projects impart

Impart

In testing

A panic button from uncoalesced for a small circle of people who trust each other. Hold it on one phone and a paired phone wakes up, takes over its lock screen and sounds an alarm.

Android 8.0+ · Kotlin · Jetpack Compose · Apache-2.0

01 · what it is

A panic button between phones that already trust each other

Hold the button and the paired phone wakes, even if it was asleep in a pocket with Do Not Disturb on. It puts a red alert over the lock screen and loops an alarm until someone acknowledges it.

It runs over ordinary SMS. There is no server, no account and no push service, and the app never asks for internet permission. The only thing that leaves a phone is a text whose body is IMPART_ALERT: followed by ciphertext. Your carrier sees that two numbers texted each other. It doesn’t see what was said, or who inside the message sent it.

Not an emergency service

If someone is in danger, call your local emergency number first.

  • Android
  • SMS
  • end-to-end encryption
  • panic button
  • Kotlin

02 · how it works

Pair in person, then sign, encrypt and text

Pairing happens face to face

Two phones scan each other’s QR codes. Each code holds a random ID, a phone number and two public keys. Both screens show a short fingerprint, and you read it out loud to be sure the code came from the phone in front of you. Nothing remote can add a contact.

The alert is signed, then encrypted

The message says who it’s from and who it’s for, with a random ID, the time, and your location if you turned that on. It’s signed with your Ed25519 key, encrypted to the other phone with Tink HPKE (X25519 and AES-256-GCM), and sent as a multipart SMS.

Acknowledging answers back

The alarm plays on the alarm audio stream. Tapping acknowledge sends a signed, encrypted reply to the number saved for that contact, so the sender knows it landed.

Five checks before anything rings

A broadcast receiver on the other phone wakes, decrypts, and only raises the alarm if:

  • the signature matches the key stored for that contact at pairing,
  • the message is addressed to this phone,
  • it is less than a day old,
  • it isn’t dated in the future,
  • and it hasn’t been seen before.

03 · why sms

Why SMS, and what it costs

An incoming text is delivered by the modem, so it wakes the receiving phone even under Doze. It also keeps every third party out of the loop. Nobody has to sit in the middle and pass the alert along.

The costs are real. You need a SIM with SMS service. Delivery usually takes seconds, but the carrier makes no promises. Both phone numbers are visible to the network.

What this does not claim

Impart keeps the content of an alert private and proves who sent it. It does not hide the fact that two numbers exchanged a text. That metadata stays with your carrier.

04 · safeguards

For when the phone itself is at risk

Dead man’s switch

Miss a check-in and a panic goes out to everyone you’ve paired with.

Duress PIN

A standard PIN unlocks the app. A second PIN, typed anywhere Impart asks for one, silently wipes it and leaves a fake “system error” screen behind.

Calculator disguise

The launcher entry can be renamed to Calculator.

05 · security

Security, and where it stops

Each phone makes its own Tink keysets on first launch. They’re stored encrypted under a key held in the Android Keystore and never leave the device. The QR code only carries public keys.

So someone who photographs your QR learns your number and public keys. That lets them encrypt a message to you, but not sign one as any of your contacts, which means they can’t set off your alarm. Old copies of alert texts, including the ones Android files in your Messages app, can’t set it off a second time either.

Screenshots and screen recording are blocked inside the app. It locks after 30 seconds in the background, and repeated wrong PINs lock it out for up to 15 minutes.

Known limits

The contact database is sandboxed but not encrypted at rest. Alert copies left in the Messages app show who you exchanged alerts with until you delete them. Nothing protects a phone that is already rooted or running malware. And Impart has not been independently audited.

06 · how it is built

Layers

Impart implementation choices by layer
UIJetpack Compose only. No XML layouts, no Fragments
DIHilt
StorageRoom, plus encrypted preferences
CryptoTink HPKE (X25519, AES-256-GCM), Ed25519 signatures, Android Keystore
TransportMultipart SMS. No internet permission
PlatformAndroid 8.0 (API 26) and up, targets API 35

The code splits into core (security, SMS receivers, the dead man’s switch), data (Room, encrypted preferences, the SMS relay), domain (plain Kotlin models and use cases) and presentation (Compose screens). Building it takes JDK 17 and the Android SDK for API 35. There is no google-services.json, no secret and no backend to deploy.

07 · status

In testing

Developed in the open

Impart is in testing and has no branding of its own yet. The most useful reports come from real hardware. Android 14 hides full-screen alerts unless you allow them, and most manufacturers’ battery savers stop the SMS receiver unless the app is exempt. If an alert doesn’t break through on your phone, that’s worth an issue.