Quiet (TryQuiet/quiet): encrypted peer-to-peer team chat that runs over Tor
A private, p2p alternative to Slack and Discord built on Tor & IPFS
At a glance
- What is it?
- Quiet replaces the central chat server with direct device-to-device syncing over Tor. It is built for small teams that accept missing features in exchange for not trusting anyone's server, and it is explicitly unaudited.
- Who is it for?
- Adopt Quiet if you run a small team, you are comfortable with an unaudited application, and the absence of a server is worth more to you than direct messages, mentions, user removal or message deletion, none of which exist yet. Do not adopt it if any of those features is a requirement, if you need communities larger than roughly 30 to 100 members, or if your threat model demands audited cryptography.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 7 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 24, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Quiet removes: a server you have to trust or run
Slack, Discord and Element all put a server between you and the people you talk to. Someone owns that machine, controls who gets in, and holds the message history. Quiet's answer is to delete the server from the architecture. The README describes it as "an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own", and says all data syncs directly between a team's devices over Tor.
The audience follows from that. Quiet is aimed at people who care about software freedom, decentralization and privacy tech, and the README frames the goal as collaborating online without handing communities, networks and data to large corporations. If your team already runs Mattermost because self-hosting was acceptable, Quiet is not solving your problem. It is solving the problem of a team that does not want to run anything at all.
The project is written mostly in TypeScript, with Electron and React Native frontends, and it takes outside contributions. It is licensed GPL-3.0.
How syncing works: OrbitDB over Tor, one network per community
The unit of isolation is the community. Each group of people gets its own insular network, and the README states that data from one community never touches the devices of Quiet users in other communities, "not even in encrypted form". That is a stronger claim than per-community encryption keys, and it means a Quiet install used for one team carries no traffic for any other.
Message syncing is handled by OrbitDB, which the README describes as a mashup of Git, a gossip protocol and BitTorrent: it broadcasts new messages, syncs the latest ones, and fetches files. The practical consequence of gossip-based sync is that members who were offline typically receive the messages sent while they were away. Transport is Tor, which is why there is no inbound server to expose.
Access control is conventional PKI rather than a token in a database. The community owner, meaning whoever created the community, grants invites, access and usernames. The owner hands out an invitation code; the invitee uses it to connect to the owner's device, registers a username, and receives a cryptographic certificate that proves to other peers that they belong to the community. PKI.js is the library named for this. The owner's device is therefore a dependency at join time, even though it is not a server in the hosting sense.
Installing Quiet and creating your first community
Quiet ships as a desktop application, so installation is a download and a normal install, not a package manager step. The README points to the downloads section of tryquiet.org and names the artifacts by platform: .dmg for macOS, .exe for Windows, and so on. There is an Android app described as fully peer-to-peer with working notifications, and an iOS app distributed through TestFlight that the README says has no notifications.
If you are building from source instead, the developer setup lives in packages/desktop/README.md. The root package.json exposes the entry point for the desktop app:
npm run start:desktopThat script runs lerna scoped to @quiet/desktop. The repository also pins Node through .nvmrc, and the build scripts pull git submodules and build vendored dependencies, so a source checkout is not a one-command affair.
Once the app is running, the workflow is: create a community, then open that community's settings to invite members. Invitations are shared as invite links, the same way you would share one in WhatsApp, Signal or Discord. No email address or phone number is required to create or join a community, which is a real difference from every mainstream chat product named in the README.
Day to day, communities are organized into Slack-like channels, and the README lists images with drag and drop and previews, file transfer without arbitrary size limits, desktop notifications with optional sounds, and keyboard navigation for switching channels without the mouse.
What is missing, and why that is the real adoption cost
The README carries a warning block that should be read before anything else: Quiet is not audited and should not be used when privacy and security are critical. It also says the app lacks basic features and probably will not replace your Slack or Discord yet, while noting the maintainers use it daily as a Slack replacement. An unaudited cryptographic messenger is a defensible choice for low-stakes coordination and a poor one for anything regulated.
The planned-features list is long and specific, which makes the gaps easy to check against your own requirements. Direct messages, mentions, user removal, user profiles, message deletion and disappearing messages, connection status, emoji reactions, joining multiple communities, account recovery from a backup phrase, and private channels are all listed as still missing. Two of these stand out operationally. Without removal, you cannot revoke someone's access to a community once they are in. Without account recovery, losing an owner account has no documented path back.
