The area of messaging — instant chat as well as email — is today marked by massive centralization of power in the hands of a few operators. Even email, though designed as a federated system, often offers little privacy in practice: protection is not always on by default, nor easy to turn on. Metadata about who talks to whom, when, and often from where, usually remains exposed on the tools most people use every day.
This dossier presents FLOSS alternatives to mainstream messengers — federated XMPP and Matrix clients, email-based chat, peer-to-peer and mesh tools, and off-grid radio. NGI / NLnet funded parts of this stack; the pages below stay on what each project does.
Bortzmeyer (2018) is blunt that the Internet already is messaging among humans — email and other direct channels, not only the Web — and that privacy is the right to control what you expose; without it, freedom of expression is at risk (see Sources). Federation, mesh, and end-to-end encryption in this dossier are the practical answer: who talks to whom should not be a platform log by default.
Metadata as the product. Even when message bodies are encrypted, who talks to whom, when, and from which network is still a log on someone else's server. That graph is enough to map a newsroom, a union, or a family.
Phone-number identity. Sign-up that requires a mobile number ties the account to a SIM, a real-world billing identity, and often to contact-discovery of everyone else in the address book.
Single operator, single outage. One company's servers, ToS, or jurisdiction can silence a whole contact list. There is no second homeserver to migrate to.
Closed clients and closed servers. You cannot audit what the app uploads, and you cannot run the same protocol on hardware you control.
No path when the internet is gone. Cloud chat dies with the uplink. Crisis, protest, and field work need sync over radio, Bluetooth, or delay-tolerant mesh — not only HTTPS to a datacentre.
Client-side scanning and chat control. Mandates to scan private messages on the device — sold as child protection — turn every phone into a sensor before encryption can help. The CCC (2025) calls on governments to reject chat control rather than normalize scanning of private correspondence (see Sources).
Encryption as infrastructure, not a feature flag. The Internet Society treats strong encryption as essential for privacy and free expression online — not an optional upgrade vendors may weaken under pressure (see Sources). End-to-end by default, and no backdoors, is the baseline this dossier assumes.
Everyday chat is how coordination happens. Waiting for a better WhatsApp privacy whitepaper does not give you federation, and it does not survive a ban or a fibre cut.
Practical alternatives exist now: federated XMPP and Matrix clients, email-based chat, peer-to-peer and mesh messengers, and open radio. None is a drop-in for every group. Together they change the default from “one company's identity graph” to “an address you can take with you”.
The projects in this dossier each target specific harms of centralized messaging. None replaces every proprietary app overnight, but together they show how inspectable messenger code, federation, peer-to-peer sync, and end-to-end encryption can reduce dependence on a single operator:
| Dino offers a polished desktop client for XMPP instant messaging with end-to-end encryption options. Federation lets communities choose their own server or run one locally, rather than routing every contact through one company's identity graph — though trust and metadata still depend on the homeserver operator you pick. | |
| Briar Desktop synchronises encrypted messages directly between devices without a central server. When the internet is unavailable it can sync over Bluetooth, Wi-Fi, or removable media; when online it can use the Tor network — reducing exposure to server-side metadata collection and outages that silence centralized apps. | |
| Qaul is a delay-tolerant mesh messenger for off-the-grid and emergency use. Configurable, verifiable P2P channels support open discussions, trusted information feeds, and distributed spam protection without requiring always-on cloud relays. | |
| Conversations is a mature Android messenger for federated XMPP with end-to-end encrypted text, media, and voice messages — plus standards-based audio and video calls. Users can pick or run their own server instead of locking contacts into one company's app. | |
![]() |
Kaidan is a user-friendly cross-platform XMPP client (kaidan.im) with OMEMO encryption and audio/video via QXmpp — so desktop and mobile users can join the same federated network without a vendor silo. |
| NeoChat is a cross-platform Matrix messenger from KDE. End-to-end encryption in the client via libQuotient means private and professional chats on open federation need not stay plaintext or tied to a single vendor's closed app. | |
| Monal is an XMPP messenger for iOS and macOS — the Apple-platform counterpart to Conversations. It ships OMEMO encryption and audio/video calls, so people on iPhone and Mac can join the same federated network without a closed vendor app. | |
| Delta Chat turns an ordinary email address into an instant messenger. Chats are end-to-end encrypted with Autocrypt / OpenPGP and can run on regular mail or dedicated chatmail servers. Related work includes a lighter desktop client (Delta Tauri) and WebXDC apps that travel inside the chat. | |
| PulzeLab C1 is a handheld LoRa mesh messenger: small packets over open UHF ISM bands, no cellular or internet operator in the path. An affordable, durable device lets people join a mesh without a phone contract — everyday use and crisis comms on low-power radio rather than a central chat server. | |
| MAGNET Communicator is an open-hardware short-range (up to 3 km) voice radio using MANET — no base station and no licence. Schematics, firmware, 3D-printable enclosure, and assembly docs use permit-free parts so the device stays repairable when cellular infrastructure is gone. | |
| TETRA BlueStation is a FLOSS TETRA base-station stack aimed at a usable station on about €200 of hardware, so surplus handheld TETRA radios can carry voice, text, and IP without vendor lock-in — one cell or a network of stations linked over the internet. |
Browse the projects in this dossier below.
Beyond the projects above, several widely used FLOSS tools shape everyday messaging — from mobile chat apps to Matrix clients and self-hostable team platforms. They are a common step away from purely proprietary services, but each still comes with structural limits.
Signal ships open clients and strong end-to-end encryption. As of 2026, sign-up still requires a phone number, but usernames and default number privacy mean you need not share that number with contacts; discovery by number can be restricted. The service nonetheless depends on centrally operated Signal servers — availability and much metadata remain tied to that infrastructure.
Session routes messages over onion-style networks without a phone number, which improves anonymity compared with mainstream apps. Users still rely on the project's network design and release cycle rather than direct peer-to-peer delivery between contacts.
SimpleX Chat has no user identifiers — not even usernames. Contacts exchange invitation links or QR codes; messages go through relays that cannot look people up by account. Users still depend on those relays and the project's own clients rather than a classic federated address.
Jami is a GNU P2P messenger for chat, audio, and video. There is no central account server and no phone number: identity lives on the device. Connectivity still depends on DHT and TURN helpers when peers sit behind NAT, so it is not a complete substitute for a well-run federated server.
Element is the Matrix client most people actually meet first — web, desktop, and mobile, with optional end-to-end encryption. Federation can reduce single-vendor lock-in, but most accounts still live on a large public homeserver such as matrix.org, so trust and metadata shift to that operator. Element is developed by a company that also sells hosted Matrix; the clients are FLOSS, the default path is not self-hosted.
FluffyChat is a Matrix client: open federation can reduce single-vendor lock-in, but most people depend on a homeserver they do not run — often a large public instance — so trust and metadata exposure shift to that operator.
Mattermost can be self-hosted for teams, which helps organisations keep data under their own control. In practice many deployments sit behind central IT, target workplace collaboration, and do not offer end-to-end encrypted private chat by default.
These projects show what “FLOSS messaging” often means in the field: inspectable code with remaining reliance on central or hosted infrastructure — useful, but not a full substitute for decentralized, metadata-resistant designs.
Most people still chat on proprietary messengers whose clients and servers are not fully inspectable or self-hostable. They are included here as reference points — not recommendations — because their defaults illustrate the centralization and metadata exposure this dossier tries to reduce.
WhatsApp advertises end-to-end encryption, but Meta still collects extensive metadata, ties accounts to phone numbers, and operates the sole authoritative server infrastructure.
Telegram is widely used for groups and channels, yet default chats are not end-to-end encrypted, server code is closed, and users depend on Telegram's centralized service for availability and account recovery.
No single app here replaces WhatsApp for every contact list. Choose the risk you actually have:
Side-by-side tables: tools comparison.