Hey is a native Android app for chat & social — where the server is your device. No company in the middle, no account on someone else's database. Just you, your keys, and your people — powered by the ElastOS Internet OS.
ElastOS is a “World Computer” — a local operating-system layer (the Runtime), a peer-to-peer network (the Carrier), and self-sovereign identity (DID). Apps run as sandboxed capsules; the Runtime decides exactly what each one is allowed to touch. Hey is one of those apps — so everything Hey does inherits ElastOS's guarantees: your data stays yours, and the network stays hidden.
Most apps are thin clients to a company's servers. Hey is the opposite: the ElastOS Runtime and the Carrier are compiled into the app and run in-process, on your phone. Your device is the node — it holds your keys, signs your posts, stores your data, and talks straight to your friends' phones.
A mini ElastOS Runtime + Carrier boot inside the app. There is no “Hey server” to go down, get hacked, or read your messages.
Your identity is a self-sovereign did:key generated on-device. No email, no phone number, no account — it signs everything you create so others can verify it's you.
A foreground service keeps the Carrier alive so messages arrive in the background. Notifications are local — no Firebase, no Play Services. Works on GrapheneOS.
Post photos and videos to a beautiful frosted feed. Tap a card to swipe a multi-photo gallery, pinch to zoom, like and comment in threads, and save what you love. Every post is signed by you and travels straight to your followers over the Carrier — no algorithm, no ads, no company deciding who sees it.
Every message and photo is sealed end-to-end with post-quantum cryptography before it ever leaves your device. Even when traffic has to pass a relay, the relay only ever sees ciphertext — never your content.
ML-KEM-768 + X25519 hybrid key exchange and ChaCha20-Poly1305 sealing, with a Double Ratchet on direct messages — secure today and against tomorrow's quantum computers.
Your private keys live in the app's sandboxed storage, which Android encrypts at rest. Nothing is uploaded to a company. An optional fingerprint/StrongBox lock adds another layer.
Hey runs as a capability-secured capsule. It can only touch what it's explicitly granted — and other apps on the phone can't read its data.
A Hey invite carries your post-quantum keys, so following someone also establishes a private, DM-capable channel — verified by their signature, no server vouching required.
Hey carries a self-custodial wallet from a single recovery phrase — Elastos, the major EVM chains, and a real privacy coin. Keys never leave your phone; for BEAM, neither does your node. Hover a coin to learn more.
Amounts, sender and receiver are hidden — by design, not opt-in. BEAM is built on Mimblewimble + Lelantus: a payment reveals no balance, no address, no graph. It isn't a mixer bolted on — confidentiality is the protocol.
Self-hosted on YOUR phone. Hey runs its own BEAM node on-device and syncs straight from the network over loopback — no third-party node, no explorer, no company ever sees your wallet or your IP. Most “private” wallets still phone home to a server; this one doesn't.
Get tipped privately. Your reusable confidential donation address can be shared right from a post or a chat — supporters send you BEAM and the amount stays between the two of you.
The native coin of Elastos — the World Computer Hey is built on. Its mainchain is merged-mined with Bitcoin for security. Send & receive ELA, signed on-device.
Elastos's EVM sidechain — ELA-powered smart contracts with full Ethereum tooling. Hold ELA and ERC-20 tokens; send with on-device signing.
Ethereum mainnet and its tokens, including stablecoins like USDT & USDC. The same recovery phrase derives your address across every EVM chain.
Coinbase's fast, low-fee Ethereum L2. Hold ETH and ERC-20s and transact directly in Hey — handy for cheap, quick on-chain payments.
A single 12-word recovery phrase derives every address — Elastos, EVM and BEAM. Generated and held only on your device: nothing custodial, nothing uploaded.
Tipping is by identity, not address: follow someone and you can support them — including in private BEAM — straight from a post or a chat. Your keys, your coins, and for BEAM, your node too.
There are no IP addresses, ports, or gateways anywhere in Hey's code. The app addresses everything by name, and the Runtime + Carrier resolve it — quietly handling the network underneath. Four schemes, and nothing else is reachable:
localhost://WebSpaces/hey/<cid>.elastos://content, elastos://peer, elastos://did.A photo in your feed is addressed as localhost://WebSpaces/hey/<cid> — a handle on your personal drive.
