> That said and if I read you correctly, the backend must be some sort of a dumb relay that just routes blobs of data between clients based on how they are grouped. Correct?
You're correct. It is just a dumb relay. That's the reason why it's so difficult (impossible?) to come up with a freemium monetization strategy. The server can't see the contents of your communications, so it can't restrict functionality.
> If so, then nothing restricts you from relaying any type of data, which is a fantastic foundation to have.
I suppose so. What did you have in mind?
> Do you have any details on how two clients would establish trust, exchange keys, if there's a replay protection, etc.? It would make for a good read.
I don't have anything written up about this (other than the code in the repositories), but if there's interest, I could compose a blog post about it. For the time being, users can verify the privacy of the communication with another friend by comparing the safety number of the friendship (tap the friend's avatar on the map, in the info panel that pops up click the triple dots at the top right, then select 'View safety number'). If you're safety numbers match, you know your share with that friend is secure. I got the idea from Signal messenger.
> PS. One thing I'd change is the name.
Yeah, I'm still reconsidering the name. I've already changed the company name once, but I may have to change it again. It's just hard to come up with an easy to remember+spell name that also has an available domain.