DUNNO v1.3.0 · Android · eu.dunno.app

The messenger that knows nothing about you.

DUNNO is an ultra-secure, peer-to-peer messenger for Android. All communication runs over Tor v3 hidden services — completely without central servers. End-to-end encrypted, screenshots blocked by default, and if threatened, the app wipes itself in 13 phases.

8.4/10
On-device security
13
Emergency wipe phases
6
Anti-Frida vectors
4
TEE keystore aliases
Features

Everything you'd expect from a messenger. Nothing that compromises your privacy.

Every feature is built from the ground up around one principle: your data belongs to you — and to no one else.

💬

Chat

Text messages with true end-to-end encryption between peers. No relays, no logs, no middlemen.

NaCl crypto_box_seal
📎

File transfer

Send files end-to-end encrypted. Every attachment is protected with AES-256-GCM, with the data key wrapped in the Android Keystore.

AES-256-GCM
📹

Video calls

Peer-to-peer WebRTC voice & video calls, end-to-end encrypted. Calls do not run over Tor — your IP address is visible to your ISP. Explicit consent required.

Explicit consent required
🎙️

Push-to-talk

Walkie-talkie style voice, fast and lightweight — and fully encrypted over Tor. The safe alternative to regular calls.

100% over Tor
🔒

App lock by default

Mandatory PIN (8+ digits) on cold start — and deliberately no fingerprint unlock. The PIN screen can never be bypassed, which keeps the wipe code effective.

No biometric bypass
🧹

Emergency wipe

One panic PIN and the app wipes itself in 13 phases: database, attachments, keys, Tor hidden service and more. Idempotent — even after a crash.

13 phases
📵

No screenshots

FLAG_SECURE is always on, on every screen. No screenshots, no screen recordings, no recents previews. Autofill is blocked too.

FLAG_SECURE always-on
🧅

Tor v3 hidden services

All communication via .onion addresses. Bridge support (OBFS4) for censored networks.

No central server
🔔

Private notifications

VISIBILITY_PRIVATE on every channel: no content on the lock screen, contact names hidden. Not switchable — security first.

VISIBILITY_PRIVATE
WebRTC calling: an honest trade-off

Voice and video calls are a service DUNNO deliberately offers. We first built them over Tor — but the latency made them unusable. That is why calls work differently from messaging:

  • Media (audio & video) is peer-to-peer WebRTC, end-to-end encrypted (DTLS-SRTP), direct between the two devices.
  • Audio calls (Fast Call): signalling runs over Tor through a server that keeps no logs; because the media itself does not travel over Tor, your IP address is visible to your ISP.
  • Video calls: only the initial invitation is sent over Tor — the rest of the call setup runs over a direct connection, so your IP address and call metadata are visible to your ISP.

This trade-off is necessary to keep calls fast and reliable. If you want fully anonymous voice, use push-to-talk: it runs entirely encrypted over Tor.

In short: chat and push-to-talk offer maximum privacy, audio calls reduced, video calls minimal.

Because calling exposes your IP address, it is off by default. Before your first call, the app asks for your explicit consent. If you do not accept, calling stays disabled.

Security

Security in layers, not as an afterthought

From transport to database, from hardware keys to runtime detection: every layer is designed defensively.

🔐 Encryption stack

  • Transport: NaCl crypto_box_seal — X25519 + XSalsa20-Poly1305
  • Transport v2: per-message crypto_secretbox, 256-bit key via X25519 ECDH + SHA-256 KDF
  • Signing: Ed25519 detached signatures on every payload
  • Database: SQLCipher AES-256, fully encrypted at rest
  • Inbox v4: layered secretbox + SessionKey per message
  • Backup: PBKDF2 600K iterations + HMAC-SHA256 + AES-256-GCM
  • PIN derivation: Argon2id (10 ops, 64 MB) — memory-hard

🔑 Hardware-backed keys (TEE)

Four separate keystore aliases, all hardware-backed in the TEE / StrongBox:

  • Database key — TEE AES-256-GCM
  • Identity key wrap — TEE + user authentication (4h timeout)
  • Device bind — attestation, hardware-backed
  • Attachment wrap key — TEE AES-256-GCM

🚫 Anti-tampering & runtime

  • 6 anti-Frida vectors: maps, tracer, port 27042, threads, artifacts, root/Magisk
  • Anti-debugger: TracerPid check in /proc/self/status
  • Runtime response: detection → SessionKey wipe + force-lock
  • ProGuard: release builds, Log.d/v stripped
  • SessionKey model: refreshed per unlock, wiped on threat
  • UserDataKey: never leaves RAM long-term
Transport
Tor v3 hidden services
HTTP client
Custom OnionHttpClient
Bridges
OBFS4 (Tor Browser compatible)
Battery / network
NodeOrchestrator — 45s idle stop
📄

Independent security audit — v1.3.0

Full source-code audits of the Android app (Kotlin) — a separate report for the Google Play edition and one for the direct download edition. Core messaging (chat, PTT, attachments): no critical findings.

Comparison

On-device security: DUNNO vs the rest

Independently scored categories for on-device security.

CategoryDUNNOSignalBriar
Data-at-rest encryption976
Key storage (TEE)945
App-level lock976
Screen security9.56.53
Anti-tampering943
Wipe / data destruction921
Notification privacy874
Backup encryption881
Maturity & external validation2106
Total8.46.14.9

DUNNO scores 8.4/10 — significantly higher than Signal (6.1) and Briar (4.9).

Privacy

No central server. Literally.

DUNNO communicates peer-to-peer over Tor v3 hidden services. There is no message server, no account database, no metadata mine. The only server-side component is an optional TURN server for video calls behind NAT — and it only provides connectivity, never content.

  • Fully peer-to-peer, even for chat
  • Onion addresses: no IP leakage between peers
  • Bridge support for censored networks
  • Works without a phone number or email address
Hidden service (example) ……………………………………………… .onion

🔒 End-to-end encrypted. Tor-routed. Frida-proof.

Download

Ready to get off the radar?

DUNNO v1.3.0 for Android — available now on Google Play. Try it free for 14 days, then keep it for €5.99 per year via Google Play Billing.

14-day free trial

Get it on Google Play

Install DUNNO straight from the Play Store with your existing Google account. Try the full version free for 14 days — after that it renews at €5.99 per year via Google Play Billing. Cancel anytime in your Play Store subscriptions.

⬇ Get it on Google Play
One-time · €9.99 EUR

Buy with Bitcoin

Private APK download link for a one-time Bitcoin payment. No Google account, no subscription. Your personal link stays valid for all future updates — no extra costs. Checkout runs on our own self-hosted BTCPay server.

₿ Pay with Bitcoin
Package eu.dunno.app · Version 1.3.0 · Platform Android · Screen security: FLAG_SECURE always-on
Affiliate program

Have an audience? Earn 40% per sale.

Promote DUNNO and earn up to 50% on every settled Bitcoin sale — paid in Bitcoin, only on real payments. No costs to join.