projects impart
Impart
In testingA panic button from uncoalesced for a small circle of people who trust each other. Hold it on one phone and a paired phone wakes up, takes over its lock screen and sounds an alarm.
01 · what it is
A panic button between phones that already trust each other
Hold the button and the paired phone wakes, even if it was asleep in a pocket with Do Not Disturb on. It puts a red alert over the lock screen and loops an alarm until someone acknowledges it.
It runs over ordinary SMS. There is no server, no account and no push service, and the app never asks for internet permission. The only thing that leaves a phone is a text whose body is IMPART_ALERT: followed by ciphertext. Your carrier sees that two numbers texted each other. It doesn’t see what was said, or who inside the message sent it.
Not an emergency service
If someone is in danger, call your local emergency number first.
02 · how it works
Pair in person, then sign, encrypt and text
Pairing happens face to face
Two phones scan each other’s QR codes. Each code holds a random ID, a phone number and two public keys. Both screens show a short fingerprint, and you read it out loud to be sure the code came from the phone in front of you. Nothing remote can add a contact.
The alert is signed, then encrypted
The message says who it’s from and who it’s for, with a random ID, the time, and your location if you turned that on. It’s signed with your Ed25519 key, encrypted to the other phone with Tink HPKE (X25519 and AES-256-GCM), and sent as a multipart SMS.
Acknowledging answers back
The alarm plays on the alarm audio stream. Tapping acknowledge sends a signed, encrypted reply to the number saved for that contact, so the sender knows it landed.
Five checks before anything rings
A broadcast receiver on the other phone wakes, decrypts, and only raises the alarm if:
- the signature matches the key stored for that contact at pairing,
- the message is addressed to this phone,
- it is less than a day old,
- it isn’t dated in the future,
- and it hasn’t been seen before.
03 · why sms
Why SMS, and what it costs
An incoming text is delivered by the modem, so it wakes the receiving phone even under Doze. It also keeps every third party out of the loop. Nobody has to sit in the middle and pass the alert along.
The costs are real. You need a SIM with SMS service. Delivery usually takes seconds, but the carrier makes no promises. Both phone numbers are visible to the network.
What this does not claim
Impart keeps the content of an alert private and proves who sent it. It does not hide the fact that two numbers exchanged a text. That metadata stays with your carrier.
04 · safeguards
For when the phone itself is at risk
Dead man’s switch
Miss a check-in and a panic goes out to everyone you’ve paired with.
Duress PIN
A standard PIN unlocks the app. A second PIN, typed anywhere Impart asks for one, silently wipes it and leaves a fake “system error” screen behind.
Calculator disguise
The launcher entry can be renamed to Calculator.
05 · security
Security, and where it stops
Each phone makes its own Tink keysets on first launch. They’re stored encrypted under a key held in the Android Keystore and never leave the device. The QR code only carries public keys.
So someone who photographs your QR learns your number and public keys. That lets them encrypt a message to you, but not sign one as any of your contacts, which means they can’t set off your alarm. Old copies of alert texts, including the ones Android files in your Messages app, can’t set it off a second time either.
Screenshots and screen recording are blocked inside the app. It locks after 30 seconds in the background, and repeated wrong PINs lock it out for up to 15 minutes.
Known limits
The contact database is sandboxed but not encrypted at rest. Alert copies left in the Messages app show who you exchanged alerts with until you delete them. Nothing protects a phone that is already rooted or running malware. And Impart has not been independently audited.
06 · how it is built
Layers
| UI | Jetpack Compose only. No XML layouts, no Fragments |
|---|---|
| DI | Hilt |
| Storage | Room, plus encrypted preferences |
| Crypto | Tink HPKE (X25519, AES-256-GCM), Ed25519 signatures, Android Keystore |
| Transport | Multipart SMS. No internet permission |
| Platform | Android 8.0 (API 26) and up, targets API 35 |
The code splits into core (security, SMS receivers, the dead man’s switch), data (Room, encrypted preferences, the SMS relay), domain (plain Kotlin models and use cases) and presentation (Compose screens). Building it takes JDK 17 and the Android SDK for API 35. There is no google-services.json, no secret and no backend to deploy.
07 · status
In testing
Developed in the open
Impart is in testing and has no branding of its own yet. The most useful reports come from real hardware. Android 14 hides full-screen alerts unless you allow them, and most manufacturers’ battery savers stop the SMS receiver unless the app is exempt. If an alert doesn’t break through on your phone, that’s worth an issue.