Tool Intelligence Profile

XChat

X Corp encrypted messenger (in-app Chat + standalone iOS app): E2EE via PIN/Juicebox, vanishing messages, files, groups. Free; Premium raises DM request limits. Not Signal-grade.

messaging freemium 0

Pricing

Contact Sales

freemium

Category

messaging

0 features tracked

Overview

XChat is X Corp’s private messaging product: encrypted “Chat” inside the main X apps (iOS, Android, web) plus a standalone XChat iOS app (App Store listing by X Corp., free, Social Networking). You sign in with an existing X account—there is no separate phone-number-only identity. The job to be done is upgraded DMs for people already on X: text, media, files, groups, vanishing messages, and (where available) voice/video—without needing to ask “are you on this app?” the way WhatsApp or Signal require a new graph.

Public rollout of the rebuilt system was announced in mid-2025 (Musk: encryption, vanishing messages, arbitrary files, audio/video calling, “built on Rust”). A dedicated iOS app went to broader testing in early 2026 and to a public App Store launch around 24 April 2026 (TechCrunch). The App Store page markets “No ads. No tracking. Fully end-to-end encrypted,” large file sharing, massive group chats, edit/delete for everyone, screenshot blocking, and disappearing messages. As of mid-2026 the store score sits near 3.9/5 from ~2K ratings—usable but not a polish leader versus mature messengers.

X’s own Help Center (“About Chat”) is the ground-truth product doc: per-user key pairs, a user PIN that never leaves the device, server-side private-key storage via the open-source Juicebox protocol (shares across three X-operated realms, two hardware-backed), per-conversation keys, safety numbers, message-request rules, and an explicit admission that the design is not forward secure today. A third-party review by Trail of Bits is linked from that page (2025 PDF). Independent press and security writers (The Register, TechCrunch, Kaspersky, WIRED) still treat XChat as a social-network messenger with encryption features—not a drop-in replacement for Signal.

Quick take: Use XChat when your contacts already live on X and you want better DMs than legacy Messages. Use Signal (or WhatsApp for reach) when security properties and third-party scrutiny matter more than the X social graph.

Key features

  • End-to-end encrypted Chat content — Official docs state that message content, links, media, files, and reactions in encrypted conversations are encrypted before leaving the sender’s device and stay encrypted at rest on X infrastructure until recipient devices decrypt them. Group messages and media can be encrypted under the current design (unlike some earlier Twitter DM experiments).
  • PIN + Juicebox multi-device keys — On first Chat registration, a public/private key pair is created. A PIN (device-local) protects recovery of the private key from Juicebox shares. X documents three realms (all currently operated by X), two HSM-backed, with a 2-of-3 recovery threshold and a hard wrong-PIN limit (20 attempts) after which shares become permanently inaccessible. HSM realm software is pointed to the open-source Juicebox HSM repo; X published a Chat HSM key-ceremony post via @XEng.
  • Safety numbers — Users can compare safety numbers derived from both parties’ public keys so messages can be authenticated against the expected peer (similar intent to Signal safety numbers / WhatsApp security codes).
  • Disappearing messages — Per-conversation timers delete messages from devices and X servers after a chosen duration (conversation info → Disappearing messages).
  • Unsend / delete — Encrypted messages can be unsent to remove them from the recipient inbox; delete/leave behaviors are documented with the usual caveat that the other party may still have seen content before deletion.
  • Message requests — Unencrypted requests can go to users who allow open DMs or Verified-to-Verified flows; requests stay separate until accepted, then the conversation becomes encrypted. Grok is used to sort Priority vs Hidden request inboxes.
  • Eligibility rules — Both sides must have registered for Chat (X apps or XChat app). Recipient must follow/subscribe to sender, have messaged before, have accepted an encrypted Chat before, or share Premium Business/Organization membership.
  • Groups & invites — Public invite links with approval gates; group name/avatar are unencrypted and can be public. Voice notes are supported from the compose bar.
  • Grok integration — Ask Grok / Edit with Grok / Grok Companions: content you send to Grok is no longer E2EE for that analysis path (original chat ciphertext stays as-is). Useful for AI side tasks; bad for threat models that ban cloud AI on chat content.
  • Standalone iOS app claims — Edit/delete for everyone, screenshot block, large media/file sharing, group chats, X-account sign-in without a separate phone-number graph. Feature parity with in-X Chat is imperfect in user reports (calls, read receipts, reply reliability).
  • Reporting & franking — Long-press report can send message content plus metadata to X for policy review; message franking is used so reports can be cryptographically tied to the Chat system.

