← Back to home Help

Frequently asked questions

Straight answers about how Qwing protects your messages, what the server can and can't see, and how the wallet and recovery work.

Encryption & the post-quantum question

Is Qwing really end-to-end encrypted?

Yes. Message text, files, voice notes, call audio and video, and even your profile name and avatar are encrypted on your device and only decrypted on your recipient's device. The keys never reach the server, so the server only ever relays opaque ciphertext. One exception: a profile photo set with an earlier version of the app was uploaded unencrypted and can still be on our server until you change or remove it or delete your account — see the privacy policy.

The encryption is on by default and there is no setting to turn it off. There is no “cloud” copy of your messages in plaintext anywhere.

What does “post-quantum” actually mean?

Most of today's encryption — RSA, elliptic curves — would break the day a large enough quantum computer exists. Post-quantum algorithms are built on math that quantum computers do not shortcut.

Qwing uses hybrid encryption: every key exchange combines the classical X25519 with ML-KEM-1024 (NIST FIPS 203), and identity signatures combine Ed25519 with ML-DSA-87 (NIST FIPS 204). ML-KEM-1024 and ML-DSA-87 are NIST-standardized lattice cryptography at the highest security level. A key made this way stays secret unless both X25519 and ML-KEM-1024 are broken. This protects the end-to-end layer: your messages and the keys for call media. The connection to our server (TLS) and the outer layer of calls (DTLS-SRTP) use standard, non-post-quantum cryptography.

Which exact algorithms does Qwing use?

X25519 + ML-KEM-1024 (FIPS 203) — hybrid key exchange: both are combined into one key when a conversation starts, in the ratchet, and for calls. Qwing uses the largest, highest-security ML-KEM variant.

Ed25519 + ML-DSA-87 (FIPS 204) — hybrid identity signatures, on your identity keys and prekeys, on the messages that start a conversation, and on call offers and answers.

XChaCha20-Poly1305 — the symmetric cipher that encrypts each message once a key is established.

AES-GCM — encrypts the audio and video of a call, with keys from the call's hybrid key exchange.

Ratchet — every message uses its own key, which is deleted after use (forward secrecy). Each side regularly mixes a fresh X25519 + ML-KEM-1024 exchange into its keys, so if a device's keys are stolen, the messages it sends after its next fresh exchange are protected again against someone who only listens (post-compromise security).

ML-KEM-1024 and ML-DSA-87 are the parameter sets in NIST's highest security category (Level 5).

Why bother now, if cryptographically-relevant quantum computers don't exist yet?

Because of “harvest now, decrypt later.” An adversary can record your encrypted traffic today, store it, and decrypt it years from now once the hardware exists. Anything protected only by classical math is on borrowed time.

A message you send through Qwing today is meant to stay private long after the quantum era begins — that is the whole point of migrating first instead of last.

What the server can see

Can the server read my messages?

No. Content is encrypted on your device with keys the server never sees. Messages, photos, files and voice notes go through the server, as ciphertext. Calls go directly peer-to-peer when the network allows, and the server only helps the devices find each other.

A message is stored on the server as opaque ciphertext until the recipient's device fetches it, and deleted about five minutes after delivery, or 30 days after it was sent if it is never delivered. Encrypted attachments are kept for up to 7 days, Vault files until you delete them, and encrypted backups of the server database are kept for 30 days. If we were compelled to hand over data, that is what exists — and we cannot decrypt the content of any of it.

Can the server see who I'm talking to?

The server can see which accounts exchange messages, but never what they say.

Do I need a phone number or email to sign up?

No. Your identity in Qwing is a set of cryptographic keys generated on your device — no phone number, no email, no SIM, no address-book upload. You share a contact by a link or QR code (qwing.app/add/<id>). There is no global directory of users, by design.

What metadata do you actually keep?

