Kotlin library & app · Android 7.0+ · Windows (beta)
Flash
A Kotlin library and app for offline file transfer, chat and calls between nearby devices. No server, no internet, no account.
- 0servers, accounts or internet needed
- 12published library modules
- AES-256GCM end-to-end encryption (v2 beta)
- 2platforms, Android and Windows (v2 beta)
The problem
Sending a large video or a folder to the phone or laptop next to you usually goes through the internet: a cloud upload, a messaging app that compresses the file, or an account on both sides. That is slow, uses mobile data, and fails completely when there is no connection.
What I built
Flash finds nearby devices on the same Wi-Fi network or phone hotspot and opens a direct, encrypted channel between them. Files, chat and calls travel straight across the local network. Nothing leaves it, and there is no backend to run.
- File transfer with live progress, and resume after an interruption, even across app restarts.
- Chat between nearby devices, including replies, reactions and typing indicators.
- Voice and video calls over the same local connection.
- An SDK for other apps. One call,
Flash.create(...), starts discovery, networking and transfers, and oneclose()shuts them down.
Use it in your own app
Flash is a library first. The app is built on the same 12 modules that other developers can add to their own Android apps from JitPack:
- One call to start.
Flash.create(context, config)starts discovery, networking and transfers on one shared coroutine scope;close()shuts all of it down. - Take only what you need. A transfer-only app can use just the discovery, network and transfer modules and skip the encrypted database and its native libraries. Calling is a separate module because WebRTC adds about 30 MB per CPU architecture.
- UI is optional. The Compose UI modules are stateless: each screen takes a state object and callbacks, so an app can reuse Flash’s screens over its own data, or use the engine with no UI at all.
- A written contract. Every core module compiles in Kotlin’s strict explicit-API mode, and the public API is documented type by type.
The library docs cover installation, the quick start, every public interface, the wire protocol and the security model.
How it works
- Discovery without location access. Devices find each other with Android NSD (mDNS), not a Wi-Fi or Bluetooth scan, so Flash needs no location permission.
- Small modules. The engine is split into modules for discovery, networking, transfer, security, storage, messaging and calling, plus Compose UI modules. An app can take the whole engine or only the lightweight transport pieces. The library modules ship no manifest, so they never add permissions an app did not ask for.
- Calls that stay intelligible. On a shared phone hotspot, video used to crowd out voice. Audio now gets priority in the bandwidth allocator, and a governor checks call quality every second. When audio degrades, it lowers video bitrate, then resolution, then drops video, and only restores it after several clean samples.
- Encrypted storage. Transfer state and messages are stored in a SQLCipher database with a key kept in the Android Keystore.
Version 2 (beta)
The v2.0.0 beta adds two layers of security and a second platform:
- TLS 1.3 between devices with trust-on-first-use certificate pinning, plus pairwise AES-256-GCM encryption of messages and file chunks (ECDH P-256 key agreement, HKDF-SHA256 session keys). Users can compare safety numbers to verify a device.
- A Windows desktop app with
.exeand.msiinstallers that bundle their own runtime, a tray mode, drag-and-drop folder transfers and taskbar badges. - Android system integration: share straight from other apps, a Quick Settings tile, app shortcuts and a two-pane layout on tablets and foldables.
Engineering practice
CI builds the app and runs the unit tests on every push to main and on every pull request. A sample consumer app compiles the README’s quick-start code verbatim, so the documented API cannot drift from the real one.