BlueOcean Orbit Messenger
A messenger that protects your privacy. From the EU — for you.
Send messages, share photos and voice messages, make encrypted calls — with whoever you want. Nobody can read along, not even us.
New here? The guide walks you through everything step by step. Our terms of use and code of conduct apply. Without a store: Android APK and Windows app.
This is what it looks like
Shots from the running app — for iPhone and Android. The names are made up, the app is real.
We cannot read along
Encryption happens on your device, decryption on the recipient's. In between, our server holds text we cannot read — we never have the keys.
Our own servers in Europe
No foreign cloud, no US corporation. European law, and the responsibility stays with us.
No ads, no data sharing
We earn from the app, not from you. Your data is not sold and not passed on.
Everything a messenger needs
Messages, photos and files, voice messages, groups, calls and video — encrypted, on iPhone and Android.
Free, no strings attached.
Try it right here
And here you drive it yourself: this preview is not a recording but a real interface. Tap a conversation, write something, send it.
- Open a conversation: tap Sarah, the team or Max.
- Write yourself: type at the bottom and send — the message appears at once.
- Verify devices: tap “Security” at the bottom. It shows which device is verified and where a key has changed.
This preview runs in your browser: it sends nothing and stores nothing. The messenger itself exists as a web app, as a program for Windows and as an app for iPhone and Android.
Verified on 3 August
Verified — key unchanged
Not verified yet — better ask
If a key changes, you see it here. Nothing is quietly forwarded without your confirmation.
Clickable preview. It shows how the messenger should feel — the finished version may differ. The preview itself runs in your browser and sends nothing.
Chat control — what applies to us and what does not
Chat control in its current form explicitly exempts end-to-end encrypted communication — and we do not scan anything in the first place. What a future law may bring, nobody can honestly promise you.
Read the full legal assessment
Many people ask this first. Here is the answer as precisely as it can be given today — including the one point nobody can honestly promise.
Chat control 1.0 does not affect us — twice over
Regulation (EU) 2021/1232 is a permission, not an instruction: providers may voluntarily scan unencrypted content. In July 2026 it was extended until 3 April 2028 — with one important change: end-to-end encrypted communication is now explicitly excluded. We scan nothing, and our service is end-to-end encrypted. So it misses us twice.
The keys are not with us
Encryption and decryption happen on the devices of the people involved. Our server holds text we cannot read, and we never hold the keys to it. So we do not know what goes through the service — not as a matter of principle, but because it is technically impossible.
What we do instead
Abuse can be fought without reading along: every account is tied to a verified sign-in, our terms of service forbid criminal and offensive content, and those affected can report. We handle reports the classic way — by blocking accounts and, where necessary, working with the authorities.
Only where we speak the language
Since 21.09.2026 across the whole EU plus Switzerland, Norway, Liechtenstein and the United Kingdom. The rule behind it is not a market decision: a country is added only if the app speaks one of its official languages — otherwise nobody there can read what they are agreeing to. It speaks 28, including every official language of the EU.
The point we do not promise
The planned CSA Regulation ("chat control 2.0") has still not been decided. The fifth negotiation round between Parliament and Council ended on 29 June 2026 without agreement; talks resume on 29 September 2026. On two points both sides now agree: encryption will be protected, and mandatory age verification is off the table. What remains disputed is the core question — whether and how providers can be ordered to detect. Worth knowing: the drafts contain no exemption for self-hosted or open-source services — the definition of a provider follows the type of service, not who runs the servers.
So we do not claim that we will circumvent a future law. What we can say: the risk-mitigation duties that appear in every draft — verified sign-in, clear terms of service, a working reporting path — we already meet today. And an order to hand over content is something we could not technically follow without breaking the encryption on the devices themselves. Should a law require exactly that of us, we will say so here — openly, and before it happens.
Preview: the three possible outcomes — and what each means for you
1. It passes without detection duties. Then risk-mitigation duties remain: verified sign-in, clear rules, a reporting path. Nothing changes for you — we already meet all of that today.
2. It does not pass at all. Then today's permission stays in force — the one that misses us twice. Nothing changes for you.
3. It passes with detection duties even for encrypted services. By the state of the negotiations the least likely path — both sides have already agreed to protect encryption. Should it happen anyway: we could not technically follow such an order without breaking the encryption on your own devices. You will read it here — openly and before anything takes effect, not after.
And the US providers? The difference, honestly explained
It is often said that US services are "legally required to scan". That is not accurate, and we prefer to say it precisely: US law (18 U.S.C. § 2258A) does not oblige them to search — the statute itself rules that out explicitly. It does oblige them to report what they know, with fines of up to one million dollars per violation. That is why the big providers scan voluntarily: whoever scans, knows — and whoever knows, must report.
Then there is the CLOUD Act: US authorities can require a US company to hand over data it controls — even when the servers are in Europe. Our answer to that is not a promise but construction: the operator is a European company, and we never held the keys to your messages. What can be seen in transit is text that even an intermediary cannot read.
Read it yourself, without going through us: 18 U.S.C. § 2258A, full text · Regulation (EU) 2021/1232 · State of the negotiations (EDRi) — as of 12 Aug 2026.
Which law applies to us — and which does not
We operate under European law, on our own servers in Europe. An authority gets from us what we have — and with encrypted content, that is not the text.
Which law exactly applies to us
“Wiretap-proof” is not a state any provider can promise. What a provider can state is: which law it operates under, what an authority actually gets from it — and where even we can do nothing. That is what this section is for.
