Claims

Each row is a sentence Soapbox published, then the document that qualifies it. Dates are the dates on those pages.

What they say Where What the record says
"Communities with channels, voice and DMs that need no host." Meta description on armada.buzz, build 7 October 2026. Derek Ross, How to Self-host Armada, 30 July 2026: the web app, the default relays, and the voice server sit on infrastructure Soapbox operates. "Voice is the one part that needs a real server." The live bundle's voice fallback is https://armada.buzz.
"No company in the middle." "Owned by no company. Not even ours." Fain's Discord-alternative essay, 22 July 2026. Soapbox homepage. The AGPL extra permission in the client README is granted by Soapbox Technology, LLC. That LLC filed the SOAPBOX trademark on 14 May 2026, owner address Watertown, South Dakota. The funding page says they are working toward a 501(c)(3) and have no shareholders. An LLC is still a company, and it holds the copyright permission the app stores rely on.
"A platform-wide ban is technically impossible." Fain, comparison essay, 30 July 2026. No company can delete a key it did not issue. The terms, 28 August 2026, say individual relays and communities enforce their own rules. A community owner can remove a member. A relay can refuse the events. Fain's Henhouse post, 17 June 2024, already states the limit: they cannot stop you speaking on the open protocol, and they can revoke the identity on their relay. Armada's defaults are relays Soapbox operates.
"Armada encrypts every community end to end." Relays "see only sealed ciphertext, with the sender and even the community's name hidden." Same essay. Also the client README: "Nobody can read your messages." True for Concord chat content, as designed. False as a description of the product. NIP-29 groups, which include Buzz, are relay-hosted: the operator has the room. The voice component says NIP-29 calls have "no media E2EE (relay-trusted SFU)." Bridged Discord channels are mirrored in plaintext. The in-app policy says NIP-04 and NIP-44 DMs leave sender, recipient, and timestamps visible. Link previews go to https://ditto.pub/api/link-preview/{url}. The code comment says that proxy "sees every previewed URL."
"There is no email, phone, face scan, or ID at any point." Comparison essay FAQ. Signup copy says the same. Creating an account does not ask for those. The self-host guide on the same blog ends with: "There is no iPhone app yet. Drop your email and we will tell you the day it ships." Installing the Play Store build requires a Google account even though the app does not ask for one. Profile and list events are also published, by default, to wss://relay.primal.net.
"Armada does not operate these relays and has no control over data stored on them." "Content published to Nostr relays is public by default." In-app privacy policy, last updated 11 July 2026. Still that text in the 7 October bundle. Soapbox's homepage: "real events, streaming live from relays we operate," with a counter for users on relay.ditto.pub. The live client falls back to wss://relay.ditto.pub and wss://relay.dreamith.to when no relay list is configured. Concord events are ciphertext, which contradicts "public by default" for that mode, and the policy's "we do not operate them" contradicts the homepage.
"This build of Armada does not collect analytics. No tracking cookies, no telemetry, and no third-party analytics are active in the client." Privacy policy branch shown when PLAUSIBLE_DOMAIN is empty. It is empty in the 7 October bundle. window.ENV is not set on the page. The HTML loads /_npanel/script.js, which calls init({"domain":"armada.buzz","endpoint":"/_npanel/api/event",...}). Pageviews use location.href, query string included. /_npanel/errors.js records clicks, navigations (path, query, and hash), and fetch URLs, and posts them to /_npanel/api/report when an error is thrown. It scrubs nsec strings before sending. The app's own Plausible helper strips pubkeys and invite secrets. The host script does not call it.
"If you sign in with a secret key, Armada stores it on your device so you stay signed in; it is never sent to the developers or to any server." Terms, last updated 28 August 2026, in the live bundle. On the web, the login store calls localStorage.setItem. Any script on the origin can read it. The same origin loads the npanel scripts. Desktop encrypts with the OS store when that store works, and writes plaintext when it does not. Android uses the system keystore. The web-push worker also keeps the decrypt key for nsec logins so it can show notification text. The terms address the developers' servers. They leave out that the official website stores the key in the clear.
"There is no build-time relay pin at all. Every build, hosted included, has no baked-in servers, and the user adds their own." AGENTS.md in the client repo. The same file, a few paragraphs later, says Concord voice defaults to https://armada.buzz. The live platform bundle, if RELAYS is unset, uses wss://relay.ditto.pub,wss://relay.dreamith.to, writes profiles to wss://relay.primal.net, and uploads media to blossom.ditto.pub, blossom.dreamith.to, and blossom.primal.net. Ross's guide says it both ways: the app ships with their relays as the defaults, and the APK pins nothing. The fallbacks are the pin.
"Pings on Android arrive directly from your community instead of through Google's push servers, so no third party learns who messages you." Comparison essay. The Android half is real. AGENTS.md forbids Google Play Services in that build, and notifications are a WebSocket to the relays. The "so" is the stretch. The socket lands on a relay. Their recommended relay config requires the client to identify itself before it can ask for community messages. That relay learns which key is connected, from which IP. Web and iPhone users are not on this path at all. The website uses a nostr-push2 gateway plus the browser vendor's push service. iOS, in the unshipped app, uses Apple push.
"Uploaded files are generally publicly accessible via their URLs." Privacy policy, 11 July 2026. This one is more honest than the essays, and it is still blunt. Concord composer code encrypts a file before upload, so the blob on the server is ciphertext. The URL is still fetched from your IP, and the media proxy that would hide that IP is off unless you turn it on. AGENTS.md says an image in a message learns the IP of everyone who scrolls past it. NIP-29 uploads follow the policy: the file server can serve the file.
"Relays only see the encrypted ciphertext (no content or author identity) plus some metadata, including the timing of messages." Team reply on r/DiscordAlternatives, thread posted 22 July 2026. The commenter wrote that they are on the team. The same reply says maximum privacy means hosting your own relay and your own client. Ross's guide tells relay operators to leave AUTH_KINDS alone, because the default makes a client identify itself before it can request community messages. Identification is the account key. The relay also sees the IP. Timing is the metadata they admit. Identity of the reader is the metadata the guide requires.
"The answer to the question in the title is yes, all the way down, with no asterisk on the calls." Ross, self-host guide, immediately before two caveats. The next sentences: invite links on your own domain do not open in the Android app, because the app only claims armada.buzz, and on iOS the app does not claim links at all yet. Running the relay means operating OpenSearch yourself. ditto-relay, the relay they tell you to clone, ships no Dockerfile. The voice broker is open by design: anyone who finds it can use it, because it is not allowed to know who is calling.

The chart grades itself a clean yes

The 30 July comparison table gives Armada a green check for "end-to-end by default," "no company kill switch," "run your own relay," "Nostr key, no email," and "no ads, no paid tier." Matrix and another Nostr app on the same table get partial marks. Armada's partial cases are in the product the table is selling: NIP-29 and Buzz are not end-to-end encrypted, the bridge turns encryption off on purpose, and the default path is a company-operated web app, relay pair, and voice broker.

The "no ads" cell matches the live client. The KLIPY gif key, which the README says would inject sponsored results and a per-install customer id, is an empty string in the 7 October bundle. Gif search falls through to the keyless provider the README names, GIFverse. That provider still receives the search query and the viewer's IP. The live build leaves KLIPY's sponsored results off.

Bugs they wrote down

The changelog treats a few of these as fixed. They belong here because the essays say nobody can read your messages, and the changelog is where the client has already been able to.

The changelog presents these as fixed. The essays still say nobody can read your messages.