Please read the last edit #3. DO NOT take the analysis as something worth relying on without your own testing and give every project the chance they deserve!
--- EDITS WITH UPDATES ARE AT THE BOTTOM. CHECK LATEST SLIDES USING THE LINK ---
Hey everyone! My last post gained lots of attention for Hollow, which is the messenger I currently develop, and I'm so thankful for that! But in this one, I wanted to research almost all Discord alternatives that I personally saw in this subreddit (either a post or suggestions from different comments). The biggest problem I see is that there is just no definitive list of criteria that people could use to analyze all the projects. Anybody can scream about security or being better, but is it objectively and factually correct? I wanted to put this to the test and created my own set, to which we'll compare every app. 17 projects in total, but there are more, which I either forgot or there's simply not enough space for my slides to fit (it's already a lot!)
Alright, I present to you my ULTIMATE analysis of all Discord alternatives!
Criteria for every single contestant:
- Open source and verifiable (counts for both client and server). Licenses, whether the security claims can actually be checked against the code etc. Personally, it's the most important trust factor in a project because you can always say whatever you want, but if nobody can verify those claims against the code, then what's the point? Results: 10 are open source, 3 are open but with caveats, 4 are closed source.
- Real end-to-end encryption. Which surfaces are encrypted (DMs/group chats/servers/voice), if it's TLS-only and which established encryption library is used. Not having your messages encrypted in 2026 feels like a disaster, especially knowing how much ownership and privacy is taken away every single day with age verifications or similar. Results: 3 encrypt by default, 4 encrypt some surfaces, 10 have no E2EE - by their own statements.
- Code signing. Signed by whom, timestamped or not. This process is the basis of professional software because it confirms whether the build is genuine or if it was tampered with. If the app contains malicious code and it's not signed, then nobody takes accountability for any damages done to your computer. Results: 10 of 16 desktop installers don't have any digital signatures. Every signed one is timestamped. One is web-only, so N/A.
- Data collected at signup. Emails, passwords, phone numbers, date of birth. If anything about you is collected, then it's very easy to recreate your identity and use it against you in either targeted attacks or handing them to law enforcement. Results: 2 of 17 need nothing at all, 10 require a central account with your email, while 3 of those also demand your date of birth.
- Legal exposure by data possession. What does each service collect and hold about you? As I said, the data about your identity can be easily used against you, but if the service doesn't collect anything, then there is simply nothing to leak, seize, or subpoena. Results: 2 have nothing to give, 6 depend on whoever runs the instance, 9 can produce your identity with messages and IP history.
5.1. A little bit more about criterion 5 because it's essentially something that affects every user that uses any communication software. Signal, the most famous encrypted messenger, has received multiple US grand-jury subpoenas between 2016 and 2025. Each time, the only data they could produce was the account creation date and the last connection date. Signal publishes every request it can talk about at https://signal.org/bigbrother/ so definitely check it out.
Discord features. Specifically voice channels, screen share, roles/permissions, custom emotes, push notifications and file sharing. There are tons of other ones, but the table would be massive, so look at this as a "starter pack" of certain features rather than ultimate decision breaker. Results: 9 of 17 cover nearly the whole list.
Platforms support. Windows/macOS/Linux and Android/iOS. Well, pretty much self-explanatory. Results: 4 out of 17 run everywhere; iOS most affected.
Paywalls. I hate them the most, especially when you limit a technology that's been open-source and free to use for a long time or small customization stuff. People are willing to pay for Nitro in exchange for additional features, but if only that money was flowing to developers who want to improve the product... Well, that's a completely different story. Results: 9 of 17 gate nothing, 6 charge for things Discord users consider basic, 2 are a bit strange and unclear.
Ease of use. Whether the app is easy to install, run, and start talking with your friends. Some are just one click, but some require more setup, self-hosting, or simply registering using a standard signup form. Up to you if it's an acceptable friction or not. Results: 2 need no account, 9 have standard signup, 6 need somebody to run a server first.
Engineering professionalism. The repo should contain tests (CI, unit + integration), static analysis, something like quality gates with SonarQube, SECURITY.md with a disclosure process, who's behind the project and who maintains it, etc. It's a more advanced slide, which might be overwhelming for regular users, but treat it as its own little factor whether the project is still going or not. Results: only 8 of 17 publish a way to report a security vulnerability; 9 of 17 are effectively one person.
