A network observer on the same Wi-Fi
Sees TLS to Livara and nothing else. No message content, direct or group.
HeldA threat model that only lists strengths is a brochure. This one names six adversaries, says exactly what each of them gets, and then prints the list of things Livara does not claim.

Two of these six get more than you might hope. They are listed anyway, in the same type size as the rest.
Sees TLS to Livara and nothing else. No message content, direct or group.
HeldReads group and channel content, and all routing metadata. Cannot open direct-message bodies or media.
Not heldCannot restore your direct-chat keys — the encrypted backup needs the recovery phrase as well.
HeldReads everything you can read. No messenger survives this one.
Not heldDirect-message content stays sealed: ML-KEM-768 is mixed into every message key. Group content does not benefit.
HeldDetectable before install. The SHA-256 is published and the Proof Lab hashes your file locally.
HeldThis table is printed identically on the home page, on the security page and here, because the answer should not depend on which page you landed on.
Direct content closes before the network sees it. Group content stays useful for moderation and membership changes, which also means the server can read it.
The cryptographic detail ↗| What it is | Direct 1:1 | Groups & channels |
|---|---|---|
| Message text | Sealed on your device | Server can read it |
| Photos, video, files | Encrypted before upload | Server can read them |
| Captions and edits | Sealed on your device | Server can read them |
| Who you talked to | Server knows | Server knows |
| When you talked | Server knows | Server knows |
| Your password | Never leaves your device | Never leaves your device |
| Your private keys | Never leave your device | Never leave your device |
Each of these is a real limitation with a real consequence. They are here because a boundary you can only discover by being disappointed is not a boundary, it is a trap.
The platform stores who talked to whom, when, in what conversation, and the delivery state of each message. That is how a second device catches up. Any messenger that claims to hide this while also offering instant multi-device sync is worth a second look.
Group and channel content is protected in transit and by server-side membership and role checks, and is readable by the server. It is never described as end-to-end encrypted anywhere on this site.
Calls are protected in transit. The post-quantum hybrid claim covers direct-message content only.
Keys live on the device. Malware with your unlocked device has your plaintext, and no protocol choice on our side changes that.
Lose the device and the phrase together and the old direct-chat ciphertext stays closed permanently. That is the real price of a server that cannot read your messages.
There is no third-party audit report to point at yet. Instead of implying one, the site ships the Proof Lab so the parts that are checkable can be checked by you today.
Hash the APK, run the handshake, corrupt a byte and watch the authentication reject it. All of it offline, in your own browser, before you install anything.