Technical Documentation

How HIY actually works.

This page describes HIY's architecture, cryptography, and infrastructure in detail — every claim is verified against the real app and relay code. For the short, fun version, head back to the homepage.

"HIY" is pronounced like "hi" — a nod to hi/hello.

Concept

Three principles, no compromises

HIY uses the computing power and storage of its users' own smartphones — server infrastructure is kept to a minimum instead of growing into a central data center.

◎

Peer-to-peer first

Posts, photos, and interactions are exchanged encrypted directly between devices. Lightweight relays only help with delivery when recipients are offline — no corporate data center collecting or owning your data.

◈

On-device AI Shield

Detection of AI-generated content, bot spam, and deepfakes runs 100 % locally on the recipient's device — nothing leaves your phone for the check.

◆

Real identity

Content is cryptographically signed via hardware (Android Keystore) when created. Full data ownership, no fake accounts.

Real LAN

Same Wi-Fi stays on the same Wi-Fi.

Choose "Local" as your reach, and your post leaves the device only over a direct connection on the local network — it never touches the internet, never a relay server. Devices on the same Wi-Fi find each other on their own, with no server and no manual pairing. A conversation on the same Wi-Fi stays technically exactly where it happens.

Your Feed, Your Rules

No likes. No central ranking.

What you see is entirely up to you — with local relevance lenses and a resonance reach you set for every post.

Other networks have to curate, because otherwise their feed overflows — and that curation is the algorithm. On HIY, nothing overflows. Every post carries a reach budget and fades out once it's spent. That works the same at a thousand people as at a million: the feed doesn't get longer, just more densely populated. There's no ranking — not out of restraint, but because none is needed.

5 local relevance lenses

In the "Everyone" feed, you decide what gets dialed back — purely local, nothing is ever counted or stored anywhere.

Fewer prolific posters Images only Text only Most commented My language

Resonance reach instead of a like button

You decide, per post, how many devices it reaches at most in the "Everyone" feed. No algorithm decides that, just a number you pick yourself.

Small Medium Large

Your friends always get the post — no matter which tier you pick.

Same Wi-Fi: how a post keeps traveling, device by device

In the local mesh, every hop increases the counter by 1. Once it reaches the chosen budget, active forwarding stops: no algorithm, no rankings, just a counter that keeps track.

FRIEND HOP Counter drops instead of rising You 1 2 3 4 5 6 7 8 × Stop BUDGET EXHAUSTED

Preset "Medium" = reachBudget 8. For friends of the author, the counter actually drops by 1 on every hop (a discount of 2 against a hop cost of 1) instead of rising — the post travels noticeably further because of them, never counted, never reported. Beyond that, the post stays retrievable for anyone reading along at that moment — only active forwarding stops once the budget runs out. This applies to the local mesh path.

Over the relay — for practically all delivery

Here, what counts isn't who forwards it, but how many devices pick the post up. The chosen tier sets how many devices your post reaches in the "Everyone" feed:

Small Medium · ~2.7× Large (HIY+) · ~7×

The ratios (Small : Medium : Large) stay fixed, while the absolute number grows with the network — small at a thousand users, correspondingly larger at a million. Your friends always get the post, no matter which tier you pick. And: only "Everyone" is limited at all — "Friends," "Local," and "Only me" are addressed, not broadcast, and go to everyone intended, unlimited.

Live from the "Everyone" feed

Only what's already public: posts visible to "Everyone." "Friends" posts are end-to-end encrypted and never show up here — same as everywhere outside your circle.

Live from the network
Loading…

Only "Everyone" — never Friends, Local, or Only me

One comment. Short and meant.

Every post gets one comment — 2 to 60 characters, no more. Scarcity changes the tone: if you only have one, you think about whether you need it. With HIY+, it's three comments instead of one, and that's still scarce.

The reasoning: a single, short comment forces you to pick what's actually worth saying — in line with the rest of HIY: no likes, no central ranking, no incentive to just keep typing.

Direct Messages

Private chat, WhatsApp-level — minus the corporation

Alongside the open feed, there's 1:1 chat with your friends — end-to-end encrypted with the same cryptographic building blocks Signal and WhatsApp use: X25519 key exchange and AES-256-GCM.

