Zerion

com.professor.zerion
by Zapstore _@zapstore.dev

Republished from GitHub / F-Droid by the Zapstore main account.

PRIVATE MESSAGING WITHOUT AN ACCOUNT Zerion is a free and open-source private messenger built to minimize metadata and remove centralized messaging infrastructure. No phone number. No email. No user account. No central messaging server. Each device runs its own Tor onion service and communicates peer-to-peer over Tor. Zerion doesn't operate a central messaging server between you and the people you communicate with. PRIVACY BEYOND MESSAGE ENCRYPTION • Communication routed through Tor • No phone number or email required • No central messaging server • No telemetry or analytics • No advertising or tracking • Open source under GPLv3 • Hybrid post-quantum cryptography PRIVATE MESSAGING & CALLING Send end-to-end encrypted messages, photos, videos, voice notes and documents. Create private groups and channels, or make voice and video calls over Tor. Calls are peer-to-peer through Tor without a central VoIP server, STUN or TURN. POST-QUANTUM PROTECTION Zerion combines established cryptography with NIST-standardized post-quantum algorithms. Cryptographic key material is continually refreshed as conversations progress, providing additional protection against future cryptographic threats. SELF-CUSTODIAL BITCOIN & MONERO Zerion includes self-custodial Bitcoin and Monero wallets. Your wallet keys remain on your device and Zerion never takes custody of your funds. BUILT FOR PEOPLE WHO NEED PRIVACY Zerion is designed for anyone who doesn't want a third party sitting between their private conversations — including journalists, sources, activists, lawyers and people living under censorship. SECURITY & PRIVACY FEATURES • Encrypted local storage • Disappearing messages • Screenshot protection • Private notifications without message previews • Optional hardened security protections • Encrypted Vault for passwords, notes and private files • Open-source code available for public inspection CHANNELS Create public or private channels with optional discussion threads. Subscribers do not receive a list of other subscribers. OPEN SOURCE Privacy shouldn't be a marketing promise. Zerion's source code is public so its implementation can be inspected, challenged and improved. Free and open source. GPLv3. Website: https://zerion.chat Source: https://github.com/zerionproject/Zerion F-Droid: https://f-droid.org/packages/com.professor.zerion/

First release: Aug 11, 2026, 13 total releases.

Most recent release: Sep 25, 2026.

Website Repo

Appears in 0 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Sep 25, 2026 3.0.14
    Zerion 3.0.14 is a corrective release for 3.0.13. It fixes account creation on devices whose key store cannot look up the app's key before it exists, and makes the build reproduce byte for byte in F-Droid's build environment. It is otherwise identical to 3.0.13. ## What is fixed - **First account on some devices.** Since 3.0.12 the app refuses to generate its Android key store key when the key store throws on the lookup of that key, so a temporary key store failure can never replace the key that existing profiles depend on. On a fresh installation there is no profile to protect, but the guard still applied, and on devices whose key store throws when a never-created key is looked up, account creation failed with "Setup
    More…
    Failed" on every attempt. Google Play's review device is such a device; 3.0.12 and 3.0.13 could not be set up there. 3.0.14 generates the key for the first account regardless and keeps the guard from then on. The dialog now names the cause. No data was ever at risk: the failure happened before any profile existed. - **Reproducible in F-Droid's layout.** The Argon2 library the app build compiles from source is packaged unstripped, like every native library, so that the pinned Tor and Monero libraries stay byte-identical; its debug sections carried the absolute build directory, so the 3.0.13 APK reproduced only from the directory it was built in. The library is now compiled without debug sections; its machine code is unchanged. The reference APK of this release is the output of `fdroid build --test` in F-Droid's own build layout, signed with the release key. Contacts on 3.0.12 and 3.0.13 keep working with 3.0.14. Tor stays at 0.4.9.13. ## Verifying this build | | | |---|---| | APK SHA-256 | `4c6a0e2f063a0e1a203ad54c1378da07900e8765889f1cb869188dd34fdfe108` | | Signing certificate SHA-256 | `d7fdb11125890d133ae89d8ba4f4331d9045e21ef01d9899a7cdee6888f704c8` | | Source commit | `7ae2d991b1f0099f79d4b9b6f10013ff65837456` | | Source tag | `v3.0.14` | | Source tree | `51e86ae4b1df48f5dca4ad5378e01a1e474b4214` | | Tor executable, arm64-v8a | `29eb99c78c803cdada5948c193308544f5c30414032c3334c3a83a124fcb9426` | | Tor executable, armeabi-v7a | `418976d0958c8b422d71126e9fe34986657b96672b4fe6059107e41a0f7b8eaa` | `release-manifest-3.0.14.json` records the same values together with the hash of every native library in the APK and the environment it was built in. `SHA256SUMS.txt` covers the attached files. The APK is the unsigned output of `fdroid build --test --on-server com.professor.zerion:31400` in `registry.gitlab.com/fdroid/fdroidserver:buildserver-trixie` (F-Droid's build layout, Tor and Monero compiled from pinned source by the recipe), signed outside the container with the same key as every previous release. `apksigcopier compare` against that unsigned output passes and every entry of the APK is identical. The F-Droid metadata for 3.0.14 is prepared and pins this commit. Full notes for every release are in [CHANGELOG.md](https://github.com/zerionproject/Zerion/blob/master/CHANGELOG.md); the limitations of 3.0.13, both fixed here, are in [SECURITY.md](https://github.com/zerionproject/Zerion/blob/master/SECURITY.md).
