Molly, but with WearOS companion patches
  • Kotlin 67.1%
  • Java 32.8%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kate 7863903205
Some checks are pending
Test / Run tests (push) Waiting to run
MOLLY-WEAR: serve image thumbnails to the wear bridge
State flags messages with a downloaded image attachment (queried
directly; the conversation reader omits the slide deck). CMD_GET_IMAGE
decrypts the attachment via getAttachmentStream, sub-samples + downscales
to a 320px watch thumbnail, JPEG-compresses under a size cap, and replies
EVT_IMAGE with the bytes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JSqhgY5GUKUyVbCqvYjaee
2026-07-29 17:52:23 +02:00
.github Rename upstream branch to upstream-main 2026-07-26 12:42:29 +02:00
.idea Merge tag 'v7.44.2' into molly-7.44 2025-06-13 11:12:07 +02:00
app MOLLY-WEAR: serve image thumbnails to the wear bridge 2026-07-29 17:52:23 +02:00
baseline-profile Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
build-logic Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
buildSrc Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
core Three-way merge of networklistener-refactor 2026-07-15 00:29:51 +02:00
core-gms Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
fast-lint Add a new ci task with faster lint. 2026-06-09 17:21:47 -04:00
feature Merge upstream v8.19.2 into molly-8.19.2 2026-07-15 00:29:51 +02:00
gradle MOLLY-WEAR: point verification at locally-rebuilt 16 KB-aligned libs 2026-07-29 13:22:37 +02:00
lib Three-way merge of networklistener-refactor 2026-07-15 00:29:51 +02:00
lintchecks Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
mk Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
reproducible-builds Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
.dockerignore Eliminate Docker dependency for running unit tests 2023-03-22 23:26:58 +01:00
.editorconfig Merge tag 'v8.6.1' into molly-8.6 2026-04-04 12:00:13 +02:00
.gitattributes Merge upstream v8.19.1 into molly-8.19.1 2026-07-10 03:48:37 +02:00
.gitignore Merge tag 'v7.29.0' into molly-7.29 2025-01-08 14:25:07 +01:00
.tool-versions Bump java and kotlin target to JDK 21. 2026-07-01 15:10:24 -04:00
build.gradle.kts Avoid lint and Kotlin tasks running concurrently 2026-07-15 20:42:16 +02:00
BUILDING.md Unify GMS and FOSS build flavors 2025-12-23 12:52:41 +01:00
Dockerfile Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
gradle.properties Fix R8 nondeterminism for Kotlin lambda Signature attributes 2026-07-22 09:34:27 +02:00
gradle.properties.docker Fix R8 nondeterminism for Kotlin lambda Signature attributes 2026-07-22 09:34:27 +02:00
gradlew Update Gradle to 7.4.1. 2022-03-17 12:12:55 -04:00
gradlew.bat Update Gradle to 7.4.1. 2022-03-17 12:12:55 -04:00
LEGAL.md Replace README-ORIG.md with LEGAL.md 2026-07-15 22:57:00 +02:00
LICENSE Update top-level LICENSE file to AGPL 2023-05-05 12:48:53 -03:00
lint.xml Downgrade ThreadConstraint lint severity 2026-07-15 01:22:53 +02:00
Makefile Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00
NOTICE Initial Project Import 2011-12-20 10:20:44 -08:00
README.md Replace README-ORIG.md with LEGAL.md 2026-07-15 22:57:00 +02:00
settings.gradle.kts Merge upstream v8.18.1 into molly-8.18.1 2026-07-09 12:38:04 +02:00

Molly

Test Reproducible build Translation status Financial contributors Cloudsmith

Molly is a hardened version of Signal for Android, the fast simple yet secure messaging app by Signal Foundation.

Introduction

Back in 2018, Signal allowed the user to set a passphrase to secure the local message database. But this option was removed with the introduction of file-based encryption on Android. Molly brings it back again with additional security features.

Molly connects to Signal's servers, so you can chat with your Signal contacts seamlessly. Before signing up, please remember to review the Signal Terms & Privacy Policy.