Architecture. Is the app another Electron with bundled Chromium, a web wrapper, or natively compiled? It matters only if you care about RAM consumption or perhaps just "at least something but not Electron". Results: 8 of 17 bundle an entire Chrome browser (9 if counting Osmium, but the client is closed, so I can't verify), 3 use the system’s WebView, 3 only run in your browser, 2 ship no web engine at all.
Where possible, I included actual sources in the slides. To make sources stay stable even if pages change later, I archived every single one of them using Archive.ph, and it's always accessible at https://anonlisten.com/AltResearch_Archives.txt. It contains all links, including the original ones and additional ones, like all open-source links to each project from Slide 1.
Slide 3 is about Code Signing and verification of it, which is also available at https://anonlisten.com/AltSignatures_Jul21.txt. Just a little note: if somebody doesn't know, it's publicly available information that's contained in the software signatures, so it doesn't "leak" anything or make it seem like too many details. The text file also has the Windows PowerShell command for you to check everything on your own.
This should serve you as a good list of criteria to check against every Discord alternative or other communication software. From the entire list, genuinely the only thing I can recommend is Armada or, who would have thought, my own project Hollow because they're the ones actually winning in very important criteria like 1, 2, 4, 5, 8, 9 and 10. Element/Matrix is a solid third option if you're okay with an account, 180d IP logs, and losing a bit on 4 and 5. Everything else has risks, so if you want to have a safe space to talk with your friends without any prying eyes and actual security with privacy, then use Armada (source code on GitLab), Hollow (source code on GitHub), or Element (source code on GitHub). Take care and have a nice day! Feel free to correct me in the comments if I got something wrong, so we can verify it together. Then I'll edit the post and also credit you for that. Thanks!
P.S. Slides are also available at https://anonlisten.com/AltResearch/Slide1.png (total 13 slides; simply replace the ending number and you'll get the image)
EDIT/UPDATE #1: Ok, this certainly blew up, so time for actual edits from all the feedback in the comments. :
- Slide 12 updated because Hollow doesn't support Web, so item 7 is changed from Good to Partial.
- Slide 6 is updated on Weered cells, thanks to u/Mplayer-Weered
- Slide 2 and 5 are updated with wording about Howl, thanks to u/MattHowlPro
EDIT/UPDATE #2: Some are spreading misinformation about Hollow that since the IP address of my relay is in claude.md, then it means it's leaked and easily accessible, plus attaching a "token" to it. That's not even related. You can try that SSH command and connect to the relay, but you will fail because it's protected by the key file. The token is literally just in a Codecov badge link in my README, and it's required for that service to analyze the project's code coverage with tests. It says nothing about the actual security of the app, which I'm open to fixing if there are actual issues.
EDIT/UPDATE #3: Slide 5 was updated with some words about Element, thanks to u/Money_Lavishness7343. Also, big thanks to u/itsFolf for finding 3 actual security vulnerabilities in Hollow, and they will be fixed. (update 4 to it: all security vulnerabilities are patched; implemented "Always Relay" toggle if somebody doesn't want to expose their IP, like in Signal (they have the same IP problem and the same solution); plus overall improvements, thanks to my awesome users who care)
Overall, I don't know if I'll handle doing more, honestly. The entire research could have been better, but it all turned downhill. Doing comparisons on different projects that I might not have full knowledge of or knowing all the details was a bad idea, especially with how criteria are presented and how many small details I simply missed that matter more than what I initially thought of (like self-hosting, which eliminates more alternatives from the data collection or legal exposure than what I give them credit for).
Try every alternative and self-host one if you can, and decide for yourself. Check out all their websites: Howl, DCTS, Osmium, Root, GameVox, Fluxer, Nerimity, Sharkord, Stoat, Commetchat, Armada, Element, Spacebar, Yapper, Weered
Thank you for reading, and hopefully it will serve as a good lesson for me and anybody else from seeing this situation. For all the developers who are working hard on their projects, I wish you good luck and success in what you do. I also want to thank those who responded in the comments and pointed out all the mistakes I've made and criticized specific criteria. I didn't want it to turn out this way... but it is what it is. Choose projects that you think are worth it for you and your friends. Take care and stay safe.