EN RO RU FR

Frequently Asked Questions

QRChat v4.0.0 — Last updated: March 21, 2026

Jump to

Getting Started Security & Privacy Messages & Media Calls Account & Data Troubleshooting Other

Getting Started

What is QRChat?

QRChat is a private, end-to-end encrypted messenger. Unlike other messaging apps, QRChat does not require your phone number or email address. You add contacts by scanning a QR code in person, ensuring that only people you physically meet can message you.

All messages are encrypted on your device before being sent, and only the recipient can decrypt them. Not even QRChat servers can read your messages.

How do I add a contact?

To add a contact, both users need to be in the same location:

  • Open QRChat and go to Contacts tab
  • Tap the QR code icon
  • One person shows their QR code, the other scans it
  • Both devices exchange cryptographic keys securely
  • The contact appears in your list — you can start chatting immediately
You can also send a contact request remotely if someone shares their QR code as an image, but scanning in person is the most secure method.
Do I need a phone number or email?

No. QRChat does not require any personal information to use. There is no registration, no phone number verification, and no email address needed. Your identity is a cryptographic key pair generated locally on your device.

How do I change the language or theme?

QRChat supports 4 languages (English, Romanian, Russian, French) and 2 themes (Light and Dark):

  • Go to Settings (gear icon)
  • Select your preferred Language
  • Select your preferred Theme

Changes are applied instantly. You can also choose the language and theme during the initial setup.

Security & Privacy

What encryption does QRChat use?

QRChat uses military-grade encryption powered by the TweetNaCl library:

  • X25519 — Key exchange (Diffie-Hellman on Curve25519)
  • XSalsa20-Poly1305 — Message encryption with authentication
  • Ed25519 — Digital signatures for identity verification
  • Double Ratchet — Forward secrecy (each message uses a unique key)
  • SQLCipher — Local database encryption (AES-256)
Even if someone compromises a message key, they cannot decrypt past or future messages — this is called forward secrecy.
Can anyone read my messages?

No. Messages are encrypted on your device and can only be decrypted by the recipient. The QRChat server only relays encrypted data — it cannot see message contents, attachments, or call audio/video.

There are no backdoors, no master keys, and no way for QRChat developers to access your conversations.

Where are my encryption keys stored?

Your private keys are stored in the iOS Keychain with the highest protection level (WHEN_UNLOCKED_THIS_DEVICE_ONLY). This means:

  • Keys are accessible only when your device is unlocked
  • Keys never leave your device
  • Keys are not included in iCloud backups
  • Keys are protected by your device's Secure Enclave
Does QRChat collect any personal data?

No. QRChat has a zero-knowledge architecture:

  • No personal information is required to use the app
  • No analytics or tracking
  • No advertising
  • No access to your phone contacts (optional, only for display)
  • Message content is never accessible to the server

Read our full Privacy Policy for details.

Messages & Media

What is the file size limit?

The maximum file size for transfers is 25 MB. This applies to photos, videos, documents, and other files. Files are transferred peer-to-peer via WebRTC when possible, or through the encrypted relay server.

Can I send photos and videos?

Yes. You can send photos and videos from your camera or gallery. Tap the camera icon in the message input bar. Multiple photos sent within a minute are automatically grouped into an album grid.

Can I delete messages?

Yes. Long-press on any message to see options including Delete. You can delete messages for yourself. Deleted messages are removed from your local database permanently.

What do the check marks mean?
  • One check (✓) — Message sent to the server
  • Two checks (✓✓) — Message delivered to the recipient's device
  • Blue checks — Message has been read by the recipient

Read receipts can be controlled in your privacy settings per contact.

How do I reply to a message?

Swipe right on any message to reply to it. The original message will be quoted above your reply so the context is clear.

Calls

How do I make a call?

Open a conversation with a contact and tap the phone icon in the top right corner. QRChat supports voice and video calls. Calls connect peer-to-peer (directly between devices) when possible, for the best quality and privacy.

Are calls encrypted?

Yes. All calls use end-to-end encryption via WebRTC with SRTP (Secure Real-time Transport Protocol). The encryption keys are negotiated directly between the two devices — the server never has access to call audio or video.

Why is my call not connecting?

Call connection issues are usually related to network conditions:

  • Make sure both devices have a stable internet connection
  • If you're on a restrictive network (corporate WiFi, some mobile carriers), the direct P2P connection may be blocked — QRChat will try to use a relay server (TURN) as fallback
  • Calls have a 45-second timeout — if the recipient doesn't answer, the call is automatically ended
  • Make sure the recipient has QRChat open or notifications enabled

Account & Data

How do I delete my account?

Go to Settings and scroll to the bottom. Tap Delete Account. Before deletion, the app shows a detailed warning explaining what you will lose and what can still be recovered.

Deleting from Settings removes:

  • All your messages from the local encrypted database
  • All your contacts
  • Server registration and push tokens

What stays on your device (unless you also uninstall the app):

  • Your cryptographic identity (private keys in iOS Keychain)
  • Your fingerprint — other people who have you as a contact still recognize you
If you also uninstall the app, your identity is still preserved in the iOS Keychain. When you reinstall QRChat, you will see a "Welcome back" screen offering to restore your old identity — you pick one and enter a display name, and your contacts will recognize you again automatically.
What happens if I reinstall QRChat?

