NostrVault

com.nostrvault.app
by Logen logen@btcforplebs.com

A Nostr client with a built-in Haven relay and Blossom server

NostrVault is a self-custodial Android Nostr client with your own relay and media server running directly on your device. Most Nostr clients are a window onto someone else's relay. NostrVault is the relay. A full Haven relay runs on your phone, so every note you write and every note you receive is written to storage you own before it goes anywhere else. If every relay you use disappeared tomorrow, your copy would still be on your device. HOW IT WORKS The app runs a personal relay on-device with five separate stores: an inbox for what people send you, an outbox for what you publish, a chat relay for private messages, a private relay only you can read, and a local feed cache. Your posts are written locally first, then broadcast outward to public relays on your terms. Incoming events are pulled in and kept. Because the relay is yours, notifications are generated entirely on-device from your own event stream. There is no push server — not Google's, not ours. Nothing about who contacts you, or when, is visible to a third party. A Blossom media server runs alongside it, so images and video you post are hosted from your own device and mirrored to external Blossom servers you choose, instead of being uploaded to someone else's host by default. A Web of Trust filter, built from your follow graph, decides what the relay accepts, which keeps spam out of your own storage rather than filtering it after the fact. FEATURES - Personal Haven relay on-device (inbox, outbox, chat, private, feed cache) - On-device notifications with no push server - Blossom media server with mirroring to external servers - Full client: feeds, threads, profiles, media gallery, NIP-50 search - Encrypted direct messages, both NIP-17 gift-wrapped and legacy NIP-04 - Remote signing via NIP-46 and Amber (NIP-55) — your key never enters the app - Multi-account with biometric protection and NIP-49 encrypted key storage - Lightning zaps with receipt validation, and an integrated NWC wallet - Cashu ecash wallet with relay-backed backup (beta) - Picture-in-Picture video - Efficient relay sync using NIP-77 negentropy reconciliation SUPPORTED NIPS 01 basic protocol · 04 legacy encrypted DMs · 05 DNS identifiers · 09 event deletion · 10 threading · 11 relay information · 13 proof of work · 17 private DMs · 18 reposts · 19 bech32 entities · 29 relay-based groups · 40 expiration · 42 relay authentication · 44 versioned encryption · 46 remote signing · 47 wallet connect · 49 encrypted key storage · 50 search · 51 lists · 55 Android signer · 56 reporting · 57 zaps · 59 gift wrap · 60 Cashu wallet · 65 relay list metadata · 70 protected events · 77 negentropy sync · 92 media attachments · 94 file metadata Blossom: BUD-01, 02, 03, 04, 06, 14 Your data, your relay, your media — all under your control.

First release: Jun 13, 2026, 4 total releases.

Most recent release: Aug 4, 2026.

