Help
Last updated: 26 August 2026
Mote is casual chat in encrypted rooms. You join with a single link — no account required. Messages are encrypted in your browser; the relay only sees opaque data.
Create a Mote
- Open the home page and confirm you are 18+ (Terms & Privacy).
- Tap Create a Mote. Optionally add a passphrase (share it separately if you use one).
- You land in a new room. The full URL — including everything after
#— is the secret.
Join a Mote
- Open the full invite link someone shared with you — or, from the home page, tap Join with link and paste the URL (must include everything after
#), or Scan QR from the host's Share screen. - Pick a temporary nickname (and passphrase if the host uses one).
- Accept Terms & Privacy if you have not already on this device.
You need a secure context: HTTPS or localhost. Plain http:// on a LAN IP is blocked so room keys cannot be stolen in transit.
Treat the link like a password
Anyone with the full link can join and decrypt that Mote. Copying only the path without the #… fragment will not work — and sharing the fragment shares the room key.
- Use Share in the room for copy + QR of the full invite.
- An optional passphrase adds a second layer for messages; it does not by itself stop someone from joining the relay room if they have the link.
Appearance
Use Light / Dark on the home page, in a room header, or in the footer. The choice stays on this device only — it is not shared with the room.
Chat
Type in the composer and send. Local bubbles show delivery status:
- Sending… / Sent — relay accepted the ciphertext. When Sent, you may also see how many other peers were online on this device at send time (not a read receipt).
- Queued — offline or the relay dropped; saved on this device and flushed when you reconnect (tap the bubble or Retry now)
- Failed — tap the bubble to retry
Tap Reply on a message to quote it in your next send. Tap React to add 👍 ❤️ 😂 🔥 or 😮 — tap again to remove yours. Tap Delete on your own chat, photos, or clips to hide them for everyone who receives the update — it is not a relay erase (opaque copies may linger in the short ring until they age out). Tap Edit on your own sent text or photo captions to patch them the same way (not a relay rewrite; queued messages cannot be edited until they send). Pin lines use Remove on the map. If you leave Chat (Map tab or another browser tab) and new messages arrive, a Jump to latest banner appears. Peer nicknames appear when others announce themselves. You may also see “is typing…” while someone is drafting.
Map pins
Open the Map tab (or the map column on desktop). Drop a labeled pin; it syncs encrypted to everyone in the Mote and shows up as a short chat line too. Event pins can include a casual time — tonight, Sat 9pm — so the pin is a when, not just a place. Tap a pin line in chat to jump to it on the map. On a pin’s details, tap Attend to toggle yourself — others see a count only, not a guest list. The relay still cannot see who is going.
Clips & photos
Record a short (~3 second) camera clip, or share a still photo (Photo button or paste an image into the composer). Type in the composer first to send a caption with the photo. Both are encrypted on your device before they leave — the relay only sees opaque ciphertext, not media files. Photos are re-encoded on your device (size capped; EXIF stripped). Clips loop muted for autoplay; tap Tap for sound to unmute. Native video controls stay available.
Huddle (hold to talk)
Hold Hold to talk for walkie-talkie audio. Only one person holds the channel at a time. The first time, you may be asked to accept ICE / network exposure for WebRTC. Same-LAN works with default settings; hard NATs may need the host to configure STUN/TURN.
People, ignore, and report
Open People in the room header:
- The room Creator (who can Clear chat or End Mote) is labeled in the list once they have announced.
- Ignore — hide that peer’s chat, pins, clips, photos, typing, and huddle audio on this device (you can Unignore later).
- Kick (creator only) — disconnect a peer from the relay. They cannot rejoin with the same peer id while anyone remains in the room.
- Report — continue to the abuse page with peer metadata (room id, peer id, nickname). Operators cannot read encrypted message content.
Save to account (optional)
Accounts are optional and stay on this device (passkey unlock):
- Home → Create account or Sign in.
- In a room → Save to account.
- Reopen saved Motes from the home account list.
Saved rooms are listed by recent activity on this device (active, opened, or saved). There is no cloud vault across phones or browsers unless you copy the invite link yourself.
