We like writing about the weaknesses of other messengers — most recently Telegram's defaults. Fair is fair: before we keep dragging others, let's turn the mirror around. Here's what doesn't shine quite as brightly on our own infrastructure as our marketing copy sometimes sounds.

"Decentralized" is currently more like "two servers, one operator"

The biggest word in our own vocabulary is "decentralized". The honest version: right now exactly two relays run. One on a rented server at Infomaniak, one on a private NAS in a living room in Switzerland. Both are operated by the same small team. That's not the same as a network of independent nodes nobody can individually switch off — it's a system with built-in redundancy, but with the same control behind it.

The difference from a classic centralized provider is still real: after the key exchange, the relays only ever see ciphertext, never plaintext — that stays true no matter how many or how few there are. But "nobody can read along" and "nobody can shut it down" are two different promises, and right now we honestly only fully keep the first one. More independent operators is the plan, not the current state — we're working on it.

Local posts only reach whoever's online right now

A feature we built deliberately and still aren't entirely happy about: posts meant for the immediate surroundings — a flea market in the neighborhood, a spontaneous announcement — only reach people who are actually connected at that exact moment. There's no lookup mechanism that finds them later, when someone opens the app for the first time two hours after posting. For posts that age quickly anyway, that's acceptable. For everything else, it's a gap we know about and haven't closed yet.

A built-in clock nobody sees

Our relay doesn't keep posts and directory entries forever — after seven days, older posts are gone, unless someone has updated them in the meantime. That's a deliberate decision: a server that endlessly hoards everything becomes exactly the kind of data hoard we're trying to avoid. Still, it's a central decision that applies equally to everyone, made by us, not by a rule users could set themselves. That too is less "decentralized" than it sounds, if you take the word seriously.

What we left deliberately as is

Some things on this list aren't bugs but trade-offs we made with eyes open. No full-text search over chat history on the server — a direct consequence of the same encryption we explained in the StrongBox article. No backup that automatically lands in some cloud — whoever loses their device had to have set that up themselves beforehand (more on that in the article about lost phones). Those are compromises where we deliberately chose the less convenient side, because the convenient side is exactly the attack surface we're trying to avoid.

The one spot we're still not happy with

If we had to name a single point that bothers us most, honestly: the number of independent relay operators. Two servers under one hand are a start, not a finish line. That's no secret we're hiding — it's written in our own technical docs, and it's why we want to use "decentralized" more carefully going forward, until more independent nodes are running. Until then: better to honestly say two servers than to claim a network that doesn't exist yet.