No account. No phone number. No email. No logs. AES-256-GCM encrypted chat rooms that exist only while you're in them โ and leave zero trace when you're not.
Most messaging apps link your account to a phone number. Most create logs. Most can be subpoenaed. MiutChat was built from the ground up to give journalists and their sources a channel where there is simply nothing to hand over โ because nothing is stored.
AES-256-GCM Encryption
Every message is encrypted in your browser before it touches the network. The server receives only ciphertext. Even a full database dump reveals nothing readable.
Zero Identity Required
No account. No phone number. No email. No name unless you choose one. A source is an anonymous session, nothing more โ unlinked to any identity in any database.
Rooms Self-Destruct
When everyone leaves, the room and every message in it are permanently deleted from the server. No archive, no history, no backup. Gone means gone.
Open Source & Auditable
Every line of encryption code is public on GitHub. No proprietary black boxes. Any security researcher can verify the implementation โ and several have.
No Download Required
A source doesn't need to install anything. They open a URL in any browser. No app store trail, no install history, no permissions requested. Just a browser tab.
Works on Any Device
Desktop, Android, iPhone. No platform-specific app required. A source can use a library computer, a borrowed phone, a public terminal โ and leave no trace on the device.
HOW IT WORKS
Set up in under 60 seconds.
No onboarding. No confirmation emails. No waiting. Create a room, share the code, and you're talking โ end to end encrypted, with nothing stored on either side.
1
Open MiutChat in any browser
Go to miutchat.pages.dev. No download, no install, no account creation. The app runs entirely in the browser โ nothing is installed on the device.
2
Create a room with a strong code
Tap Create Room. Choose a room code โ this code is the encryption key. The longer and more random, the better. Think of it like a passphrase, not a username.
3
Share the code out-of-band
Send the room code to your source through a separate channel you already trust โ a one-time email, a physical note, an in-person conversation, or another encrypted channel. The room code never passes through MiutChat's servers.
4
Communicate โ then it's gone
Once your source enters the code, you're both in an AES-256-GCM encrypted room. When either party leaves and the room is empty, every message is permanently deleted from the server. There is no archive, no export, no backup.
โ IMPORTANT OPSEC NOTE
MiutChat protects the content of your messages. It does not protect metadata at the network level โ your ISP and the Cloudflare CDN can still see that you connected to miutchat.pages.dev. If your threat model requires hiding the fact that you communicated at all, use MiutChat over Tor or a trusted VPN. No single tool is sufficient for high-risk source protection โ MiutChat is one layer, not a complete solution.
FREQUENTLY ASKED
Real questions from journalists.
There is nothing to hand over. Messages are deleted when the room empties. MiutChat stores no plaintext, no decryption keys, and no message logs. A server-side subpoena would return only encrypted blobs from a session that no longer exists. That said, anything visible on a screen can be photographed โ operational security on the device itself remains your responsibility.
Nothing compromising would be found. The server holds only encrypted ciphertext โ and only while a room is active. When a room empties, those records are deleted. The encryption keys are derived from the room code, which only exists in the participants' browsers, never on the server. There is no master key.
Different tools serve different threat models. Signal is excellent and is trusted by security researchers worldwide โ but it requires a phone number, which links a source's identity to the conversation. MiutChat requires nothing. The tradeoff is that Signal's app has a longer security audit history. For a source who cannot risk having a Signal account linked to their identity, MiutChat offers a genuinely account-free alternative.
Yes โ this is one of MiutChat's core advantages. Your source opens a URL in any browser. No download, no install, no app store, no permissions dialog. They see a page asking for a room code, they enter the code you shared, and they're in. Nothing is installed on their device.
Read the source code. The full implementation is at github.com/MiutChat/MiutChat. The encryption is in crypto-engine.js โ it uses the browser's built-in Web Crypto API (SubtleCrypto) which is implemented in native code and has been audited independently of MiutChat. No custom cryptography is used. The key derivation is PBKDF2 with SHA-256 and 310,000 iterations. The cipher is AES-256-GCM.
GET STARTED
Your next source conversation doesn't need to leave a trace.
Free. No account. No download. Works in any browser. The room disappears when you're done.