Website Repo

Appears in 2 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Aug 4, 2026 2.6.0
    # NostrVault v2.6.0 (Build 14) Release Notes The headline fix is for Android 10, 11, 12 and 13: on those versions the relay never actually started. It failed silently and reported itself offline, with nothing to indicate why. This release also closes a hole that let anyone fake zap totals, stops private message send times leaking, repairs authentication on the local relay, and ends the sync loop that fired a notification every minute. ## Security * **Zap Totals Could Be Faked**: A zap receipt is an ordinary Nostr event, and the app counted every one it saw without checking it. Anyone able to reach a relay your app queried could publish a receipt claiming any amount against any note or profile. Receipts are now validated against the recipient's Lightning provider. Validation fails open when that can't be determined, so legitimate zaps are never dropped. * **Private Message Send Times Leaked**: Private messages were stamped with the true send time instead of the randomized timestamp the spec calls for, so anyone watching relays could tell exactly when you sent one. Now randomized, matching iOS. ## Improvements
    More…
    * **Catch-Up Sync Slowed to a Sane Interval**: The default moves from every 60 seconds to every 15 minutes, with a hard minimum so an old saved setting can't bring the old behaviour back. This was also firing a notification a minute. * **Default Relay List**: `relay.damus.io` was removed from the defaults after it began refusing sync queries and rate-limiting connections. Relays you configured yourself are untouched. * **Matching Version Numbers**: macOS, iOS and Android now all report 2.6.0 (14), instead of three different version numbers for the same release. ## Bug Fixes * **Relay Never Started on Android 10–13**: The background service asked the system for a service type that only exists on Android 14 and later. On Android 10 through 13 the system rejected that request, the error was caught and turned into a normal-looking "offline" state, and the relay simply never ran. If you are on one of those versions, this is the update that makes the app work at all. Android 14+ was unaffected. * **Authentication Broken on the Local Relay**: The relay checked authentication against a secure address while Android serves the local relay unencrypted, so authentication always failed and every read requiring it was silently rejected. * **Posting With Media Failed on the First Try**: Uploads nearly always failed once and worked on retry, because the default mirrors had gone dead and the Mac relay mirror was asleep until the failed attempt woke it. Mirrors are now warmed when the composer opens and the upload retries once. The app also no longer quietly embeds an unreachable local link in a note when every mirror fails — it reports the failure. * **Replies Not Notifying Everyone in a Thread**: Replies only tagged the person you replied to, leaving everyone else in the conversation out. * **Replies Vanishing From Their Own Threads**: In threads with seven or more participants, short replies tripped the mention-spam filter and disappeared — including your own. * **Reposting Articles**: Long-form articles were reposted using the note-only event kind, producing something most clients ignore. Reposts were also missing the relay hint and original author tag. * **Profile Notes Fetched From the Wrong Relays**: Loading someone's notes queried the relays they *read* from rather than the ones they publish to, so profiles could look emptier than they are. * **Blocking Didn't Take Effect Until Restart**: Blocking hid content from view immediately, but the relay was never told, so it kept importing and notifying about that person all session. * **Notifications for Old Backlog**: Catching up on old events could light the activity dot and fire notifications as if they were new. * **Stale Values in Dashboard & Feed Settings**: The cache location, cache duration, feed relay list and autoplay toggle never refreshed, so those screens could show outdated settings after you changed them. * **A Single Bad Setting Could Prevent Startup**: A malformed or blank value in the relay's configuration — twenty settings qualified, including the relay port — made the app quit during startup with no error and no crash report. Bad values now fall back to their default. * **Release Build Was Broken**: The app had not compiled from a clean checkout since 2026-07-16, after a relay-list cleanup left an incomplete statement behind.
  • Jul 6, 2026 1.2.0
    # NostrVault v1.2.0 (Build 5) Release Notes This update removes the remote push server entirely — notifications are now generated fully on-device from your own relay — adds Picture-in-Picture video, and fixes a Web of Trust bug that was causing real replies and reactions to go silently missing. ## Key Features * **No More Push Server**: Every notification — mentions, replies, DMs, zaps, reactions, reposts — is now generated entirely on-device from your own embedded relay. Nothing about who's contacting you, or when, ever passes through a third-party server — not Google's, not ours. * **Picture-in-Picture Video**: Full-screen video now supports PiP — swipe home or tap the PiP button and it keeps playing in a floating window. A new unified control rail (play/pause, time, scrubber, mute, PiP) auto-hides while playing. * **Catch-Up Summary Notifications**: Coming back to the app after being away now shows one clean "N new notifications" summary instead of a flood of individual pushes.
    More…
    ## Improvements * **Per-Account Notification Accuracy**: On multi-account setups, notifications now apply the correct account's preferences and open the correct account, instead of guessing from whichever one is currently active. * **Blossom Dashboard Backup**: The "Backup" button now actually checks which files are missing from your mirrors and pushes only those, with real progress and an accurate backed-up count. * **Settings → About**: Now shows the real app version instead of a stale hardcoded one. ## Bug Fixes * **Web of Trust Getting Stuck**: A stale Web of Trust snapshot could silently reject real replies and reactions as untrusted for days at a time. It now checks its own freshness on launch and refreshes itself in the background when due. * **Notifications Missing After Catching Up**: Activity that arrived only through the Mac Relay catch-up sync (rather than live) wasn't triggering notifications at all. Fixed. * **Local Relay Becoming Unreachable**: Mac Relay Sync could, in rare conditions, fire repeatedly and overwhelm the local relay badly enough that posting stopped working entirely. Fixed with a cooldown between sync rounds. ## Removed * Remote push server registration and all associated plumbing
  • Jun 14, 2026 1.1.0
  • Jun 13, 2026 1.0.0