# Supergroup

Superpowered personal messaging for the AI era

- Team: Johnny Rodgers (co-founder), Jamie Scheinblum (co-founder)
- Invested: 2026
- Field: Making and talking

## The problem: How do you add an AI to a group chat without spoiling it?

### How a group chat works

In most messaging apps a service provider sits in the middle, relaying each message from the sender to everyone else. With end-to-end encryption, the message is encrypted on the sender's device so that no third party, the provider included, can decrypt it, and each recipient decrypts it on their own phone. WhatsApp, iMessage, Facebook Messenger and Signal all work this way for chat messages.

Groups make this harder. A common trick is to hand out "sender keys" over existing one-to-one secure channels, so each member encrypts messages to the group with their own key. A newer IETF standard, Messaging Layer Security, is built for groups as large as 50,000 and for people who chat from several devices.

### Why it is hard

**Keys for a crowd.** Sender keys are efficient, but they heal badly. Recovering security after a key leaks takes a number of key update messages that grows with the square of the group's size, and an attacker holding a sender key can often listen in indefinitely. MLS takes a different route, arranging the group's keys in tree structures so the whole group can refresh its keys, even when members are offline.

**The model has to read.** The big AI models run on servers, not phones, and that means the provider can see the requests. A cloud model needs unencrypted access to your request and the personal data that comes with it, which rules out end-to-end encryption. So every helpful thing an assistant does with your chat, like summarising it, pulls against the privacy people expect from a messaging app.

**Knowing when to talk.** Most dialogue research studies conversations between two parties, and group chats aren't that. In a group a model has to decide when to talk, a skill that models trained on pairwise conversations appear to lack. It also has to work out who it is answering. Everyone knows the friend who replies to every single message. Nobody wants that friend to be software.

### What Supergroup is after

Supergroup is building "super-powered group chat for you & your friends": a place for making plans and shooting the breeze, with AI built into the conversation.

### How they go at it

**An AI in the thread.** The app includes AI features such as conversational replies, image generation and assisted web search. When someone uses them, the relevant message content goes to the AI provider serving the selected model, and the answer comes back into the conversation where it was asked.

**Plans that become invites.** A scheduler helps the people in a conversation find a time to meet. Connecting a calendar is optional. If someone does, the scheduler can read when they're busy, and a time the group agrees on becomes a real calendar invitation.

**Answers everyone can see.** An answer from the assistant is a message like any other, so if you ask about your schedule in a group chat, everyone in it sees the reply. For privacy, ask in a one-to-one conversation. Location is asked for only when a feature needs it, such as showing how far away a place is, and never collected in the background.

### Still open

Can an AI read your messages without the company reading them? WhatsApp's Private Processing sends AI requests to a confidential environment where, by design, no one, including Meta and WhatsApp, can access them. Apple's Private Cloud Compute makes a similar promise for its devices. Both rest on outside security researchers being able to check that the promises hold.

When should an assistant chime in? Research systems built for group discussion split the problem into what to say, when to respond and whom to answer, and have shown they can chime in at sensible moments with small to medium groups. A recent survey argues that a working model of what each participant knows and wants, which researchers call theory of mind, is essential for doing it well.

### Words used here

- **end-to-end encryption**: Encryption where only the sender and the intended recipients hold the keys to read a message.
- **sender keys**: A key each group member uses to encrypt their messages to the whole group, shared privately with the other members.
- **Messaging Layer Security**: An internet standard for end-to-end encrypted group messaging that scales to very large groups.
- **tree structures**: Arrangements of keys in a branching hierarchy, so an update only has to touch one branch.
- **Private Processing**: WhatsApp's system for running AI on messages inside a sealed server environment that the company cannot see into.
- **theory of mind**: The ability to model what other people know, believe and intend.

## About Supergroup

Supergroup is building superpowered personal messaging for the AI era.

## Sources

1. [End-to-end encryption](https://en.wikipedia.org/wiki/End-to-end_encryption), Wikipedia
2. [RFC 9420: The Messaging Layer Security (MLS) Protocol](https://www.rfc-editor.org/rfc/rfc9420.html), IETF / RFC Editor
3. [Messaging Layer Security](https://en.wikipedia.org/wiki/Messaging_Layer_Security), Wikipedia
4. [Building Private Processing for AI tools on WhatsApp](https://engineering.fb.com/2025/04/29/security/whatsapp-private-processing-ai-tools/), Engineering at Meta
5. [Private Cloud Compute: A new frontier for AI privacy in the cloud](https://security.apple.com/blog/private-cloud-compute/), Apple Security Research
6. [Multi-Party Chat: Conversational Agents in Group Settings with Humans and Models](https://arxiv.org/abs/2304.13835), arXiv
7. [Multi-User Chat Assistant (MUCA): a Framework Using LLMs to Facilitate Group Conversations](https://arxiv.org/abs/2401.04883), arXiv
8. [Multi-Party Conversational Agents: A Survey](https://arxiv.org/abs/2505.18845), arXiv
9. [Supergroup](https://supergroup.chat/), Supergroup
10. [Supergroup Privacy Policy](https://supergroup.chat/privacy.html), Supergroup