Optional: tick Notify me when a saved Mote has a new message when you create an account (or later on the account panel). You only get pings for rooms you have saved. The banner is always generic — “This Mote has a new message. Open the app to read it.” — never the chat itself. iOS needs the PWA on the home screen. Production builds only (the service worker is off in local next dev).
Self-destruct chat
When you create a Mote (or later in Share, as creator), you can set room-wide chat self-destruct: after 1 minute / 5 minutes / 1 hour of quiet, or when everyone leaves. Map pins are not removed. Devices wipe chat locally; the creator also syncs a clear when they are online. Offline copies may linger until that device reconnects.
Clear, leave, erase
- Delete / Edit (on your own bubbles) — Delete hides chat, photos, or clips; Edit patches sent text or photo captions. Neither is a relay erase. Use Clear chat or End Mote for bulk options.
- Clear chat (in room, creator only) — clears the conversation for everyone in the Mote. Map pins stay. The creator is labeled in People. After you create a room, save the creator recovery code from Share — paste it via More → Restore creator on another device. Anyone can still Erase local data from the home account panel to wipe this device.
- End Mote (in room, creator only) — disconnects everyone and locks this mote id on the relay so the old invite cannot rejoin. A new link is a new room key. To keep talking, create a new Mote.
- Leave — go home; does not delete saved account data by itself.
- Home → Erase local data — remove all Motes, history, ignore lists, and consent on this browser. Cannot be undone; the relay cannot restore E2EE history.
Offline & install
If you go offline or the relay drops, sends stay queued on this device. Chat shows a clear offline banner with a Retry now action; the client keeps trying to reconnect for a long grace period. In production, Mote can install as a PWA. If you see the offline page, use Try again or wait until the network returns.
Home screen tip— A installed PWA has no address bar, so a brand-new invite is easiest from chat (tap the link), or from the app home via Join with link / Scan QR. Use the home icon mainly for creating rooms and returning to Motes you already saved on this device.
Threat model
Mote is for casual, invite-link rooms: client-side end-to-end encryption, a blind relay that forwards opaque envelopes, and no phone-number identity. “Secure” here means a defined scope — not magic.
Protects against
- Relay or hosting operators reading chat, clips, photos, pins, or huddle payloads (they see mote ids, peer ids, and ciphertext — not content)
- Passive network eavesdropping when you use HTTPS (the room secret stays in the URL hash and is not sent to the server)
- Strangers joining without the link secret (join proof is derived from the room key)
Does not protect against
- Anyone who obtains the full invite link (including
#…) — they can join and decrypt - A compromised device, malicious browser extension, or XSS on the Mote site origin
- Peers you invited (or who stole the link) — same trust as sharing a passphrase
- Metadata: that a room is active, peer counts, approximate timing or size of envelopes. Opt-in notifications add that this device’s push endpoint is watching a mote id while you are away — still not message content
- Advanced goals deferred for this MVP (e.g. Double Ratchet / per-peer forward secrecy). Messages use a room-key model
- WebRTC path risks if STUN/TURN is enabled (possible IP exposure to peers or ICE infrastructure). Default huddle ICE is host-only with consent
If the link is exposed — treat it as a password leak. Assume full read/write of that Mote. Create a new room, stop resharing screenshots of the URL, and use Ignore / Clear / End Mote / Erase local data as needed. An optional passphrase adds a second layer for message decryption; it does not by itself stop relay join if someone has the link to an open room. End Mote (creator only) locks this mote id on the relay so that invite cannot rejoin — a new Mote is a new room key.
Presence is always in-memory on the relay. Production deploys keep the short opaque message ring in Redis so restarts and empty rooms do not wipe recent envelopes; history on your device is separate. Check Status for live web/relay health (no content is exposed there).
Troubleshooting
- “HTTPS required” — open via HTTPS or localhost, not a bare LAN HTTP address.
- Cannot decrypt / join fails — confirm you have the full link (with
#) and the same passphrase the host set, if any. - No huddle audio — allow microphone permission; both peers need a working ICE path (same LAN, or the host’s TURN/STUN — VPS default is self-hosted coturn).
- Same Mote in two tabs — a warning appears; prefer one tab to avoid send conflicts.
More
Status · Privacy · Terms · Report abuse