Support
No account desk. No recovery email. Help is public, on GitHub, so we never need your chats. This page is also the troubleshooting notebook — read it before filing an issue.
How to reach us
Open an issue at github.com/julienlhk/horus/issues.
Write the platform (iOS or Android), what you expected, what happened, and what you already tried. A short timeline helps: “created invite, they joined, I accepted, I sent text, they never saw it.”
Do not paste invite links, keys, screenshots of chats, wake identifiers, or device tokens. We do not need them to debug “Tor is stuck” or “accept never unlocks,” and posting them in public makes the situation worse.
We do not run a phone line, a ticket form that receives message contents, or a recovery inbox. Response time varies. This is a small project. If the issue is “I lost my phone,” the answer is already on this page: we cannot restore keys.
What we cannot do
These are not support failures. They are how the product is built.
- Reset your identity or restore keys from a lost phone, a reinstall, or a wiped app.
- Read, search, export, or produce your messages. We do not have them.
- Unsend something already delivered to someone else’s device.
- Make notifications as reliable as iMessage.
- Guarantee that Tor is reachable on every café Wi-Fi, school network, or national filter.
- Merge two installs into one identity, or move history to a new phone from our side.
How do I delete my data?
Inside the app, delete a chat or leave a group. That wipes the transcript on this device. It does not reach into the other person’s phone. If you already sent a photo, they still have it unless they delete it too.
Uninstalling Horus deletes the local keys, the sealed history, and local settings. That is the complete deletion path for what the app stored. If Wake when closed was on, uninstalling is also how the device token we hold is meant to be removed.
If you claimed an @ handle, change or release it in the app before you uninstall if you want the name freed. We cannot decrypt a handle claim into a chat log, because there is no chat log on that registry.
There is no “download my data from Horus cloud” button. There is no cloud copy. The Privacy Policy is the formal version of this.
Why is the first launch slow?
Horus starts Tor on the device. The first time, it may take several minutes to fetch directory data. The progress you see is that bootstrap, not a Horus account being created. Later launches reuse what was cached and are usually much faster.
Stay on a network that can reach Tor. Some captive portals, office firewalls, and national filters block it. A phone hotspot on cellular often works when hotel Wi-Fi does not. Do not force-close the app in the middle of that first setup if you can avoid it — you will just download the same data again.
If it sits at a low percentage for a long time, wait. Wiping Tor’s cache from outside the app is the wrong instinct: it forces another cold start. If it never finishes on several networks, file an issue with the platform and roughly how long you waited — not a screenshot of a chat.
Invites
Invites are one-time and time-limited. If you see “already used” or it expired, ask for a new one. Do not keep recycling a screenshot of an old QR.
If you created the invite, you still have to Accept before the chat is live. Redeeming is not enough. Nearby Bluetooth is the exception: matching the short code is the confirmation, so you should not also be stuck on a remote Accept sheet for that path.
Until you accept, incoming ciphertext is buffered. It should not vanish. If you accepted and still see a locked chat, say so in the issue — that is a real bug, not “wait for Tor.”
Treat an unused invite as a secret. Anyone with the link can try to join until it is burned. If you posted it in public, create a new one and ignore the old.
I sent a message and it did not arrive
Both sides need a path. You encrypt on your phone, then the blob has to reach their onion mailbox, then they have to fetch it. If Tor is down on your side, the app keeps an outbox and retries. You should not need to tap send twice for that — wait, or check that bootstrap actually finished.
The other person must be able to fetch: app open, Stay connected still allowed by the OS, or Wake when closed if they enabled it. Force-quit on iOS still often means mail waits until they open Horus. We cannot inject a message from here.
If you can chat in one direction only, say which platform created the invite. Cross-platform (iPhone and Android) is supposed to work; if it does not, that is worth an issue. Include whether Accept happened, not just “it feels stuck.”
Photos should be small. A huge file is the wrong shape for Tor. If text arrives and a photo does not, try a smaller picture before assuming the session is dead.
Notifications and Wake when closed
Default alerts are local, after the app fetches mail. They do not include the message body. That is a product choice, not a missing setting.
Stay connected tries to keep fetching while the OS still lets the process live. It is not a promise. Force-quit ends it.
Wake when closed is optional and off by default. If you enable it, a wake host may hold a random id and the Apple or Google device token. Someone sending you mail can request a generic ping: “You have a new message,” no preview. Ciphertext still travels on Tor. The host never sees the words.
This is not iMessage. Focus, Low Power, battery restrictions, and force-quit can delay or drop the ping. If wake is off in Settings, or the product build has no wake host configured, the toggle will not help. Do not file “make it like iMessage” as a bug. The home page and the Privacy Policy describe the same limit on purpose.
How do @ handles work?
A handle is optional discovery. Chats are still invite sessions. Changing @ frees the old name and does not rename or delete existing threads. One handle per install.
Messages are not written on-chain. The registry stores a commitment, not your keys and not a public directory of encryption identities. If a name is taken, pick another. If you reinstall, you start over; the old handle may still sit until it is released.
After you are already chatting, the other person may see your handle on their profile of you because the session announced it peer-to-peer. That is not them looking you up again on a chain.
Nearby Bluetooth asked for location on Android
Older Android versions require a location permission to scan Bluetooth. Horus uses that scan for nearby pairing on the device, and optionally for a sealed uplink through a friend who is already online. We do not collect location from it. We do not build a map of who is near whom.
You can refuse the permission. Nearby pairing will not work. Link and QR still will, over Tor.
Calls feel slow or video fails
Voice is encrypted over Tor. It can be slower than a cellular call. That is expected. Video is beta. If video is unusable, drop to voice or to text. There is no “switch to a Google meeting room” fallback, because that would be a different product.
Both sides still need a live path, same as chat. A call will not ring like a phone number on the public network.
Stores
App Store and Google Play listings are not live yet. When they are, this page remains the support URL those stores point to. There is nothing to refund here: Horus is not sold as a subscription on this site.
For how the app is supposed to work, start at the home page. For what we collect (and do not), read Privacy. For the agreement, read Terms.