The Runtime resolves it to bytes through the content provider. The app never sees an IP, a port, or a gateway. The network is simply… hidden.
A relay is only a matchmaker: it helps two devices find each other and punch through firewalls. The instant they connect, your devices form a direct peer-to-peer link and data flows device-to-device — the relay steps aside, and it's always end-to-end encrypted so even a relay only ever sees ciphertext. When either side has a real public address — a public IPv4 or a global IPv6 — the relay leaves the path entirely. Nothing hosts it, nothing carries it: your chats, your feed, your metaverse run device-to-device, owned by the people on it.
Finds your friend's device and helps both sides punch through NAT/firewalls. It never stores your account or messages.
Your two devices form a direct peer-to-peer link. With a real public IPv4 or a global IPv6 on either end — common on home Wi-Fi and many mobile carriers — data goes straight device-to-device: no relay, no server in the path.
Everything is encrypted with ML-KEM-768 + X25519. If a relay must carry it, it only ever sees ciphertext.
Relay use isn't a leak — it only ever moves ciphertext. But the goal is no relay at all, and on a public IP or global IPv6 that's exactly what happens: introductions aside, the relay is gone from the path. The result is a network — feed, chat, world — with no host but its users: a metaverse you own, not one you log into.
Because your devices talk direct, so does everything they carry. Video and voice flow straight phone-to-phone over the same end-to-end encrypted link — there's no media server, ever, and when a direct path exists (a public IP or global IPv6, common on Wi-Fi and mobile) no relay at all. The picture and the sound never touch a company's cloud.
One-to-one and group. Video and audio ride QUIC streams straight between devices — encrypted end-to-end, carried by no one. Group calls mesh peer-to-peer, with no conferencing server doing the mixing.
Send any file, any size — photos, full-quality video, archives — straight to your friend's device. Large files stream directly between phones (hash-verified), never staged in a cloud and never throttled by an upload cap.
The same post-quantum seal as your chats: ML-KEM-768 + X25519. A relay that ever introduces the two sides sees only ciphertext — never your face, your voice, or your files.
No TURN servers, no media relays, no “fair-use” transfer caps. The call and the files are between you and the person you called — and nobody else is in the room.
The Carrier is a blind courier. It shunts sealed envelopes between devices and knows nothing about them — not who sent one, not who it's for, not what's inside. There are no DIDs on the wire: a conversation rides an opaque per-pair handle, and the body is post-quantum ciphertext only the two endpoints can open.
The sender's DID is encrypted inside the envelope. A relay can't tell who sent a message — only the recipient learns that, after decrypting.
Conversations travel on an opaque 256-bit queue handle the two participants derive privately — not your identity. The Carrier routes a number, never a name.
The body is ML-KEM-768 + X25519 sealed. A relay that carries it — or anyone sniffing the wire — sees random bytes and nothing more.
No accounts, no directory, no server logs to subpoena. The most a relay can observe is that some opaque envelope moved, and when — never who, to whom, or what.
HeyVerse is a living 3D world built right into the app. Invite a friend the way you'd start a call; they walk into your space, and you see each other move, sit, chat and explore in real time. There is no game server anywhere — the world renders on each device and stays in sync peer-to-peer over the same Carrier that carries your messages.
HeyVerse on the phone — your avatar, your world, kept in sync peer-to-peer. No game server. Save a capture to docs/heyverse.png to show the real render in the frame.
The whole 3D engine ships inside the app and runs locally — no streaming, no cloud render, no logging in to anyone's world server. You own the client and the world both.
Position, turning and sitting fan out ~15×/second over an ephemeral gossip namespace — never the chat lane, never disk. With a public IP or global IPv6 it travels device-to-device with nothing in between, so it feels instant.
A friend is present exactly as long as they're connected. Walk out — or close the app — and you simply leave each other's world. Nothing is stored, nobody is tracked, there is no history to mine.
Your chat stays end-to-end encrypted; movement is ephemeral and unsealed — it's only "where am I standing right now," so it's free to be fast. Same principle as the rest of Hey: the relay just introduces, then steps aside. When both sides are reachable, the world has no host at all — a metaverse owned by the people walking through it, not one you log into. Proven on real hardware: a phone on cellular and a phone on home Wi-Fi, moving together, direct · no relay.
Hey is what social media looks like when there's no company in the middle — just your phone, your keys, and the people you choose. Powered by ElastOS.