✉

End-to-end encrypted

Every direct message is sealed with a fresh content key and individually wrapped for the recipient — the same mechanism used for "Friends only" posts. No relay operator can read along.

⚡

Instant delivery via push

New messages arrive as a push notification, even when HIY isn't open — no waiting for the next app launch.

✓

Read receipts

You can see whether your message arrived and was read — like any modern messenger.

◆

Identical on Android and iOS

Same encryption, same behavior on both platforms — one HIY code is enough to chat across platforms.

HIY+

More room for those who want more

HIY stays free and ad-free in its base version. HIY+ is an optional upgrade — no core feature sits behind a paywall.

✦

Three comments instead of one

Normally, every post gets one comment. With HIY+, it's three — more room for you, without changing the principle: still short, still meant.

✧

High resonance reach

The "Large" resonance-reach preset is reserved for HIY+ — if you want a post to travel noticeably further, you choose that deliberately, instead of it applying to everyone automatically.

Trust & Moderation

Moderation that hides nothing

No silent deletions, no black-box bans — and your circle of friends only forms when both sides agree.

◐

Report without deleting

A post never disappears over a handful of arbitrary reports. Reports from real, mutually confirmed friends count in full immediately; reports from strangers only after a waiting period and with less weight — and the further a post has already spread (hops, comments), the more of them it takes. Only then does it get replaced with one of eight random quips — e.g. "Poof! 🎩✨ And it's gone." Every hidden report counts as a strike against the author; after three strikes, a posting/commenting ban follows (reading still works), with the duration doubling each time: 1, 2, 4, 8, 16 days.

◑

Friendship by mutual consent

A friend code never grants automatic access — it only sends a request. You're only friends once both sides accept.

◒

Signed reports, honest warning

Reports are cryptographically signed just like posts and can be traced to a real device identity. If a different identity later shows up under the same name, HIY displays a visible warning instead of silently treating it as the same person.

◓

No confirmed account, nothing goes out

Posts, comments, and friend requests all require a confirmed account through ortino.AUTH. That's the real defense against bots — not a filter that catches spam afterward, but an entry condition that applies before anything happens.

Removed posts never just vanish without a trace: every removal is logged with a timestamp and a reason in an audit log — modeled on the statement-of-reasons requirement in Article 17 of the EU Digital Services Act (DSA). A complete DSA process (including notifying the affected person and a right to appeal) isn't there yet, but it's a first building block in that direction.

Security

Cryptographically secured, not just promised

Every claim here can be technically verified — offline, on your own device, without having to trust anyone.

◓

Hardware-signed posts

Every post, comment, and report carries an ECDSA signature from the Android Keystore (where available: the StrongBox hardware chip). The signing key never leaves your device — recipients verify offline that nothing was altered afterward.

◔

Cryptographically proven verification

Anyone signing in via ortino.AUTH with a confirmed email can bind their device via proof-of-possession (an open standard, RFC 7800). No server you have to trust — every device checks this itself, offline, against a public key.

◕

Photos without location

Photos are automatically recompressed before sharing — this fully removes EXIF metadata like GPS coordinates and camera model. A deliberately verified side effect, not a coincidence.

●

Encrypted storage

Your local database is encrypted with SQLCipher (AES-256) — the key itself is, once again, hardware-bound in the Android Keystore.

◑

Continuously hardened

Went through a dedicated security pass ahead of the beta: identity spoofing on device/account switches, forged friend requests, comments without trust signals — all found and closed before real users could ever run into them.

○

End-to-end encrypted between friends

Posts visible to "Friends only" and direct messages are end-to-end encrypted (X25519 + AES-256-GCM) — no one but the recipients can read them, not even a relay operator.

◈

Two keys, two protection levels

The signing key lives in the security chip (StrongBox or Secure Enclave) and never leaves it. The key used for encryption sits next to it in protected storage — the chips simply can't do the algorithm that requires (X25519). Both stay on the device, both never leave it — only the protection level differs, and we'd rather say so than leave it unsaid.

