BurnPony

com.burnpony.android
by Zapstore _@zapstore.dev

Republished from GitHub / F-Droid by the Zapstore main account.

Send a private, encrypted note that self-destructs — a secure secret message the other person opens with one link, no account and no app. Write a note, set the self-destruct rules, share one link. The note is encrypted on your device with AES-256-GCM before anything is uploaded, and it decrypts only in the recipient's browser. The decryption key travels in the part of the link after the #, which browsers never send to any server — so the server stores ciphertext it cannot read, plus a note ID, a view count, and an expiry. No accounts, no names, no analytics. WHAT YOU CONTROL • Views: burn after 1 reading, or allow up to 100 • Expiry: 5 minutes to 30 days, changeable later, counted from now • Optional passphrase, stretched with PBKDF2 and mixed into the key — send it through a different channel than the link • Auto-hide: the revealed note re-hides after a timer • Read receipts, disclosed to the recipient before they reveal the note — BurnPony does not do silent read tracking • A private label for your own list; it never leaves your device • QR code for in-person handoff: the whole link, key included, transfers with no network at all • Disappearing messages done honestly: one-time view links, temporary notes, password-protected sharing HONEST LIMITS Whoever has the full link (and passphrase, if set) can read the note. A recipient can always copy or photograph a note while it is visible. Self-destruction limits future access; it does not control the moment of reading. OPEN The app, the server, the viewer, and the wire-format specification are open source (Apache-2.0), with cross-implementation test vectors shared with the iOS app and the web viewer. Self-hosters can point the app at their own server from Settings. Protocol: https://burnpony.app/protocol BurnPony is part of the pony family of privacy tools: encryption you can inspect instead of taking a developer's word for it.

First release: Aug 1, 2026, 2 total releases.

Most recent release: Aug 25, 2026.

Website Repo

Appears in 0 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Aug 25, 2026 1.4.0
    # BurnPony 1.4.0 ## Route BurnPony through Tor or a SOCKS5 proxy Settings has a new Proxy section. Choose Off, Orbot for one-tap Tor, or a custom SOCKS5 host and port. When a proxy is on, every relay request goes through it: creating a note, checking status, burning, changing expiry, and push registration. The destination is resolved by the proxy rather than on the device, so the relay hostname does not reach your local resolver while a proxy is active. When a proxy is enabled and unreachable, requests fail instead of quietly falling back to a direct connection. There is no silent direct path. ## Stream isolation
    More…
    The Proxy section takes an optional username and password. With Tor, any pair puts BurnPony on its own circuit, separate from other apps sharing Orbot (Tor's IsolateSOCKSAuth). For a SOCKS5 proxy that requires a login, use its credentials. The SOCKS5 client is BurnPony's own, so it offers exactly the method in use and sends the destination as a domain name for proxy-side resolution. The username and password path is verified against Tor. It has not been exercised against a third-party authenticated SOCKS5 proxy, which uses the same handshake. ## For F-Droid This is the first release published to F-Droid since 1.0.1. It also carries the accessibility, language, and reliability work from the versions in between. ## Verify this build Whole-file SHA-256 (is this download the published file): ``` 2995fe5109326478d54a20a6dc603c77e2ed6833dcac4cde53aa4221767d3852 ``` Content hash (for rebuilders; excludes signature, see REPRODUCIBLE_BUILDS_PLAYBOOK.md): ``` 7b046211a530d87e46cc0701633dc898f528a0ccac9cb04bdf4c45295f33d180 ``` The APK is signed with the NorseHorse release key; the detached signature is attached to this release.
  • Aug 1, 2026 1.0.1