  • Sep 25, 2026 3.0.13
    Zerion 3.0.13 is a security release. It updates the embedded Tor to 0.4.9.13 and fixes the Tor-related findings left open in 3.0.12. ## What is new - **Tor 0.4.9.13.** Tor's security release of 23 September 2026 fixes ten tracked issues in the client, the onion-service code and relays. Eight of them are in code this app runs on every session: guard accounting, directory streams, connection setup, onion-service introduction and rendezvous, and stream isolation. The update was not yet available from the publishers of Android Tor packages, so the executable is now built in this
    More…
    repository from the signed upstream release source, with its libraries at pinned commits and the same build recipe the publisher uses. The same recipe reproduces the previously published 0.4.9.12 executables byte for byte, and F-Droid's build image reproduces the 0.4.9.13 hashes. - **Tor executable pinning.** The Tor and lyrebird executables are pinned by hash in the build, which refuses to package anything else, and the app verifies the executable it is about to start against the same pins before every start. - **In-tree Tor process wrapper.** The Tor process is run by code in this repository: the generated configuration isolates the SOCKS listener and enables connection padding from the start, a Tor process that does not stop is killed within a bound, a start that fails or is interrupted leaves no process behind, and the network screen learns of address publication from Tor itself instead of assuming it. - **Client authorization stays usable after network changes.** Tor discards the client-authorization credentials the app installs whenever its configuration changes, which the app does on every connectivity change. In 3.0.12 that left locked-in contacts unreachable after the first network change until Tor was restarted; the protected path never fell back to the open address, it was unavailable. The credentials are now re-installed after every reconfiguration. Contacts on 3.0.12 keep working with 3.0.13. ## Verifying this build | | | |---|---| | APK SHA-256 | `10d5aac1362e09fc5c2ec6032d73209177d6521a219e9c613f010ae4f0a78d2b` | | Signing certificate SHA-256 | `d7fdb11125890d133ae89d8ba4f4331d9045e21ef01d9899a7cdee6888f704c8` | | Source commit | `1d26de37314dd55b7ce8e890a6df0289add19106` | | Source tag | `v3.0.13` | | Source tree | `5063a1de1aead6c0285abfc14d9d889b0e755518` | | Tor executable, arm64-v8a | `29eb99c78c803cdada5948c193308544f5c30414032c3334c3a83a124fcb9426` | | Tor executable, armeabi-v7a | `418976d0958c8b422d71126e9fe34986657b96672b4fe6059107e41a0f7b8eaa` | `release-manifest-3.0.13.json` records the same values together with the hash of every native library in the APK and the environment it was built in. `SHA256SUMS.txt` covers the attached files. The APK is built in `registry.gitlab.com/fdroid/fdroidserver:buildserver-trixie` from the tag above, with the Tor and Monero executables compiled from pinned source in the same image, and is signed outside the container with the same key as every previous release. Rebuilding from the tag in that image reproduces the payload. The F-Droid metadata for 3.0.13 is prepared and pins this commit; their own build follows once it is submitted. Full notes for every release are in [CHANGELOG.md](https://github.com/zerionproject/Zerion/blob/master/CHANGELOG.md), and the known limitations of the previous release, all fixed here, are in [SECURITY.md](https://github.com/zerionproject/Zerion/blob/master/SECURITY.md).
