has your plaintext, and no protocol choice on our side changes that.
Lose the device and the phrase together and the old direct-chat ciphertext stays closed permanently. That is the real price of a server that cannot read your messages.
There is no third-party audit report to point at yet. Instead of implying one, the site ships the Proof Lab so the parts that are checkable can be checked by you today.
Hash the APK, run the handshake, corrupt a byte and watch the authentication reject it. All of it offline, in your own browser, before you install anything.