Pricing

The XChat / Chat product itself is free. There is no separate paid “XChat Pro” SKU on the App Store—the app lists as Free. Monetization and capacity sit on the parent X Premium stack and on message-request quotas.

Plan / surfacePrice (US web, indicative)What it means for Chat
Free X account + Chat$0Full Chat registration and encrypted conversations with eligible peers; 7 message requests / 24h
X Premium BasicFrom ~$3/mo or ~$32/yr (web)Platform perks; request caps still tier-based (see Premium row for listed Chat caps)
X PremiumFrom ~$8/mo or ~$84/yr (web)35 message requests / 24h (official Chat limits table)
X Premium+From ~$40/mo or ~$395/yr (web)75 message requests / 24h
Premium BusinessOrg pricing500 message requests / 24h; same-org Chat eligibility rules
Standalone XChat iOS$0 downloadSame X identity; App Store privacy labels still list analytics/identifiers linked to you

Regional prices and App Store / Play billing markups differ from web. Premium is optional for basic 1:1 Chat with people who already follow you or accept requests; it mainly raises how aggressively you can cold-message strangers and unlocks wider X product benefits (verification, Grok access tiers, reduced ads on the social feed—not a separate crypto tier for Chat).

Billing note: Treat Chat as freemium on identity and quotas, not as a pure open-source client. If you only need encrypted messaging and do not want an X account or social graph, pay $0 elsewhere (Signal) rather than buying Premium “for Chat.”

Limits & gotchas

  • Not forward secure (official) — X’s About Chat page states that if a registered device’s private key is compromised, an attacker can decrypt encrypted Chat messages sent and received by that device. Key rotation for stronger forward secrecy is described as future work, not a present guarantee.
  • Metadata is not E2EE — Recipient, timestamps, and similar metadata are not encrypted. Sharing Posts inside Chat leaves a record that those Posts were shared.
  • Message requests start unencrypted — Cold outreach is unencrypted until acceptance. That is intentional product design; do not assume E2EE on first contact.
  • All Juicebox realms currently run by X — Split-key design reduces pure software-server risk, but trust is not multi-operator today. X says it may allow third-party realms later; that is a plan statement, not a current user control.
  • PIN UX friction — Security write-ups (e.g. Kaspersky) flag confusing first-run PIN prompts and contrast server-side key custody with Signal/WhatsApp device-centric models. Lose the PIN without a still-logged-in device and encrypted history recovery can fail.
  • Logout deletes local Chat data — Logging out of X (and XChat if both are installed) erases local messages/keys unless device-managed passcode/iCloud Keychain recovery applies on iOS as documented.
  • Grok breaks the privacy boundary on purpose — Anything you send to Grok for analysis or companions is decrypted for the model path.
  • Reporting decrypts for moderation — User-initiated report packages content for agent review.
  • Feature parity gaps (user reports) — App Store reviews frequently cite missing or flaky read receipts/online status, reply-to-message bugs, delayed reactions, screenshot-block failures, and calls present in the main X app but missing or weaker in standalone XChat.
  • Requires X account — No anonymous burner identity without the parent platform’s signup, phone/email recovery norms, and ToS. Privacy marketing on the App Store still coexists with Apple privacy labels listing contact info, identifiers, usage, and diagnostics linked to you for analytics/functionality.
  • Expert trust gap — Register coverage of the 2025 “Bitcoin-style encryption” framing, Element CEO comments on centralized opacity, TechCrunch “shouldn’t trust it yet,” and WIRED’s Messenger-not-Signal verdict all cluster the same way: treat marketing claims as weaker than Signal’s long audit/open-source track record until you personally verify safety numbers and accept residual platform risk.
  • Daily request caps — Free users hit a wall fast (7/day). High-volume outreach is a paid Premium behavior, not a free growth hack.