◒

Local content check (image)

Before sharing, a purely local model checks photos for nudity and graphic violence — using Apple's own SensitiveContentAnalysis on iOS, and a bundled on-device model on Android. No photo ever leaves your device for this.

◐

Word filter at posting time

Before a post goes out, your device checks the text for slurs and threats — across all five languages on this site. A hit doesn't silently block: it shows a warning, and you choose to revise or send anyway. A word filter alone can't read context and can be evaded — it's a floor, not a wall, complementing after-the-fact reporting rather than replacing it.

Recovery

Losing your phone doesn't mean losing everything

Three separate paths — and none of them give the operator any insight.

◐

Identity

Your account, code, and friendships all hang off ortino.AUTH. You confirm a new device by email — no separate password, no recovery process of our own to build.

◑

Friends list

Optionally backed up encrypted at the relay, unlockable only with your own chosen PIN (PBKDF2-HMAC-SHA256, 600,000 rounds). Without the PIN, the backup isn't readable by us either.

◒

History

Posts and chats live locally on the device. You export them yourself, wherever you like — no cloud backup for us to manage.

The three paths are deliberately separate: recovering your friends list doesn't get anyone your history, and vice versa.

Infrastructure

The operation is watched around the clock too

HIY's relay servers and ortino.AUTH (your login) run on the same Swiss root server — automatically secured, not just when we're building features.

◍

CrowdSec — real-time attack detection

Continuously reads the access logs of every site plus the SSH logs, recognizes known attack patterns — brute-force attempts, known exploit signatures — and blocks the attacking IP address immediately via the firewall. Purely rule-based, no AI, no delay.

◔

Trivy — daily vulnerability scan

Every night, Trivy scans every running Docker image for newly disclosed security vulnerabilities (CVEs) — findings get closed promptly, before they become a problem.

◒

DB monitor — login surveillance

A dedicated monitor counts failed database logins and raises an alert on unusual patterns — an extra layer of protection below the application layer.

○

Daily report, evaluated locally

A self-hosted AI model (Ollama) summarizes the raw data from CrowdSec, Trivy, and the DB monitor into a readable report every night — running entirely on our own infrastructure, no raw data ever goes to a cloud provider.

Status

In active development

HIY is being built openly, step by step. Here's where things stand.

Live verified

P2P engine (text, LAN)

Peer discovery, gossip forwarding, live feed with no server.

Live verified

On-device text shield

Local, explainable AI detection with an adjustable sensitivity slider.

Live verified

ortino.AUTH

OAuth2 + PKCE, real names & avatars, auto-login via hardware keystore.

Live verified

Self-regulation

Trust-weighted, reach-dependent report threshold, transparent removal quips instead of silent censorship, strikes with a doubling ban duration.

Live verified

Photos in the feed

Attach, compress, P2P transfer — end-to-end confirmed.

Live verified

Signed reports & identity warning

Report signing like posts, plus a warning on name/identity changes.

Live verified

iOS

Native SwiftUI port, wire-compatible with the Android client — tested on real devices. Not publicly released yet.

Live verified

End-to-end encryption for friends

Content visible to "Friends only" is end-to-end encrypted (X25519 + AES-256-GCM, implemented identically on Android and iOS) — no one but the recipients can read it, not even a relay operator.

Live verified

HIY+ reach limit

High resonance reach (the "Large" preset) is reserved for HIY+ — prevents reach-farming without limiting basic use.

Live verified

Local content check (nudity/violence)

A purely local model checks photos for nudity and graphic violence before sharing — via Apple's SensitiveContentAnalysis on iOS, and a bundled on-device model on Android.

Live verified

Guided first-time setup

A one-time setup flow on first launch — language, friend-list backup, profile, a short feed explainer — plus a Help & FAQ page right in the menu, identical on Android and iOS.

Live verified

Direct messages

Private 1:1 chats with friends — end-to-end encrypted (X25519 + AES-256-GCM), instant delivery via push, read receipts, identical on Android and iOS.

FAQ & Help

Questions? Just search.

Everything about login, posting, security and more — searchable here. For the short, witty version: chat on the homepage.

No results.