  • Sep 24, 2026 3.0.12
    Zerion 3.0.12 is a security release. ## What is new - **Client authorization of your contact address.** Each pair of contacts whose apps support it moves from the open onion service to a second, authorized one. Each side generates a random X25519 key for the other and only that contact receives it, so Tor will not hand out the information needed to reach the address to anyone who cannot prove they hold the key. Once both sides have proven the new path, the pair uses it and nothing else, with no fallback to the
    More…
    open address. Removing a contact withdraws their key at once and rotates the address for the others. Contacts on an older version keep working as before. - **Post-quantum authentication at pairing.** Completing a link pairing now requires the post-quantum key behind the link, so an adversary who recovered only the classical half cannot take a peer's place. Pairing by QR code or Bluetooth gained the same hybrid protection. - **Calls.** Fixed a call that could keep ringing after the other side gave up, a self view drawn on its side, a video call reporting a camera error when the video link had been lost, and a first video attempt failing on a broken connection. Video setup now has a full minute. - **Network status** shows what Tor is really doing, building circuits or publishing your address, offers a Restart Tor button, and reports how many contacts have client authorization locked in. - **Wallets, storage and the rest of the hardening** from this quarter's internal security work, including the Monero wallet being unable to reach a node over Tor on one Android version. - **Reproducible native build.** The Monero wallet library is built from pinned source with a pinned build clock, and both libraries were rebuilt byte-for-byte in F-Droid's own build image on a different distribution. The call audio format is documented correctly for the first time: it is uncompressed 16 kHz mono PCM in fixed 20 ms frames, not Opus. ## Verifying this build | | | |---|---| | APK SHA-256 | `c02b77be7631f9830f0b2afd6c7ee601096bd4d46d59dd5d52ffa13cb3f7552e` | | Signing certificate SHA-256 | `d7fdb11125890d133ae89d8ba4f4331d9045e21ef01d9899a7cdee6888f704c8` | | Source commit | `fecfc69d7e538c0765be8545e6c5adb83ad230c2` | | Source tag | `v3.0.12` | | Source tree | `224f6c15b2ddcfcae4ac922af8e0724d61a7cc7e` | `release-manifest-3.0.12.json` records the same values together with the hash of every native library in the APK and the environment it was built in. `SHA256SUMS.txt` covers the attached files. The APK is built in `registry.gitlab.com/fdroid/fdroidserver:buildserver-trixie` from the tag above, with the Monero library compiled from pinned source in the same image, and is signed outside the container with the same key as every previous release. Rebuilding from the tag in that image reproduces the payload. The F-Droid metadata for 3.0.12 is prepared and pins this commit; their own build follows once it is submitted. Full notes for every release are in [CHANGELOG.md](https://github.com/zerionproject/Zerion/blob/master/CHANGELOG.md), and the known limitations of the previous release, all fixed here, are in [SECURITY.md](https://github.com/zerionproject/Zerion/blob/master/SECURITY.md).
  • Sep 21, 2026 3.0.11
    Reliability release for Android: reconnection after a loss of signal, a Tor upgrade, and a reproducible build of the Monero wallet library. - Coming back online after a dead spell. After a period without signal, such as in an elevator or an underground garage, the app could stay offline to contacts until it was force closed. The app now notices when a link that stayed attached stops or resumes passing traffic, tells Tor that the network went away and came back, and restarts Tor's network on its own if Tor stays stuck reconnecting. Contacts can reach you again without a restart. This fix is based on the reports we received; on-device confirmation in the exact elevator scenario is still in progress, so please report if you still see it. - Tor upgraded to 0.4.9.12. - The Monero wallet library is now built from a clean tree by the committed build script on every release, and the resulting hashes are recorded and enforced at build time. The shipped 3.0.10 library had been relinked against cached dependency archives from an earlier script revision, which is why F-Droid could not verify 3.0.10 against its published APK; the build now refuses such a cache. - Dependency verification metadata gained the checksums the unit test classpath needed, so a strict verified build of the whole test suite passes again. - Version 3.0.11 (31100). Everything else is identical to 3.0.10. Built reproducibly (F-Droid), signed with the same key as previous releases.
