End-to-end, always
Messages are encrypted on your device and only decrypted on your recipient's. The server relays ciphertext it can't read, then deletes it about five minutes after delivery. There is no plaintext copy to leak, subpoena, or sell.
Qwing encrypts every message, call and file end to end with hybrid cryptography — classical X25519 and Ed25519 paired with lattice-based ML-KEM-1024 and ML-DSA-87, built to resist quantum computers — no phone number, and no data sold to anyone. The structure that protects you is the same structure that will still hold when the machines arrive.
Fast, familiar messaging — 1:1 and group chats, voice & video calls, and an encrypted file vault. The lattice does the hard part; you just talk.



Other apps ask you to believe a privacy policy. Here is what our relay stores for each message, field by field. Type a message on the right to see an illustration: the fields are the real ones, the values are made up on this page, and nothing you type is sent anywhere. The envelope is opaque ciphertext padded to a fixed size; next to it the server keeps the recipient and the arrival and delivery times.
on your device — readable plaintext, never leaves encrypted
on our server — the stored message row (illustrative values)
Most apps ask you to trust their policy. Qwing removes the data they'd have to be trusted with. Four design choices do the work — here's what each one actually means for you.
Messages are encrypted on your device and only decrypted on your recipient's. The server relays ciphertext it can't read, then deletes it about five minutes after delivery. There is no plaintext copy to leak, subpoena, or sell.
Every message is stored with no sender ID and no sender hint. Even if our database or backups were stolen or requested by a court, they would not show who wrote to whom. Your contact list is not stored on the server in readable form.
Voice and video calls go directly between devices when the network allows; the server helps two phones find each other, and relaying is a fallback, never the default. Photos, files and voice notes are uploaded to the server encrypted and deleted 7 days later.
Sign up with nothing tied to your real-world identity. No SIM, no inbox, no address book upload. You share a contact with a deep link — qwing.app/add/<id>.
The hard part isn't adding features. It's making each one earn the same guarantees as the last. Messages, calls and phone transfer run on the same hybrid post-quantum core; the Vault uses AES-256 with a key only your phone holds, and the wallet uses each blockchain's own signatures.
Private threads and groups with the same end-to-end protection. Plus disappearing messages and view-once media for the things that shouldn't outlive the moment.
disappearing · view-onceVoice and video, encrypted end-to-end with keys from a hybrid X25519 + ML-KEM-1024 exchange, set up with signed offers and answers, and routed peer-to-peer where the network allows.
voice · video · P2PA private store for your files. Each file is encrypted on your phone (AES-256-GCM) before it is uploaded, and our server keeps only ciphertext it cannot read, until you delete the file or your account. The server sees each file's size and upload time; the file name is encrypted too.
encrypted before uploadA multi-chain wallet that lives in the same app and the same trust model. Your keys stay on your device — Qwing never holds them, and never can.
multi-chain · self-custodialMove to a new phone by scanning an animated QR code and confirming a 12-digit code — your account and history travel directly between your phones, encrypted, never through a server. A recovery phrase is your backstop if a device is lost.
animated-QR · 12-digit code · recovery phraseEvery message gets its own key, deleted after use, so a key stolen today can't unlock yesterday. Each side regularly mixes in a fresh hybrid key exchange, so what it sends after that is protected again from an eavesdropper holding stolen keys. Forward secrecy and post-compromise security, on for everyone, with no settings to find.
ratchet · FS + PCSIt's called harvest-now, decrypt-later: capture encrypted traffic today, store it, and break it once a quantum computer can. Anything protected only by classical math — RSA, elliptic curves — is on borrowed time. Qwing pairs classical elliptic-curve keys with lattice-based ones, chosen precisely because that machine doesn't help an attacker solve them: to decrypt recorded messages, an attacker has to break both. Encrypt a message in Qwing today, and it's meant to stay private long after the quantum era begins.
No phone number. No email. Install Qwing, share your link, and you're talking inside the lattice in under a minute.