It's been a long journey. What started as frustration with emailing myself links has become a focused Core and Ops product with encrypted transfer, encrypted rooms, an authenticated browser companion, and native clients under release validation.
Core and Ops are the only launch products. Legacy, Play, and Dev remain parked. A native client is not treated as publicly available until its signed artifact, version, checksum, installation result, and exact source revision are published.
What's Launching
The launch scope is:
- Core — Encrypted clipboard, screenshot, file-transfer, Private Share, and Secure Drop workflows
- Ops — Encrypted deal rooms with messages, files, membership, expiry, kill-switch, and audit records
- Browser companion — The currently public client surface
- Native clients — Windows, Apple, and Android remain in release validation
Release evidence is tracked separately from feature source. Public availability will be updated only after the backend and each native artifact are tied to one exact release revision and the required install/runtime checks pass.
Core Features at Launch
- Encrypted transfer — Clipboard and file payloads are encrypted before they leave your device
- End-to-end encryption — Authenticated client-side encryption with client-held keys for protected content payloads
- Device pairing and revoke — Pair devices, transfer, and remove access when needed
- Ops rooms — Invite members, post encrypted messages and files, rotate keys after removal, and keep an audit trail
- Honest launch scope — Native push and browser-extension sync stay out of launch claims until their end-to-end evidence exists
Pricing
Paid plans are handled through the Apple App Store and Google Play via RevenueCat. Purchase and restore flows are implemented in the apps, but public paid-launch claims wait on dashboard, product, public-key, entitlement, and sandbox receipt evidence.
We chose this model because:
- Running secure, real-time sync infrastructure costs money
- We want to build a sustainable business, not chase growth metrics
- A subscription aligns our incentives with yours — we only succeed if you keep using Quilon
No ads and no selling your data. Web and Windows direct users to the mobile apps for subscriptions; there is no web checkout.
What's Not in the Launch Claim
These items stay out of launch copy until they are implemented and proven:
- Native push — APNs/FCM delivery remains deferred until signed-device evidence exists
- Browser extension sync — The extension listing is limited to screenshot and local scanning unless sync QA is completed
- Share/keyboard extensions — iOS extension claims wait until App Groups and extension flows are production-proven
- Live Tunnel — Disabled for Core + Ops; creation is rejected and public tunnel routes fail closed
- Legacy, Play, and Dev — Parked and not offered as launch products
- Socket.IO horizontal scale — Render stays single-instance until a Redis adapter is implemented and verified
Join the Community
We've set up a Discord server where you can chat with us, report bugs, request features, and connect with other users. Join us:
Thank You
Building Quilon has been an incredible experience. Thanks to everyone who's followed along, given feedback, and encouraged us to keep going.
Thanks for following the launch hardening work.