    More…
    SHA-256: 5b7b24ea25c2cacdcf0458486b6f4467236f9e127a7514e66ff0246f52ff750f Asset note (2026-09-21): the APK attached here was republished from the same tag and release commit (6e24cdd8476b9ce96fb27ecae81203256bd52cfa), built in F-Droid's buildserver image and signed with the same key. The first upload (SHA-256 fa9380ec58e17a89e792af8439f2ae5179736b7316b306e2356d87ee37ca3c6c) was built on a Windows host; its machine code is identical, but the Argon2 helper library carried Windows build paths and a different compiler ident in its debug metadata, which F-Droid's byte-for-byte comparison rejects. Version, code, tag and signing key are unchanged.
  • Sep 10, 2026 3.0.10
    Emergency fix for the 3.0.9 update failure. - Updating to 3.0.9 could show "Zerion was unable to open the database" after signing in, on every launch. The cause was a database migration that referenced a table by the wrong name. No data was affected at any point: the failed migration rolls back completely, and your account, contacts, messages and wallets are intact. Installing 3.0.10 over the top opens the account normally. - Important: do not use the "I have forgotten my password" option to get past the error screen. That resets the account. Just install this update. - The migration is now self-healing and covered by a regression test that executes it against a real database, so this class of failure cannot ship again. - Everything else is identical to 3.0.9 (rotating pairing links, Bitcoin wallet hardening, independent text sizes, key store resilience). Built reproducibly (F-Droid), signed with the same key as previous releases. SHA-256: 6a5e301401cf4c14b415bb82ff04f712f133cbd24e283a9d2111f1ba1dca8d2c
  • Sep 10, 2026 3.0.8
    - Much lower data usage: cover traffic drops to a slow constant rate when a connection is idle, and slower still on mobile data. A new switch in Settings > Connections controls the mobile-data reduction. Active messaging is unchanged, and traffic stays fixed-size and constant-rate within each regime. - Storage cleanup: cancelled or failed media uploads no longer leave chunks behind, orphaned attachment data is reclaimed automatically (including data leaked by older versions), the database compacts itself when deletions free significant space, and channel attachment caches are garbage collected. - Vault: auto-lock timeout and hide-content settings now work, taking a photo into the vault saves the full-resolution image, unlock failures show why, and unsaved note changes warn before closing. - Fixed a crash in chats containing voice call history. - Password dialogs keep your input when validation fails, including a pasted recovery phrase. - Many polish fixes: working sign-in progress indicator, notification switches reflect the real system state, dates on older group messages, tappable links in groups and channels, faster media scrolling in group chats, and more translated texts. Built reproducibly (F-Droid), signed with the same key as previous releases. SHA-256: d6b156d9d34e851264c044e9910458133e7a0570a14ba63136c84478f770277d
  • Sep 9, 2026 3.0.7
    - Security hardening across the encrypted transport: stream replay protection on restart, stricter post-quantum ratchet state handling, and connection lifecycle fixes - Onion address rotation is now fully wired end to end - The vault asks for unlock every time you enter it and locks when you leave - New chat button inside the vault to return to the chat environment - Fixed sign in being unreadable in light theme - Language changes now apply immediately - Fixed password change accepting a mismatched confirmation - Fixed a crash after account creation on some devices - Wallet stability and documentation improvements
    More…
    Built reproducibly (F-Droid), signed with the same key as previous releases. SHA-256: 5f6cc98c598759ec15e36d0cc6722ecf90ac68670c12bfb3b3f63b872472bf63
  • Sep 2, 2026 3.0.6
    Zerion 3.0.6 - Maintenance release. Updates a bundled native library (JNA) to a build aligned for 16 KB memory pages, so the app is robust on newer devices, including Android 15. No functional changes from 3.0.5. - No messaging protocol or database change. Both people still need matching versions to message. Built reproducibly (F-Droid), signed with the same key as previous releases.