The server holds a random account ID, your public keys and prekeys, an optional username, your encrypted profile and encrypted contact backup, the delivery tokens you give your contacts, the list of accounts you have blocked and any reports you file, your most recent push token, queued ciphertext envelopes (deleted about five minutes after delivery, or after 30 days if never delivered), encrypted attachments and Vault files, a profile photo you set with an earlier app version (stored unencrypted until you change or remove it or delete your account), and encrypted backups of the database kept for 30 days. When your device connects, the server necessarily sees your IP for the duration of the connection, retained only briefly in rotating logs for abuse protection. We do not keep server-side message logs, “last seen” timestamps, or read receipts. The Privacy Policy has the full retention table.

Calls, devices & safety

What protects my voice and video calls?

Calls are end-to-end encrypted and routed peer-to-peer by default. The call is set up with end-to-end encrypted messages signed with both parties' hybrid keys (Ed25519 + ML-DSA-87), and its keys come from a hybrid X25519 + ML-KEM-1024 exchange. Each direction's audio and video is encrypted with its own key (AES-GCM), inside the standard WebRTC transport encryption (DTLS-SRTP, which is not post-quantum) — so media is encrypted twice. If the network forces a relay (a strict firewall or NAT), the relay handles encrypted packets only: it never holds keys and never sees your audio or video, but it sees both parties' IP addresses.

How do I know I'm talking to the right person, not a man-in-the-middle?

Compare the in-app safety number with your contact, or scan their QR code in person. If it matches, the keys your app uses for that contact are theirs, and messages and calls with them are protected against someone in the middle. Until you verify, your app trusts the keys it first received for that contact.

Calls in Qwing 2.0 do not show a spoken safety phrase; it is not in this version.

What if my phone is lost or stolen?

Your local message database is encrypted at rest. The app can be gated by a PIN, and you can set self-destruct timers per chat. A separate panic PIN wipes local data immediately when entered at the lock screen, and notifications can be set to never reveal the sender or content on the lock screen.

Can I move to a new phone?

Yes. Your new phone scans an animated QR code shown by your old phone, and you confirm the transfer with a 12-digit code. Your account, contacts and message history travel directly between your two phones, encrypted to a key your new phone made — never through our server. The old phone then stops working for the account. Your recovery phrase is the backstop if you lose a device: it can restore your identity and your wallet. Keep it somewhere safe and offline; anyone who has it has your account.

The wallet

Is the wallet self-custodial? What can it do?

Qwing includes a self-custodial wallet. Your keys are derived from your recovery phrase and stored only on your device — Qwing never holds them and never can. The wallet signs and broadcasts real transactions across multiple EVM-compatible networks; those transactions are recorded permanently on-chain and are irreversible.

Because it is non-custodial, Qwing cannot reverse, freeze, or recover a transaction or any lost funds, and a third-party RPC provider can see your wallet address and IP when you broadcast. Read the full Wallet Disclosure before you send anything.

What happens to my funds if I lose my recovery phrase?

If you lose your device and your recovery phrase, your funds are permanently unrecoverable. There is no reset and no support path that can retrieve them — that is the trade-off of true self-custody. Back up your recovery phrase offline, and never share it with anyone. Qwing will never ask you for it.

Account & availability

How do I delete my account?

In the app, go to Settings → Delete account and confirm. This calls the server to remove your data and wipes the app's local data on your device in one step. Messages already delivered to your contacts stay on their devices, and on-chain transactions remain public. Full detail and timeline are on the Account Deletion page.

Which platforms is Qwing available on?

Qwing runs on iOS and Android. The cryptography stack and call protocol are implemented to the same standard on both so the two platforms interoperate.

What happens if Qwing shuts down?

Your local message database stays on your device, encrypted with your key — your messages were never uploaded in plaintext, so there is no cloud lock-in. What you would lose is delivery of new messages. Your self-custodial wallet is independent of Qwing's servers: as long as you have your recovery phrase, you can restore it in any compatible wallet.

Still have questions?