Documentation (14 pages)
Chat
Chat is a built-in part of the Tallow room, not a separate app. The module’s tab bar carries three working surfaces — Send, Receive, and Chat — and chat rides whichever room session is already live.
Starting a Chat
Chat pairs on its own: no files required.
- Select the Chat tab
- Choose Start a chat — a room code and share block appear (Copy code, Copy link, QR)
- Send the code or link to the other person
- They select Chat → Join with a code and enter it; the conversation opens on both sides
Files can travel in the same thread: the attach control stages your picks first, then sends them as a normal offer, with each file’s state shown inline in the conversation. A chat is joined with the room code, exactly like a file room.
Encryption: End-to-end vs Transport-only
Chat follows the room’s mode, and the split is the same honest one as everywhere else in Tallow:
| Mode | Chat encryption |
|---|---|
| End-to-end encrypted | Every message is encrypted in your browser with AES-256-GCM under per-direction keys — one HKDF subkey of the room key for what you send, a different one for what you receive — so the two directions never share a nonce space, and chat nonces are domain-separated from file-chunk nonces. The relay forwards ciphertext only. |
| Transport-only | Chat is not end-to-end encrypted. Messages still ride the same room connection, but the payload is plaintext. The mode says transport-only, and the chat says so too. |
The protocol’s chat session ratchets message keys (with sparse ML-KEM re-keying carried inside the encrypted payload), and only claims post-quantum forward secrecy once a re-key exchange has actually completed.
History and Retention
- Chat history is memory-only on the relay — it keeps no message history and writes none to disk. On your own device, messages stay in your browser’s local store (encrypted at rest) so a refresh doesn’t lose the thread; clear it any time from Settings → Clear all data.
- The relay’s side of the conversation disappears when the room closes — there is nothing to recover from us. Your own device keeps its encrypted local copy until you clear it (or use the panic wipe).
- The room closes after about ten quiet minutes with no activity, like any other room.
In the Room
- Typing indicator — shows while the other person is composing
- File attachments — offer cards in the same thread, with live per-file state
- Share block — Copy code, Copy link, and QR for the join link
- Ephemeral codes — the chat code is the room code; the relay only ever receives a one-way, memory-hard Argon2id derivation of it — never the code itself
Related
- Sending in the Browser — the transfer module the chat lives in
- Security Model — algorithms, trust boundaries, and the relay’s zero-knowledge design
- FAQ — room codes, share links, and file-size limits