Law that applies to us
- EU law — GDPR and the ePrivacy Directive.
- Cypriot law, because BOP BLUEOCEAN PRIVACY LTD is seated in Larnaca. Those are the courts and authorities with jurisdiction over us as a company.
- Where required, the law of your country — today Germany, Austria or Switzerland, because those are the only countries we currently admit.
The server location Germany is a statement about the technology, not about the company seat. Both belong stated separately — anything else would be dressed up.
Law that does not apply to us
- No CLOUD Act. It obliges US companies to hand over data they control — including data held in Europe. We are not a US company and have no US establishment.
- No FISA 702. That power is directed at US communication providers. We are not one.
- No UK order under the Investigatory Powers Act — no seat, no establishment in the United Kingdom.
This is not an attitude, it is a question of jurisdiction: each of these laws needs a connecting factor that does not exist here.
What an authority really gets from us
Content: nothing. Your messages are encrypted on your device and become readable again only at the recipient. The keys live on the participants' devices — we never had them. An order to hand them over would come to nothing: you cannot hand over what you do not have.
Connection data: that we do have. That two accounts write to each other, when, and from which IP address — every server needs that in order to deliver. We can be asked for it, and we comply with a lawful order. We do not analyse it, and the server deletes messages by itself after 30 days. What accumulates in the meantime is set out in the privacy policy.
And the sentence that matters: we do not promise to defy a law. Such a promise would be worthless — it would hold exactly until the first order. Instead we are built so that the content never reaches us at all.
Where even we can do nothing — the four honest places
1. Your device. Decryption happens with you. Anyone who gets hold of your unlocked phone — through seizure, theft or malware — reads along without touching our server at all. That is why this page explains how to secure your device; it is not a side note, it is the weakest point of every encrypted messenger.
2. The person you write to. Every message has a recipient, and they can show it, photograph it or pass it on. No encryption helps against someone who wants to talk.
3. The path to us. In front of our server sits Cloudflare protecting the domain, a US company. It sees that a device connects from an IP address, and when. It does not see your messages — those are encrypted before they leave your device, and the key was never in transit. The same goes for your internet provider: it sees the connection, not the content.
4. The delivery services of Apple and Google. For your phone to tell you a message has arrived while the app is closed, there is no way around Apple and Google. They learn that your device is being woken and when — not by whom and not what. The wake-up call carries no content, only an identifier; your device fetches the text itself and decrypts it there. We could not send it along even if we wanted to — we never hold it in readable form. Calls work the same way: they learn that your phone is ringing, never who you are talking to.
And so that no wrong conclusion is drawn here: using a US service provider for connection protection does not place us under US law. Applicable law follows the provider — that is us — not its subcontractors. We remain a European company with no US establishment, and Cloudflare could not read along even if it wanted to.
The method, verifiable
We did not invent our own encryption. We use what has been open to scrutiny for years: the Matrix standard with Olm and Megolm (m.megolm.v1.aes-sha2). The cryptographic core is the open-source matrix-rust-sdk — the same one in the iPhone app, in the Android app and in the browser. Every device has its own keys; a new one is confirmed by symbol comparison or with your recovery key.
Why this matters: home-made encryption cannot be checked by anyone from outside. Open encryption can be checked by everyone — including against us.
Us against the others — including where we lose
Each of these was built for something. Here is what we are built for: people who have to keep quiet for a living and need a contractual partner for it.
| Signal | Threema | BlueOcean | ||
|---|---|---|---|---|
| Who you are | phone number | phone number | random ID | e-mail address |
| Who stands behind it | Meta, USA | foundation, USA | company, Switzerland | company in the EU, with a contract |
| Data processing agreement for professional confidentiality | only via the Business API | no | yes | yes |
| Protocol | closed | open | closed | Matrix, open standard |
| Calls and video | yes | yes | yes | yes, encrypted |
| The people you know are already there | yes | partly | rarely | no |
The last row goes against us, and it cannot be written away: whoever starts here is alone at first. That is why you can invite as many friends as you like — and why what still creaks on our side is written out below.
€8.99 per month
The price
€8.99 per month, VAT included. Cancel any month, effective at the end of the billing period. No minimum term, no setup fee, no fee for cancelling.
First 3 days free
After signing up you can use everything free — no payment details, for 3 days. If you do nothing after that, it simply ends. We never charge for something you did not explicitly buy.
Payment runs through the App Store or Google Play, not through us — we never see your payment details. Cancelling happens there too, with one click, at the end of the current billing period.
Voluntary, without anything in return
What it is
A voluntary contribution towards development. You receive nothing in return: no credit, no pre-order, no discount, no refund. It is not a purchase and not a contract for any service.
The only thing you get
You hear first how things are going. That includes personal invitations to events and personal conversations with us, online or in person. No entitlement arises from this.
Payment runs through Revolut. All we see is that a contribution was made and how large it was — we never receive your payment details.
What is not true today
Built, but not released yet
The messenger runs — as an app for the iPhone, as a program for Windows and in the browser. It is still not publicly released: before that, a full security pass goes through the source code. What is already finished is listed one by one under What we are building — we will name a date only when we can keep it.
For now only DE, AT and CH
We start where we can offer support in our own language. Other countries follow later.
Encryption protects the content, not everything
The server has to know who writes to whom in order to deliver. Those connection details do arise — we store them as briefly as possible and pass them to nobody.
The legal situation is moving
The planned EU regulation on chat control has not been decided. We do not promise you that we will circumvent a future law. We build so that content is technically protected — and we will say openly if that changes.