Help

How it works and how it protects you

  1. What this app is
  2. Linking your phone
  3. Chatting, attaching and dictating
  4. How your messages are protected
  5. Who can see what
  6. What this does NOT protect
  7. Backups
  8. If you lose your phone

1. What this app is

It is a window into your own Univirtex agent, which lives on your computer. It is not a chat service: there is no cloud account holding your conversations, and nobody but you can read them.

Between your phone and your computer sits a mailbox on the internet that only ever stores encrypted messages. Think of a post box you drop sealed safes into: the courier carries them, but cannot open them.

Your phone encrypts and decrypts Mailbox ciphertext only cannot read it Your computer the agent Your computer reaches OUT. Nobody can call in to it.

The journey of a message

You do this once per device. No password to invent, no odd code to copy from anywhere.

webapp.univirtex.com

Link this device

Open “Remote access” in the desktop application and scan the QR it shows. No username or password needed.

The first thing you see on a new device

Step by step

  1. On your computer, open the Univirtex app and go to Remote access. It will ask for your main password — on purpose, so nobody walking past your desk can link a phone of their own.
  2. A QR code appears, with the same characters written below it in case you cannot scan.
  3. Point the phone's camera at the QR: it is a link to this site and the camera opens it by itself. If the site is already open, its Scan the QR to link button reads it too.
  4. Choose a PIN of 4 to 8 digits (asked twice). That is it — you are in the conversation.

This phone's PIN

It protects what the app keeps on this phone: without it the conversation cannot be opened. It cannot be recovered, because it is not stored anywhere: if you forget it, tap "I forgot the PIN" and link again by scanning a new code on the computer. Five wrong tries in a row and the phone forgets the link by itself.

In Settings → Lock you decide when it asks: every time you close the app, or after 1, 5, 15 minutes, 1 hour or 8 hours idle. In between it opens by itself. The "Lock" button at the top asks right away.

A few-digit PIN is no substitute for your phone's own lock. It stops whoever picks it up from the table; whoever copies what is inside faces hours or days of trying combinations, not an impossibility. Keep the phone's own lock on, and the PIN on top.

The QR expires after 3 minutes and works only once. If you run out of time, generate a new one from the computer. That short life is exactly what stops someone who glimpsed your screen from using it later.

Before the camera opens you will see a notice explaining what happens to the video. The images never leave your phone: they are analysed on the device itself to read the QR and then discarded. Nothing is recorded or sent.

3. Chatting, attaching and dictating

Conversation
Can you summarise the report I sent you?
Of course. The document has 12 pages and covers…

The clip attaches files; the microphone records a voice note

Photos are optimised before sending: they are scaled down to a size the agent reads just as well, and take far less space. In the process their metadata is stripped, including where the photo was taken.

The “Your agent” menu shows, read-only, which models it has configured and which tasks it can run. You can look, but not change them: that is decided on your computer.

4. How your messages are protected

The key

When you link, your computer creates a random key and puts it inside the QR code. Scanning it moves the key from the computer to the phone through the camera, never across the internet.

That means the mailbox has never held your key and cannot hold it. It is not a promise not to look: there is simply nothing to look with.

Why a random key instead of a password

A password can be guessed by trying millions of combinations. This key is a random number so large that guessing it is not possible: there are more combinations than atoms on Earth. There is nothing to guess.

What happens to each message

  1. You type the message on your phone.
  2. Your phone seals it with the key, right there, before sending.
  3. The mailbox receives an unreadable block and stores it as-is.
  4. Your computer collects it and opens it with the same key.
  5. The reply travels back the same way, also sealed.

Readable text exists only on your two devices. At no point along the way does it appear in the clear.

The encryption also detects tampering: if anyone altered a single character of a stored message, opening it would fail rather than show something changed. It cannot be forged unnoticed.

Your computer opens no door

It might seem your computer has to be “opened up” to the internet to receive messages. It does not. Your computer is the one reaching out every few seconds to ask whether anything is new, just as it does when you open a web page. Nobody outside can connect to it, because nothing is listening.

And while the application is locked, the agent stops decrypting and replying until you unlock it again.

5. Who can see what

WhoCan they read your messages?
The service hosting the mailbox
Anyone who copied the whole database
Anyone eavesdropping on the connection
Anyone who steals your locked phone
You, on your phone and your computer

In the mailbox each message is a row with an anonymous identifier, a date and an encrypted block. No names, no subjects, no text, no file names.

6. What this does NOT protect

No system protects everything. These are the real limitations:

7. Backups

We collect no data from your communications: the server only stores encrypted text it cannot read, and there is no analytics or tracking of any kind.

As a direct consequence, backing up your conversations is each user's own responsibility. We have no copy to give you, and could not read it even if we did.

Your remote conversations are also kept in the desktop app's history, encrypted with your vault. That is the copy worth including in your usual computer backups.

8. If you lose your phone

First: the lost phone has the PIN in front. Once the lock time you had set has passed, what is inside is the link wrapped with the PIN, and five wrong tries erase it. That buys time; it is not forever.

  1. On the computer, in Communications, press Unlink and link again the phones you still use with a fresh QR. Each link creates a new account and a new key: the lost phone is left talking to an account the computer no longer serves.
  2. If you ever signed in with username and password, change the password from the computer and, on any device still in, use Forget this phone to close those sessions too.

You do not lose your conversations: your computer keeps the key and the history.

On the sign-in screen itself there is a red button, “Clear sessions and sign-in data”, which cleans only that device. Use it if you lend or sell a phone.