  • Sep 1, 2026 3.0.4
    Zerion 3.0.4 - Adds optional non-custodial Bitcoin and Monero wallets inside the encrypted vault. They are self-custodial: the keys are generated on your device, sealed under their own password, and never leave the phone, so no server can move or freeze your funds. All wallet network traffic goes over Tor. - The Monero wallet runs view-only at rest, so its spending key is in memory only for the moment a payment is signed. The Bitcoin wallet reviews the exact transaction before it is signed, so what you approve is exactly what is broadcast. - Adds a full Light theme option and user control over background connections, along with localisation updates. - No messaging protocol or database change from 3.0.3. Both people still need matching versions to message. Built reproducibly (F-Droid), signed with the same key as previous releases.
  • Aug 22, 2026 3.0.3
    Zerion 3.0.3 - The lost-password screen now requires typing DELETE before it can erase an account, so an irreversible wipe cannot be triggered by accident or by someone with brief physical access to an unlocked device. - A contact added over a link is now labelled Cryptographically paired instead of Verified. Link pairing sets up an encrypted channel but does not confirm the person's identity in person, and the new wording reflects that. - The disappearing-messages timer shown in a chat now updates immediately after you change it in the chat settings. Built reproducibly (F-Droid), signed with the same key as previous releases.
  • Aug 19, 2026 3.0.2
    ## Zerion 3.0.2 A broad reliability release, plus I2P fixes and twelve fully translated languages. No database upgrade from 3.0.1. ### Pairing and connections - **Remote contact adding over links is fixed.** An upgraded account could sit on "connecting" because its post-quantum handshake key was regenerated on each start instead of stored once. It is now saved once, so links stay stable. If a contact is still stuck, remove it and add it again with a fresh link. - Nearby pairing works on more devices and reports clearly when Bluetooth is off instead of hanging. - **I2P** now connects and reconnects reliably, and reports "Connected" only once it can actually carry traffic. An optional, off-by-default direct bootstrap is available for networks where Tor is blocked (it only contacts the reseed servers directly, over HTTPS with signature checks, when you turn it on and Tor cannot connect). ### Stability and safety
    More…
    - The calculator **decoy** no longer freezes while you enter the code. - Signing in works correctly when multiple profiles share a password. - Backup import shows clear, specific error messages, and documents open from the media gallery. - Numerous stuck or dead-end screens across messaging, groups and channels now behave correctly, and failures surface instead of being silently swallowed. - The network status screen reflects real connectivity in step with the Tor status. ### Translations Twelve languages are now fully translated: Simplified and Traditional Chinese, Spanish, German, French, Italian, Portuguese, Russian, Japanese, Korean, Arabic and Dutch. ### Install The attached `zerion-3.0.2.apk` is signed with the project key. F-Droid builds and verifies its own copy from source.
  • Aug 12, 2026 3.0.1
    ## Zerion 3.0.1 A fix release. 3.0.0 could fail to start and show a black screen on some installs, including from Google Play, because the app's signature self-check did not recognise Google Play's app-signing key. This release fixes startup. ### Fixed - The app no longer fails to start on Play installs. The release signature self-check now accepts both the release key and the Google Play app-signing key. - Removed a startup check that could lock the app when USB debugging was enabled, with no in-app way to recover. ### Changed - Optional hardened mode is now off by default. You can still enable it under Security settings.
    More…
    ### Build - Reproducible build from the tagged commit (`fe79e81`). ### Verify the download SHA-256 of `zerion-3.0.1.apk`: `d0e047cdca2e63b906be33ec27b7655cf61b2e1a1baf642d989550a3ed788cc0`
  • Aug 11, 2026 3.0.0
    ## Zerion 3.0.0 A major release. Zerion now works offline over an encrypted Bluetooth mesh, adds Tor bridges and an optional embedded I2P transport, and turns on tamper detection by default. Both people need this version to message each other. ### New - Offline messaging over an encrypted Bluetooth mesh. When there is no internet, nearby devices connect directly, so you can send messages, replies, and photos in one-to-one and group chats. - Tor bridges (obfs4, snowflake, meek) for connecting where Tor is blocked. - Optional embedded I2P transport. - Hardened mode with tamper detection on by default, plus an app-signature self-check on release builds.
    More…
    ### Changed - Release builds now obfuscate the app layer, and camera and media capture temporaries are securely wiped when leaving a chat. - Targets Android 16 (API 36). ### Build - Reproducible build from the tagged commit (`b8adbd0`). ### Verify the download SHA-256 of `zerion-3.0.0.apk`: `cedb8096981ace87535395989b33c968f7bb8ae5db3030fd46111bc5c8af13c9`