QRChat is designed so that your cryptographic identity survives reinstall on the same device. Your private keys are stored in the iOS Keychain, which iOS keeps even when you delete an app.

When you reinstall:

  • At first launch, QRChat scans the Keychain and finds your previous identities
  • A "Welcome back" screen appears listing up to 3 recent identities by fingerprint
  • Tap one, enter a display name, and your identity is restored instantly
  • Your contacts will recognize you with the same fingerprint as before
  • Or tap "Create new account" to start fresh with a new identity

What is NOT recovered after reinstall:

  • Your message history (messages are stored in the local encrypted database, which is wiped with the app)
  • Your contact list (contacts are also stored locally)
Good news: your contacts will reappear automatically. When any of your existing contacts sends you a message, QRChat will create a pending contact with their real name and fingerprint, and you simply tap Accept to resume the conversation. No QR re-scan needed.
I lost my contacts after reinstall — how do I get them back?

You do not need to re-scan anything. Just wait for your contacts to message you — QRChat will recreate each contact automatically with their real name, avatar color, and fingerprint, shown with a "PENDING" badge until you review and accept.

Step by step:

  • Your contact sends you a message (text, not a call)
  • A new conversation appears in your list with an orange "PENDING" badge
  • Open the conversation — you see the message and a yellow banner with their fingerprint
  • Tap Accept — the conversation becomes permanent, no further prompts
  • Tap Block — the sender is ignored for future messages and calls
Both devices must be on QRChat version 4.3.0 (build 409) or newer for automatic profile recovery to work. Older builds will still deliver messages, but the contact will show as "User xxxxxxxx" with an empty fingerprint until you scan the QR code manually.
Why do I see "New contact — not verified"?

This yellow banner appears when someone you do not have in your contacts sends you a message. Their display name and fingerprint are taken from the encrypted message itself (never from the server), and the message has already been cryptographically proven authentic — no one can impersonate another person without their private key.

Why the warning then? The displayed name is whatever the sender set in their profile. If your real friend "Ana" sends you a message, you will see "Ana" — but in theory, a stranger could also name themselves "Ana". The fingerprint below the name is the only unforgeable identifier.

Your options:

  • Accept — if you recognize the fingerprint (or know the sender by context), the contact becomes permanent
  • Block — future messages and calls from this user are silently ignored
  • Verify in person — for maximum safety, scan their QR code when you meet; a QR-verified contact is marked as fully trusted
Until you accept a pending contact, QRChat does not send typing indicators or read receipts to the sender — they cannot tell whether you received or read the message.
What happens if I lose my phone?

Since QRChat stores encryption keys exclusively on your device (in the iOS Keychain), losing your phone means:

  • Your messages cannot be accessed by anyone (the database is encrypted with SQLCipher)
  • Your keys cannot be extracted (protected by Secure Enclave)
  • You will need to set up QRChat fresh on a new device
  • You will need to re-scan QR codes with your contacts

There is no cloud backup of your messages or keys — this is by design for maximum security.

Can I use QRChat on multiple devices?

Currently, QRChat supports one device per identity. Your cryptographic identity is tied to a single device. Multi-device support may be added in a future update.

Troubleshooting

I'm not receiving notifications

Check the following:

  • Go to iOS Settings > QRChat > Notifications and make sure notifications are enabled
  • Make sure Do Not Disturb is off
  • QRChat uses silent push notifications (content-available) to wake the app — your device must have an internet connection
  • If you just installed the app, try closing and reopening it to register for push notifications
The connection is unstable

QRChat uses WebSocket for signaling and WebRTC for peer-to-peer communication:

  • Check your internet connection (WiFi or mobile data)
  • If the connection drops, QRChat reconnects automatically with exponential backoff (up to 30 seconds between attempts)
  • A heartbeat system (every 30 seconds) monitors connection health
  • In debug mode, you may see "Fast Refresh disconnected" — this is normal and does not affect the release version
The app crashed or won't start
  • Force close the app and reopen it
  • Make sure you have the latest version installed
  • If the problem persists, try reinstalling the app (note: this will delete your messages and keys)
  • Contact us at ruscon2001@gmail.com with a description of the issue

Other

Is QRChat free?

QRChat offers a free tier — you can add up to 10 contacts and use all features (messaging, calls, file transfer, encryption) at no cost. There are no ads and no hidden fees.

To add more than 10 contacts, you can upgrade to QRChat Unlimited for a one-time payment of $4.99. This unlocks unlimited contacts permanently — no subscriptions, no monthly or annual fees, no recurring charges. You pay once and use it forever.

Free version: up to 10 contacts, all features included
QRChat Unlimited: $4.99 one-time payment — unlimited contacts, forever
Which devices does QRChat support?

QRChat is available for:

  • iPhone — iOS 15 and later (iPad is not supported)
  • Android — Coming soon
How do I report a user?

You can report a user in two ways:

  • From a message: Long-press on a message and select Report
  • From a profile: Open the contact's profile and tap Report

Reports are reviewed and appropriate action is taken. You can also block a user to prevent further communication.

How do I contact support?

You can reach us at: