fireplace. Download
ENCRYPTION, EXPLAINED

From Alice to Bob, step by step.

Every message is locked on the sender’s phone and only unlocked on the receiver’s, with post-quantum protection built in. Click through to watch one message travel from Alice to Bob.

ALICE’S PHONEFIREPLACE’S SERVERSBOB’S PHONEprivate keyprivate keyAlice’s padlockBob’s padlockBob’s padlockseal okshared secretsame secretmessageone-time keyfor this messagesealed boxone-time keyburnedcan’t open itone-time keyrebuiltmessagenot alteredone-time keyburnedfresh keysfresh keys

Every phone makes a pair of keys

Alice’s and Bob’s phones each make a private key (it never leaves the phone) and a public padlock (anyone can use it to lock a message that only the private key can open).

X25519 + ML-KEM-768 key pairs, certified by Ed25519 + ML-DSA-65 identity keys

Padlocks go to Fireplace, private keys never do

Both phones hand their padlocks to Fireplace so people can find them. Fireplace stores padlocks only. It never has a key.

public keys + signed prekeys uploaded; private keys stay on the device

Alice fetches Bob’s padlock and checks his seal

Each padlock carries Bob’s seal, which only he can make. Alice’s phone checks it. If anyone had swapped in a fake, the seal would not match and she would be warned.

hybrid digital signature: Ed25519 + ML-DSA-65

Alice makes a secret only she and Bob can make

Her phone mixes her private secrets with Bob’s padlock using two kinds of maths: today’s proven kind and a newer quantum-proof kind. Fireplace is not involved and never sees the result.

hybrid key agreement (PQXDH-style): X25519 + ML-KEM-768, combined with HKDF-SHA-256

Alice makes a one-time key for this message

From the shared secret her phone makes a one-time key: a key that will lock this one message and nothing else. Alice writes her message.

message key derived from the symmetric ratchet chain (HKDF-SHA-256)

She locks the message, then burns that one-time key

The message goes into a sealed box locked with the one-time key (it also shows if anyone tampers with it). Then the phone burns the one-time key, so even Alice can never reopen the box.

AES-256-GCM encryption; the message key is deleted after use (forward secrecy)

Fireplace carries a box it can’t open

Fireplace can read the label (who it is for, when it was sent, roughly how big) but not what is inside. It has no key and cannot make one.

ciphertext + metadata only; no keys on the server

The box reaches Bob

The sealed box is delivered to Bob’s phone, one box for each phone he has.

one encrypted envelope per device

Bob’s phone rebuilds the same one-time key

Using his private key and the details printed on the box, Bob’s phone works out the same shared secret and from it the same one-time key. Nobody else can.

same hybrid key agreement on Bob’s side: X25519 + ML-KEM-768 → HKDF-SHA-256

Bob opens it, then burns that key too

The key opens the box, the phone checks nothing was altered, and the message appears. Then Bob’s phone burns that one-time key as well.

AES-256-GCM authentication tag verified; key deleted after one use

Every reply uses fresh keys

Whenever the conversation changes direction, both phones make brand-new keys and delete the old ones. A stolen key could open one message at most, and the chat heals itself.

hybrid double ratchet: new X25519 + ML-KEM-768 keys; post-compromise security
POST-QUANTUM

Built to stay private against quantum computers

What it means

A large enough quantum computer could break the public-key cryptography most messengers rely on today (X25519, Ed25519). Post-quantum cryptography is different maths, designed to resist quantum and ordinary computers alike.

Why it matters now

Attackers can record encrypted traffic today and open it years later, once the hardware exists. Fireplace protects conversations against that from the very first message.

How Fireplace does it

Every key exchange and every signature is a hybrid of a proven algorithm and a post-quantum one. An attacker would have to break both.

The standards

  • Key exchange: X25519 + ML-KEM-768 (NIST FIPS 203), combined with HKDF-SHA-256
  • Signatures: Ed25519 + ML-DSA-65 (NIST FIPS 204). Both must verify.
  • Messages: AES-256-GCM and SHA-256, which stay strong against quantum computers with 256-bit keys.

The post-quantum code is checked against NIST’s published test vectors.

THE DOUBLE RATCHET

Fresh keys for every message

What it is

A ratchet is a gear that only turns one way. The double ratchet, designed for Signal, gives every message its own key and keeps replacing the keys, so a stolen key is only ever useful for a moment.

How it works

Each message key comes from a one-way chain (HMAC-SHA-256), is used once and is deleted. Whenever the conversation switches sides, the replying phone also makes brand-new keys and mixes them into the chain.

How Fireplace implements it

We extend it with post-quantum maths: every switch adds a fresh X25519 and ML-KEM-768 exchange, so quantum protection keeps renewing. Message headers and both phones’ identities are bound into AES-256-GCM, so altered, replayed or misdelivered messages are rejected, and a forged message never changes the saved state.

What it ensures

  • Forward secrecy: messages already processed stay unreadable if your phone is later compromised.
  • Post-compromise security: if someone copies your keys, the chat heals itself once both sides have replied, usually within two round trips.
  • Independent keys: one compromised key opens one message, not the conversation.

Limits that apply to every messenger: Fireplace can’t control what happens outside the app. That includes a phone in an attacker’s hands, copies of messages already on other people’s phones, and a first chat with someone you haven’t verified by comparing safety numbers. A stolen password also lets someone sign in as you, though they can’t read your earlier chats and your contacts are warned.

WHAT SERVERS SEE

What Fireplace can and can’t see

Fireplace’s servers can see usernames, which accounts talk to each other and when, and roughly how big each message is. They can’t see what your messages say, your private keys or your history, which stays on your phone.

To be sure you are really talking to Bob, compare a safety number (or scan a QR code) when you meet. Fireplace pins each contact’s identity and blocks sending if it ever changes.