Gluline

The messenger that tells you exactly what it can see.

Chats, calls, files and an AI assistant. Below is the list of what stays on the server and what never reaches it. No “military-grade encryption”, and none of the other words that mean nothing.

Open Gluline Runs in your browser. Android and iPhone apps are on the way.
N Nina online Can you pick up the keys Thursday? Yes, after six. I’ll send the address 0:14 12 Tverskaya Message

What our server can see, and what it cannot

Can see

  • Your phone number. It is your identifier here, and the channel your sign-in code arrives on.
  • Who writes to whom, and when. Delivery metadata is not hidden: there is no sealed sender here.
  • The size of attachments and when you were last online.
  • The contents of chats with AI switched on. For the assistant to work at all, those messages are decrypted on our side. It is a choice you make explicitly at sign-up, and can change at any time.

Cannot see

  • The text of chats with AI switched off. Encrypted with a room key the server does not hold.
  • Your private key. Created in your own browser or phone; we hold it only in sealed form.
  • The contents of files and voice notes in those same chats: they are encrypted before they leave you.
  • What is said on a one-to-one call. The media goes directly, and is signed with your key.

What it does

01

Messaging

Direct chats, groups, channels, folders, replies, forwarding, pinned messages, and search across your whole history.

02

Calls

Voice and video, one to one and in groups. Works where UDP is blocked, too: there is TURN over TLS.

03

Files and voice

Photos, video, documents, video notes, and voice messages with transcription. Large files are encrypted chunk by chunk and never held whole in memory.

04

Glu, the assistant

Answers questions, summarises what you missed, and pulls meetings and tasks out of a conversation. Off by default: for it to read your chats, you have to say yes.

And what it does not do

A group call is not end-to-end encrypted. It runs through our media server, where the stream is decrypted so it can be fanned out to everyone on the call. One-to-one goes directly. We do not write “calls are end-to-end encrypted” without that qualification, and we will not.

Metadata is not hidden. The server knows who writes to whom, and when. If your threat model is hiding the fact of the conversation itself, you need a different tool.

The web client is weaker than the app. In a browser, security depends on the code the server hands you on every load. A guarantee against a dishonest server exists only in an app you installed once.

The full account, including the wording we are bound to keep, is in the security model and the privacy policy.

All it needs is a phone number.

Open Gluline The code arrives by SMS. We ask for your name once; you can change it later.