← PortfolioMaking and talking

Supergroup

Superpowered personal messaging for the AI era

Team
Johnny Rodgersco-founder
Jamie Scheinblumco-founder
Invested
2026
The problem

How do you add an AI to a group chat without spoiling it?

Click a friend's row in the scheduler to connect or disconnect their calendar. Press and hold anywhere else to ask the AI one to one instead of in the group.Friends plan dinner in a group chat. The scheduler reads the busy evenings of whoever connected a calendar, finds one that is free for all of them, and the time they agree on becomes an invite. When someone asks the AI, the messages that request needs go out to the provider serving the model, and the answer comes back as a message the whole group can see. Asked one to one, only you see it.An illustration, not real data.
How a group chat works

In most messaging apps a service provider sits in the middle, relaying each message from the sender to everyone else. With , the message is encrypted on the sender's device so that no third party, the provider included, can decrypt it, and each recipient decrypts it on their own phone. WhatsApp, iMessage, Facebook Messenger and Signal all work this way for chat messages.

Groups make this harder. A common trick is to hand out "" over existing one-to-one secure channels, so each member encrypts messages to the group with their own key. A newer IETF standard, , is built for groups as large as 50,000 and for people who chat from several devices.

Further reading End-to-end encryption (Wikipedia)RFC 9420: The Messaging Layer Security (MLS) Protocol (IETF / RFC Editor)Messaging Layer Security (Wikipedia)

Why it is hard
  1. i.

    Keys for a crowd

    Sender keys are efficient, but they heal badly. Recovering security after a key leaks takes a number of key update messages that grows with the square of the group's size, and an attacker holding a sender key can often listen in indefinitely. MLS takes a different route, arranging the group's keys in so the whole group can refresh its keys, even when members are offline.

  2. ii.

    The model has to read

    The big AI models run on servers, not phones, and that means the provider can see the requests. A cloud model needs unencrypted access to your request and the personal data that comes with it, which rules out end-to-end encryption. So every helpful thing an assistant does with your chat, like summarising it, pulls against the privacy people expect from a messaging app.

  3. iii.

    Knowing when to talk

    Most dialogue research studies conversations between two parties, and group chats aren't that. In a group a model has to decide when to talk, a skill that models trained on pairwise conversations appear to lack. It also has to work out who it is answering. Everyone knows the friend who replies to every single message. Nobody wants that friend to be software.

Further reading RFC 9420: The Messaging Layer Security (MLS) Protocol (IETF / RFC Editor)Building Private Processing for AI tools on WhatsApp (Engineering at Meta)Private Cloud Compute: A new frontier for AI privacy in the cloud (Apple Security Research)Multi-Party Chat: Conversational Agents in Group Settings with Humans and Models (arXiv)Multi-User Chat Assistant (MUCA): a Framework Using LLMs to Facilitate Group Conversations (arXiv)

What Supergroup is after

Supergroup is building "super-powered group chat for you & your friends": a place for making plans and shooting the breeze, with AI built into the conversation.

Further reading Supergroup (Supergroup)

How they go at it
  1. Step 1: An AI in the thread

    The app includes AI features such as conversational replies, image generation and assisted web search. When someone uses them, the relevant message content goes to the AI provider serving the selected model, and the answer comes back into the conversation where it was asked.

  2. Step 2: Plans that become invites

    A scheduler helps the people in a conversation find a time to meet. Connecting a calendar is optional. If someone does, the scheduler can read when they're busy, and a time the group agrees on becomes a real calendar invitation.

  3. Step 3: Answers everyone can see

    An answer from the assistant is a message like any other, so if you ask about your schedule in a group chat, everyone in it sees the reply. For privacy, ask in a one-to-one conversation. Location is asked for only when a feature needs it, such as showing how far away a place is, and never collected in the background.

Further reading Supergroup Privacy Policy (Supergroup)

Still open
  • Can an AI read your messages without the company reading them?

    WhatsApp's sends AI requests to a confidential environment where, by design, no one, including Meta and WhatsApp, can access them. Apple's Private Cloud Compute makes a similar promise for its devices. Both rest on outside security researchers being able to check that the promises hold.

  • When should an assistant chime in?

    Research systems built for group discussion split the problem into what to say, when to respond and whom to answer, and have shown they can chime in at sensible moments with small to medium groups. A recent survey argues that a working model of what each participant knows and wants, which researchers call , is essential for doing it well.

Further reading Building Private Processing for AI tools on WhatsApp (Engineering at Meta)Private Cloud Compute: A new frontier for AI privacy in the cloud (Apple Security Research)Multi-User Chat Assistant (MUCA): a Framework Using LLMs to Facilitate Group Conversations (arXiv)Multi-Party Conversational Agents: A Survey (arXiv)

About Supergroup

Supergroup is building superpowered personal messaging for the AI era.

Words used here
end-to-end encryption
Encryption where only the sender and the intended recipients hold the keys to read a message.
sender keys
A key each group member uses to encrypt their messages to the whole group, shared privately with the other members.
Messaging Layer Security
An internet standard for end-to-end encrypted group messaging that scales to very large groups.
tree structures
Arrangements of keys in a branching hierarchy, so an update only has to touch one branch.
Private Processing
WhatsApp's system for running AI on messages inside a sealed server environment that the company cannot see into.
theory of mind
The ability to model what other people know, believe and intend.
Sources