INVITE ONLY
OBSERVATORY

Support

A human answers.

No chatbot maze. No ticket purgatory. QERYX is invite-only, and one mailbox lands with the people who build it — the gate, the procedures, and the limits nobody can work around are all written below.

QERYX is invite-only.

An account is created with a single-use invite code issued by someone already on QERYX. There is no open sign-up, no waitlist form, and no way for us to hand a code to a stranger who writes in. If you do not have one yet, the person who told you about QERYX is the person who can give you one.

  • Code

    One code, one account. A code is spent the moment a registration completes with it. It cannot be reused, shared onward, or restored.

  • Code

    “Already used” means it was spent. Ask your inviter for a fresh one. If your sign-up was interrupted mid-way, presenting the same code again from the same device finishes the registration instead of refusing it — the code is bound to the identity it started creating.

  • Code

    A code is a key to the door, not a plan. It creates the account and nothing else. This version of QERYX sells nothing: there is no purchase, no subscription, and no tier to buy. Invited accounts reach every feature the build ships with.

Write to us. Every message is read.

One mailbox, read by the people who build QERYX. Put the tag in the subject line and it is routed accordingly.

Help, accounts, and bugs

What you did, what you expected, what happened. Include your version and build: open Profile and read them from the ABOUT section at the bottom of that screen. No crash reporter is embedded in the app, so nothing is collected in the background — what you write is what we get.

support@qeryx.com

Security vulnerabilities — subject: SECURITY

Coordinated disclosure with a safe harbor. Scope, keys, and the rules of engagement are on the bug bounty page.

support@qeryx.com

Abuse reports — subject: ABUSE

Violations of the Acceptable Use Policy. Name what happened; we cannot read the conversation it happened in.

support@qeryx.com

Press — subject: PRESS

Materials and technical interviews — see /press.

support@qeryx.com

What we cannot do.

QERYX is zero-knowledge by design. Some things other services do for their users, we deliberately cannot — the same capability would be a surveillance backdoor.

No key-escrow · No master reset

We cannot recover your messages or your account if you lose your device and your Secret Phrase. There is no key-escrow and no master reset.

  • Cannot

    Reset a lost Secret Phrase. Only you hold it. A reset path for us would be a reset path for anyone who could compel us.

  • Cannot

    Retrieve message content for you. We never hold it in plaintext — your history is encrypted to your device, not to us.

  • Cannot

    Produce a plaintext contact list or conversation history. The relay routes by opaque identifiers; undelivered messages queue with routing metadata under a published retention ladder.

  • Cannot

    Reach into someone else's phone. Messages already delivered to your contacts live on their devices; deleting your account does not delete their copies.

  • Cannot

    Issue you an invite code. Codes come from members, not from this mailbox. Writing in does not move you up a queue, because there is no queue.

Before you write.

How fast do you respond?

As fast as a small team honestly can. There is no SLA theater: security reports take priority, and every message gets a human reply.

Those two values are your Recovery Credentials — the app shows them under Profile → Recovery Credentials, behind a biometric check. Together with your encrypted backup they are the only door back into your account. If you still have the device, open that screen now and write them down somewhere only you can reach. If you have lost both the device and the phrase, the account is unrecoverable — by you, by us, by anyone. The full procedure is on recover your access.

Codes are single-use, so a spent code stays spent. Ask your inviter for a fresh one. The exception is an interrupted sign-up: presenting the same code again from the same device finishes the registration it started, because the code is bound to the identity being created. We cannot issue codes from this mailbox.

It leaves your device readable. The assistant is the one surface in QERYX that is not end-to-end encrypted: the text you send it, and any image you attach, are forwarded by the relay to an AI processing provider to produce the reply. Your assistant history syncs as a blob encrypted on your device and is deleted after 90 days. Your conversations with people never take that path — nothing you write to a contact, a group, or a channel is sent to any model. The exact extent is written out in the privacy policy, section 03.

No. The relay cannot read messages, and neither can we. No crash reporter and no analytics SDK is embedded in the app, so nothing is collected in the background either — a diagnostic reaches us only when you write it into an email yourself.

No. The Hydra SIM surface is present in the build, but live carrier provisioning is not connected to this server: the storefront stays dark, with no plans listed and no checkout. Nothing there can be bought and nothing is charged. Messaging, calls, and every other part of the app are unaffected. When provisioning turns on, the procedure is published here first.

No. Email only — it keeps the channel verifiable and keeps us honest about what we can promise.

Not yet. A live status surface ships with the account area; until then, incidents are announced in the changelog. Every value on this site is true or absent — we do not decorate.

Ask a human.

support@qeryx.com — no chatbot between you and an answer.