Community sentiment

Security and privacy communities have been skeptical since the 2025 architecture relaunch. Hacker News threads on The Register’s “no more secure” piece and follow-ups on Juicebox/key custody repeatedly compare XChat unfavorably to Signal’s Double Ratchet, open clients, and client-held keys. Reddit’s r/privacy, r/cybersecurity, and r/crypto hosts reverse-engineering and “can the platform read this?” debates; a common paraphrase is that Juicebox + X-operated realms is clever engineering but still centralized trust.

Consumer press after the April 2026 standalone app launch is mixed-to-cool: TechCrunch frames XChat as a strategic messaging/payments surface more than a privacy product, notes past expert warnings, and observes the irony of a multi-app “everything app.” WIRED’s hands-on argues the product feels like Facebook Messenger attached to a social network—not a lean Signal competitor. Kaspersky’s 2026 blog lands on a quotable expert line: Signal for security, WhatsApp for reach, XChat if your life already runs on X.

App Store feedback is more practical than cryptographic: people like the idea of a focused chat shell without the firehose timeline, then ding reliability and missing messenger basics. Expect praise from heavy X power users who finally get vanishing messages and large files, and shrugs from anyone who already standardized on iMessage, WhatsApp, or Signal.

“If what you want is good security, use Signal. If what you want is to be able to talk to pretty much anybody using encrypted messages, use WhatsApp. If your whole life is based around X, I guess this is better than nothing.” — cybersecurity expert quoted in coverage of XChat (WIRED / Kaspersky summaries)

Who should use it

  • Active X users who message creators, colleagues, or communities already on the platform and want E2EE content, vanishing messages, and file transfer without migrating contacts off-platform.
  • Creators and community mods who live in replies/DMs on X and need group chats plus invite links without building a separate Discord solely for the same audience (still evaluate Discord for larger community tooling).
  • Premium subscribers who cold-message often and need higher daily request limits.
  • Not ideal for journalists, activists, legal/medical confidential work, or high-threat users who require mature forward secrecy, multi-vendor audits, open clients, and minimal metadata—prefer Signal-class tools.
  • Not ideal as a phone-number-free anonymous messenger—you still inherit an X identity and platform policies.
  • Teams looking for workplace chat should compare Slack or Microsoft Teams rather than bending a social DM product into an employee OS.

Alternatives

  • Signal — Default choice for strong E2EE, open protocol heritage, and security community trust; requires contacts to install Signal.
  • Discord — Communities, voice, servers, bots; not a Signal substitute, excellent for interest groups and gaming-style orgs.
  • Slack — Workplace channels, admin controls, integrations; paid seats vs free social DMs.
  • WhatsApp — Massive default E2EE reach via phone numbers; Meta ecosystem tradeoffs.
  • Telegram — Feature-rich clients and large groups; default cloud chats are not Signal-style E2EE (secret chats differ).
  • iMessage / RCS — Best when your graph is Apple-heavy or carrier RCS; different threat model.
  • Element / Session / SimpleX / Threema / Wire — Stronger “privacy product” framing depending on whether you want Matrix federation, metadata resistance, paid Swiss hosting, or business compliance.

VersusTools also tracks the pair context on XChat vs Signal when that comparison is published on the site.

Verdict

XChat is a real, shipping encrypted messenger for the X social graph—not vaporware marketing alone. Official documentation is unusually candid about architecture (Juicebox, PIN limits, safety numbers, missing forward secrecy, metadata exposure, Grok decryption). The free tier is enough for normal mutual follows; Premium mainly buys request volume and the rest of X’s subscription bundle. The standalone iOS app makes Chat feel like a product, not a drawer tab, but mid-3s App Store ratings and expert press agree it is still maturing as a messenger UX and as a high-assurance crypto system.

Bottom line: Prefer XChat when the network effect is “everyone I need is already on X.” Prefer Signal (or WhatsApp for ubiquity) when encryption quality, open scrutiny, and threat-model conservatism matter more than X identity. Treat “fully end-to-end encrypted” marketing as partially true for content, incomplete for metadata/forward secrecy/platform trust, and always verify safety numbers with high-value contacts.

Alternatives

Best Alternatives to XChat

View all XChat alternatives →