StegoChat — User Manual
Website
https://stego.shimpinomori.net
What this manual is for
Step-by-step help for using StegoChat on a phone or computer: create an
account, encode a secret into cover text, paste it into any messenger,
and decode a cover you received.
Important
- StegoChat is not a messenger. It only prepares and recovers text. You still send messages with WhatsApp, Telegram, Signal, iMessage, or any other app.
- Two people must share the same conversation topic, the same secret phrase, and the same cover language.
- The cover text may look a bit odd or fail a spell-checker. That can be normal. What matters is that decode recovers the secret.
- You can keep several conversations (several topics); each has its own phrase, your display name, and its own chain history.
You can switch the site language with the flags at the top of the page (French, English, German, Japanese, Russian).
Table of contents
- What you can do
- Open the site
- Email and account
- Vault: saved conversations
- Before the first message (shared setup)
- Encode a secret (send)
- Decode a cover (receive)
- Conversation chain and sync
- Credits and GPU
- Phone: long waits and recovery
- Tips and common problems
- When you need help
1. What you can do
| Term | Meaning |
|---|---|
| Secret | The real message only you and your partner should read |
| Cover | Innocent-looking text that hides the secret (what you paste into WhatsApp, etc.) |
| Topic / conversation | Shared label for this thread (part of the crypto key; do not rename once started) |
| Secret phrase | A long shared password (min. 16 characters) |
| Cover language | Language of the generated cover (both parties must match) |
| My name | Your sender identity in this conversation (used when encoding) |
| Sent by | Who produced the cover you are decoding (required; any participant) |
| Chain | History of covers already used; both sides must stay in the same order |
| Vault | Encrypted backup of your conversations (topic, phrase, name, language, chain) |
Basic flow (4 steps)
- Both of you create an account and verify email.
- Agree offline on topic + secret phrase + cover language + display
names.
- One person encodes, copies the cover, pastes it
into a messenger.
- The other pastes the cover into StegoChat and decodes the secret (stating who sent the cover).
2. Open the site
Computer
- Open a browser (Chrome, Firefox, Safari, Edge…).
- Go to:
https://stego.shimpinomori.net
- You should see the welcome page with logo and QR code.
Phone
- Open the same URL, or scan the QR code on the home
page.
- Optional: use Add to home screen at the bottom of the page so it opens like an app.
3. Email and account
Sign up
- Tap Sign up.
- Enter name, email, and a strong password (12+ characters, upper,
lower, digit, symbol).
- Complete the captcha if shown.
- Check your email and open the verification link.
Login
Use Log in with your email and password.
Your account password also unlocks the conversation vault. After a normal password login, the vault unlocks automatically in the same browser.
Email in spam
Verification and password emails often land in Spam / Junk / Promotions. Check there first.
Profile
After login, Profile lets you change your display name and preferred language.
4. Vault: saved conversations
StegoChat can remember several conversations so you do not retype topic, phrase, and your name every time.
What is saved (per conversation)
- Topic
- Shared secret phrase
- Your name in that conversation
- Cover language
- Chain history and sync code
Security
- Data is encrypted in the browser (account password)
before upload.
- The server only stores an encrypted blob — it does
not see the phrase in clear text.
- A local mirror may also exist on the same device for faster restore.
When saving happens
- On the first successful encode of a new topic, a
profile is created in the vault.
- Later encodes/decodes update the chain for that
topic.
- You can juggle several topics with the conversation selector at the top of the tool.
Unlocking
| Situation | What happens |
|---|---|
| Login with password | Vault unlocks automatically on the tool |
| Magic link / other device / auto-unlock failed | Unlock saved conversations panel: enter account password once |
| Account password changed | Old vault unreadable → Reset vault, then re-enter settings (covers already exchanged still work if everyone still shares the same phrase) |
Conversation selector
- New conversation: free topic, phrase, your name,
language.
- Existing conversation: fields auto-fill; the topic
is locked (renaming would break crypto).
- Sent by (decode) is not filled with your name: it must name the other person (or a third party). Suggestions come from history.
5. Before the first message (shared setup)
Meet in person (or by a channel you already trust) and agree on:
- Conversation topic — example:
weekend-plansor a private joke.
- Secret phrase — at least 16
characters, hard to guess (several random words).
- Cover language — e.g. both choose
French.
- Display names — how each person is called in this
thread (
alice,bob…).
Type them exactly the same on both sides (spaces and accents matter).
Do not put the secret phrase in the public messenger chat.
6. Encode a secret (send)
- Open Tool (after login; unlock vault if
needed).
- Pick an existing conversation or New
conversation.
- Check / fill:
- Topic
- Secret phrase
- My name in this conversation
- Cover language
- Topic
- Open the Encode tab.
- Type the secret message. Shorter secrets usually
need shorter covers.
- Tap Generate cover — the button shows 1
credit if the shared GPU is warm, or 3 credits
if cold.
- Wait until generation finishes (GPU banner may say “in use — job
running”; that can be your job).
- When the cover is final, use Copy
cover.
- If the cover is missing (phone switched apps): Recover last
result.
- Paste the cover into WhatsApp / Telegram / … and send it as a normal message.
About cover text
- It is meant to look like casual chat.
- Spell-check may underline words. That does not mean decode will
fail.
- Do not edit the cover by hand before sending (typos break
decode).
- A somewhat long cover is not always a bug: steganography has technical overhead.
7. Decode a cover (receive)
- Open Tool (same conversation as the sender).
- Same topic, secret phrase, and cover language.
- Open the Decode tab.
- Sent by = the display name the other person used
when encoding (required). Use suggestions when
available.
- Paste the exact cover from the messenger (whole
message).
- Tap Decode.
- Read the recovered secret.
- If the UI is empty after a long wait: Recover last result.
If decode fails: check message order, exact paste, matching settings, and the sender name.
8. Conversation chain and sync
StegoChat keeps a chain: each new cover depends on previous ones.
- Encode and decode in the same order as messages
appear in the messenger.
- Do not skip a cover — later messages will
fail.
- A banner under the settings shows message count,
next index, sync code (when known),
and a short list of recent covers.
- After success, a sync code may appear — useful to
check alignment.
- Reset local chain clears history for this topic on this device/vault. To restart together, both must reset (or start a new topic).
More than two people
The chain is not limited to a pair. Each message has a sender. On decode, Sent by names who produced the cover (not a single automatic “them”).
Skipped message or wrong order
Errors about chain index or sender sequence usually mean:
- a cover was not decoded into the local chain, or
- StegoChat order does not match messenger order.
Fix: decode missing covers in order, or reset on both sides and restart (last resort).
When operators change the protocol (e.g. model upgrade), create a new topic or reset chains on both sides.
9. Credits and GPU
Encoding and decoding use a remote GPU (language model).
| Shared GPU status (banner) | What it means | Button / cost |
|---|---|---|
| Warm — ready | Worker recently used; free for a new job | 1 credit |
| Warm — in use (job running) | An encode/decode is running (yours or another user’s) | 1 credit (your job queues if it is not yours) |
| Cold / scaled to zero | No recent activity; first job may start the worker | 3 credits |
| Loading | Worker is booting / loading the model | Wait or start anyway |
- The GPU banner is live and shared. It is
not clickable and does not wake the
GPU by itself.
- Button labels follow that status: you should not
see “3 credits” when the system already knows the GPU is warm.
- Only one encode/decode job uses the GPU at a
time.
- Free accounts may exist for operators; others buy packs in the Shop.
10. Phone: long waits and recovery
An encode can take several minutes (especially on a cold GPU start).
- You may switch apps while waiting.
- When you return, job status is reloaded and the
cover should reappear.
- If browser storage was cleared: Recover last result
(server keeps the finished result for a limited time, typically up to
~24 hours).
- The active job id is also stored so an in-progress job can resume after a tab close.
11. Tips and common problems
| Problem | What to try |
|---|---|
| Decode error | Exact paste; same topic, phrase, language; correct Sent by; same message order; right conversation in the selector |
| Missing message / wrong order | Decode intermediate covers, or both sides reset chain |
| “No credits” | Buy a pack or ask an admin for a grant |
| Long wait | Cold or busy GPU: job stays queued; you can leave the app and come back |
| Cover looks weird | Normal under steganography; if decode works, you are fine |
| Copy greyed out | Wait until done or use Recover last result |
| Vault unreadable | Wrong password or password changed → manual unlock or Reset vault |
| Two people out of sync | Both reset chain (or new topic) and restart |
Privacy
- Prefer not to log secrets.
- The cover goes through your usual messenger.
- The vault is encrypted; the server does not see the phrase in
clear.
- StegoChat transforms text; it does not transport messages for you.
12. When you need help
Contact the operator of your deployment (e.g. site admin /
Shimpinomori).
Have ready: approximate time, encode or decode, credits or GPU wait —
do not send secret phrases or secret messages in clear
email if you can avoid it.
StegoChat — encode/decode cover text for any
messenger.
Provided by Shimpinomori.NET