Scale is the other hard boundary. The README puts the practical limit at roughly 30 to 100 members, with 1000-member communities deferred to post-1.0 work. Moderation, spam and denial-of-service protection, search, threads, Tor bridges and Tor Browser support are likewise post-1.0. iOS notifications are also absent, and the README explains why: receiving them requires a service Apple mandates be centralized, which conflicts with the no-server design.
Quiet compared with a self-hosted Slack alternative
The obvious alternative for a team that wants out of Slack is a self-hosted server such as Mattermost or Element's Matrix deployment. The difference is not encryption, it is topology. A self-hosted deployment still has a server: one machine that holds history, enforces membership and must stay reachable. Quiet has no such machine. Messages move between member devices over Tor, and the only owner-side dependency is the invitation handshake that issues a certificate.
That trade cuts both ways. A self-hosted server gives you administration: remove a user, delete a message, moderate a channel, search history, run a community of thousands. Quiet gives you none of that yet, and the README is explicit that removal, message deletion, moderation and search are unbuilt. What you get instead is a deployment with no host to pay for, no host to patch, and no operator who can read your messages.
Element sits closer to Quiet on the encryption story but keeps a homeserver in the path, and it does not require Tor. Quiet's design bet is that Tor plus per-community gossip networks is worth the feature gap. Whether that bet fits you depends entirely on whether the features in the missing list are things you actually use.
Maintenance, licensing and the cost of upgrading
The repository is not archived, and the last push was on 2026-09-23. The same date carries releases for @quiet/[email protected] and @quiet/[email protected], with @quiet/[email protected] published immediately after. That is a project shipping on a versioned cadence across two clients, with alpha builds visible in the open.
Upgrade cost is mostly the client. Desktop and mobile are distributed as binaries, so a team member upgrades by installing a new release. The friction is on the source side: the root package.json shows lerna orchestration, husky hooks, vendored submodules under 3rd-party/ (auth, js-libp2p-noise, orbitdb) with their own build scripts, and a patch directory applied to the qss dependency. Anyone maintaining a fork is maintaining that whole chain, not just the app code.
The licence is GPL-3.0, stated in the repository and in LICENSE.md. For internal use by a team this is unremarkable. If you intend to embed Quiet in a product you distribute, GPL-3.0 carries source-disclosure obligations, and that is a question for your own counsel rather than something this article can settle. The README does not document a rollback procedure for a bad release, and the release notes guide in the repository describes how notes are written rather than how downgrades are handled.
Editorial conclusion
Adopt Quiet if you run a small team, you are comfortable with an unaudited application, and the absence of a server is worth more to you than direct messages, mentions, user removal or message deletion, none of which exist yet. Do not adopt it if any of those features is a requirement, if you need communities larger than roughly 30 to 100 members, or if your threat model demands audited cryptography. Before rolling it out, check the downloads page for the current release, read the threat model wiki page, and confirm how you would recover a community owner account, since account recovery from a backup phrase is listed as still missing.
Frequently asked questions
Does Quiet require a server to work?
No. The README states that Quiet syncs messages directly between a team's devices over Tor with no server required, and that message syncing is handled by OrbitDB. The one owner-side dependency is the invitation handshake, where an invitee connects to the owner's device to register a username and receive a certificate.
Is Quiet audited, and is it safe for sensitive work?
It is not audited. The README carries a warning that Quiet should not be used when privacy and security are critical. The repository links to a threat model wiki page, which is the right place to check what the design does and does not claim.
How large can a Quiet community get?
The README puts the current limit at roughly 30 to 100 members. Communities of 1000 members or more are listed under post-1.0 features, meaning they are not available now.
Can I remove a member or delete a message in Quiet?
Not yet. Removal and message deletion, including timed disappearing messages, both appear on the README's list of planned but still-missing features. Moderation tools are deferred to post-1.0 work.
How do I install Quiet?
Download the latest release for your platform from the downloads section of tryquiet.org and install it normally; the README names .dmg for macOS and .exe for Windows among the artifacts. There are also Android and iOS apps, with the iOS build distributed through TestFlight and without notifications.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/tryquiet-quiet)