An anonymous chat application designed with privacy at its core (Android | Flutter).
CasualChat delivers instant, frictionless group chats by interest and one‑to‑one private messaging without collecting unnecessary permissions or personal data. Private chats use end‑to‑end encryption (RSA + AES‑GCM); group chats are lightweight and easy to browse. The app is built on Flutter with Firebase for realtime data sync.
- Anonymous by default: no registration forms or personal data collection. A
UUIDcredential is generated and used for login on first launch. - Interest‑based group chats: browse topics, join groups instantly, and create your own.
- End‑to‑end private messages: start from a user avatar in a group; RSA‑OAEP protects the session key, and AES‑GCM encrypts messages.
- Minimal permissions: sensitive data is stored in secure storage with clear separation of concerns.
- Profile basics: username and avatar (with a sensible default) for simple identity display.
- Realtime UX: backed by Firebase Firestore snapshot streams for live updates.
- App framework:
Flutter (Material 3) - Cloud services:
Firebase(Authentication, Firestore, Storage) - Cryptography:
RSA 2048(OAEP) andAES‑256‑GCM - Secure storage:
FlutterSecureStorage(private keys and session keys),SharedPreferences(non‑sensitive preferences)
main.dart: App bootstrap andFirebaseinitialization.welcome.dart: Welcome screen and entry into the login flow.login.dart: Anonymous login (UUID → email/password); generates RSA keypair on first login and stores public key with signature.navigation.dart: Bottom navigation withHome,Search,Add, andProfile.home.dart: Shows joined conversations split intogroupsandchats.search.dart: Fetchesinterests, displays topic lists, and joins relevant groups.add.dart: Create new group chats (title/topics/cover image).profile.dart: Edit username and avatar; sync changes to Firestore and cache locally.messages.dart: Message stream UI; private chat encryption/decryption and session key handling.encryption.dart: RSA helpers, AES‑GCM encrypt/decrypt, signing/verification, PEM encode/decode.
Key Firestore collections and fields (examples):
-
users(minimal user profile){ "userID": "<Firebase Auth UID>", "username": "User#abcd1234", "profilePicture": "<base64>", "publicKey": "-----BEGIN RSA PUBLIC KEY-----...", "signature": "<base64 signature>", "groups": ["<chatID>", ...], "chats": ["<chatID>", ...] } -
chats(group or private conversation metadata)- Group example:
{ "chatID": "<uuid>", "title": "Photography", "image": "<base64>", "interest": ["Art", "Camera"], "isGroup": true } - Private example:
{ "chatID": "<uuid>", "user1": "<userID A>", "user2": "<userID B>", "title": "<peer username>", "image": "<peer avatar base64>", "isGroup": false, "encryptedAESKey_user1": "<RSA‑OAEP encrypted>", "encryptedAESKey_user2": "<RSA‑OAEP encrypted>" }
- Group example:
-
messages(message records){ "userID": "<sender userID>", "content": "<plaintext for group | AES‑GCM ciphertext for private>", "timestamp": "<Firestore Timestamp>", "chatID": "<chatID>" } -
interests(topic catalog){ "name": "Travel" }
- Credential generation: the app generates a
UUID‑based email and a random password on first launch and signs in via Firebase Email/Password. No personal data is requested. - Key management:
- First login creates an
RSA 2048keypair. The private key is stored inFlutterSecureStorage(privateKey). - The public key (PEM) and its signature (
SHA‑256 with RSA, over the PEM text) are stored in theusersdocument. - On subsequent logins, the public key’s signature is verified to detect tampering.
- First login creates an
- End‑to‑end private chat:
- Initiation: tap a user avatar within a group to open or create a private conversation.
- Session key: a 32‑byte
AES‑256key is generated per private chat, RSA‑OAEP‑encrypted with both participants’ public keys, and stored in thechatsdocument (encryptedAESKey_user1/2). - Local storage: the current user decrypts the AES key with their private key and stores it in
FlutterSecureStorage(aesKey_<chatID>). - Message encryption: private messages use
AES‑GCMwith a 96‑bit IV; group messages are plaintext for lightweight browsing and search.
FlutterSecureStorageprivateKey: RSA private key (PEM).aesKey_<chatID>: AES session key for private chats (base64).
SharedPreferencesemail/password: auto‑generated credentials.username/profilePictureBase64: cached profile edits.
- Prerequisites: install
FlutterandAndroid SDK; set up a device or emulator. - Firebase setup:
- Use FlutterFire CLI to generate and update
lib/firebase_options.dart. - Place
google-services.jsoninandroid/app/(a sample is included in this repo).
- Use FlutterFire CLI to generate and update
- Install dependencies:
- Run
flutter pub get.
- Run
- Launch:
- Run
flutter run. The app performs anonymous login automatically and navigates to the main UI.
- Run
- Home: browse your joined
GroupsandChats; long‑press a card to remove the chat from your list. - Search: explore topics and join group chats; tapping a room adds it to your profile and opens messages.
- Start a private chat: tap a member’s avatar inside a group to create or enter a one‑to‑one conversation (key distribution and encryption happen automatically).
- Create a group: go to
Add, input a title, select topics, upload a cover, and submit. - Edit profile: update username and avatar in
Profile(default avatar atassets/images/default_profile.png).
- Login flow (10 devices): auto‑generated UUID credentials; no personal info requested; returning users re‑enter seamlessly.
- Privacy checks: network monitoring and local storage inspection confirm no personal data transmission or storage beyond UUID and non‑identifiable fields.
- User feedback (10 participants): smooth login, strong sense of anonymity, comfortable using the app without revealing identity.
- Group messages are plaintext today for simplicity and openness. Planned enhancements:
- Group end‑to‑end encryption (key agreement, member rotation).
- Offline message caching.
- Message recall/reporting.
- Multi‑platform support (iOS, Web) and push notifications.
- Security note: private chat security depends on key custody and device integrity; avoid using on untrusted devices.
lib/
add.dart # create group chat
encryption.dart # crypto/key/signing utilities
home.dart # conversation list
login.dart # anonymous login and key generation
messages.dart # message UI and crypto
navigation.dart # bottom navigation
profile.dart # user profile
search.dart # topic search and group browsing
welcome.dart # welcome screen
- Tap a member’s avatar in a group to start a private chat (automatic key distribution).
- Deleting a chat currently removes its
chatIDfrom the user document; it does not deletechats/messagesglobally (to avoid affecting other participants). - Crypto/signing helpers in
encryption.dart:- RSA‑OAEP:
encryptAESKey/decryptAESKey - AES‑GCM:
encryptMessage/decryptMessage - Signing/verification:
sign/verify
- RSA‑OAEP:
Built on Flutter and Firebase to provide instant realtime chat and robust privacy‑first design. Thanks to the course staff and peers for guidance and feedback.