INVITE ONLY
OBSERVATORY

Solutions · 01

Privacy you would want for your family.

On by default, at maximum, for everyone you talk to. A fresh key for every message you send — and a relay that cannot read a single one.

Q-RATCHET ML-KEM-1024 + X25519 No phone number required

Walk one ordinary day, sealed end to end.

  • 07:42

    You send the school-run photo.

    Sealed on your phone under a fresh Q-Ratchet key before it leaves your hand. The relay carries ciphertext it cannot open.

    ChaCha20-Poly1305
  • 13:05

    You call your mother.

    The call is keyed by the same hybrid handshake as your messages and routed through the relay, so your home address is not handed to the network.

    ML-KEM-1024 + X25519
  • 18:30

    The family group plans the weekend.

    Group name, subject, avatar, and every word are end-to-end encrypted. The relay holds opaque routing identifiers.

    Q-GROUPCIPHER
  • 22:15

    You delete a message you regret.

    Deletion is a true erasure on your device, and delivered messages are erased from the relay on acknowledgment — not flagged, gone.

    ERASURE

Read everything the relay holds of that photo.

Sealed envelope — in transit field shapes are real · values illustrative
payload
ciphertext — ChaCha20-Poly1305, sealed on your device
route_id
opaque identifier — maps to no name, no number
sender
stripped from the stored row (sealed-sender v2); authenticated at send time
your phone number
never collected — identity keys are generated on your device (ML-DSA-87)
after delivery
erased on acknowledgment; undelivered messages queue with routing metadata under a published retention ladder

The server is a dumb encrypted blob relay. It cannot read messages.

Take a fresh key for every message

Q-Ratchet advances the key with every message you send. A key stolen today opens nothing you said yesterday, and the conversation heals forward on its own — the stolen key goes stale in your next breath.

Make today’s recording worthless in ten years

Adversaries already record encrypted traffic to decrypt later, once quantum computers mature — the migration deadlines in national standards exist because of it. Every QERYX session is keyed by hybrid ML-KEM-1024 (FIPS 203) + X25519, so reading a recorded session requires breaking both.

Know what we cannot do — on purpose

We cannot recover your messages or your account if you lose your device and your Secret Phrase. There is no key-escrow and no master reset. That limit is the design: a recovery door for you would be a recovery door for anyone.

Ask the four that decide it.

Can QERYX read my messages?

No. Messages are sealed on your device before they travel; the relay holds ciphertext and opaque routing identifiers. There is no plaintext on our side to read, hand over, or lose.

Do I need a phone number?

No. Your identity is a keypair (ML-DSA-87) generated on your device. Nothing about signing up asks who you are.

Why will there never be a free tier?

v1 sells nothing. Every invited account carries every capability in this build, and no screen in the app takes money. When the tiers open there is no free seat, because a free seat is paid for with the person sitting in it. The subscription is the entire business — no advertising, no data sales, no telemetry product.

What happens when I change tiers?

When the tiers open, retiring one is a billing-state change and never a data event. Identity keys, IDs, history, contacts, vault, mail, and memberships are preserved. Higher-tier app tiles stay visible with an unlock badge, and every conversation keeps its maximum security either way.

Bring your people with you.

Maximum for you is maximum for them — the floor is universal.