We update Molly every two weeks to include the latest Signal features and fixes. The exceptions are security patches, which are applied as soon as they are available.

Download

You can download the app from GitHub's Releases page or install it from the Molly F-Droid Repo:

Get it on F-Droid

There are two versions available: Molly or Molly-FOSS. Learn the differences below and download the right one for you.

You can also get Molly-FOSS from Accrescent:

Get it on Accrescent

To verify the APK, use the following signing certificate fingerprints:

SHA-256: 6aa80fdf4a8cc13737cfb434fc0cde486f09cf8fcda21a67bea5ee1ca2700886
SHA-1: 49ce310cdd0c09c8c34eb31a8005c6bf13f5a4f1

Features

Molly has unique features compared to Signal:

  • Data encryption at rest - Protect your app database with passphrase encryption
  • Secure RAM wiper - Securely shred sensitive data from device memory
  • Automatic lock - Lock the app automatically under user-defined conditions
  • Multi-device support - Link multiple devices to a single Signal account, including Android tablets
  • UnifiedPush - Receive push notifications without Google through the UnifiedPush protocol
  • Block unknown contacts - Block messages and calls from unknown senders for security and anti-spam
  • Disappearing call history - Clear call logs together with expiring messages
  • Custom backup scheduling - Set daily or weekly interval and the number of backups to retain
  • SOCKS proxy and Tor support - Tunnel app network traffic via proxy and Orbot
  • Debug logs are optional - Android logging can be disabled

Additionally, you will find all the features of Signal, along with some minor tweaks and improvements.

Free and Open-Source

Molly is open-source just like Signal. But Signal depends on proprietary Google software for some features.

To support a 100% free and auditable app, Molly comes in two versions: one with proprietary blobs like Signal, and one without. They are called Molly and Molly-FOSS, respectively. You can install the flavor of your choice at any time, and it will replace any previously installed version. The data and settings will be preserved so that you do not have to re-register.

Feature Comparison

Here's how some key features work in different versions of the app:

Feature Molly-FOSS Molly Signal
Push notifications (1) ✔ WebSocket
✔ UnifiedPush
⚠ FCM
✔ WebSocket
✔ UnifiedPush
⚠ FCM
✔ WebSocket
Location sharing ✔ OpenStreetMap ⚠ Google Maps ⚠ Google Maps

(1) You might need to turn off system-level battery restrictions for the app to receive messages when the app isn't open.

UnifiedPush

UnifiedPush is an open standard for delivering push notifications, offering a privacy-friendly alternative to Google's proprietary FCM service. It allows users to choose their own notification distributor.

Important

To use UnifiedPush notifications, you need access to a MollySocket server to link your Signal account to UnifiedPush. You can either run MollySocket on a server you control (strongly advised) or use a public instance.

Currently, UnifiedPush is unavailable for linked devices.

Compatibility with Signal

Molly and Signal apps can be installed on the same device. If you need a second number for messaging, you can register Molly with a different number while keeping Signal active. Any phone number capable of receiving SMS or calls can be used during registration.

If you wish to use the same phone number for both Molly and Signal, you must register Molly as a linked device. Registering the same number independently on both apps will result in only the most recently registered app staying active, while the other will go offline.

For Signal users looking to switch to Molly without changing the phone number, please refer to the Migrating From Signal guide on the wiki.

Backups

Backups are fully compatible. Signal backups can be restored in Molly, and the other way around, simply by choosing the backup folder and file. However, to import a backup from Signal, you must use a matching or newer version of Molly.

Feedback

Reproducible Builds

Molly supports reproducible builds, so that anyone can run the build process to reproduce the same APK as the original release.

Please check the guide in the reproducible-builds directory.

Changelog

See the Changelog to view recent changes.

License

Licensed under the GNU Affero General Public License, version 3 only (AGPL-3.0-only).

See LEGAL.md for legal and copyright information.

Acknowledgements

Molly is an independent project built on code published by Signal. We are deeply grateful to the Signal contributors for the work we build on.

Thanks to the following organizations for supporting the Molly project.