Account help
How to create and look after your Querlyn account. The desktop app does not use your account yet; this covers the website.
For help with the Querlyn app itself, see Querlyn help.
Creating an account
Go to Create an account and enter your email address and a password.
- Use at least 15 characters. There are no rules about symbols or digits; a few unrelated words make a strong password that is easy to remember.
- Passwords that are very common, or that contain your email address, are refused.
We then send you an email to verify your address. If the address already has an account, we email it a note instead of creating a second account.
Verifying your email
Open the link in the verification email within 24 hours, then enter the password you chose when you signed up and confirm on the page it opens. Opening the link alone changes nothing. If you do not know the password (for example, you did not create the account yourself), reset it: setting a new password from the reset email also verifies your address. An account that is not verified within seven days is removed (a link sent on the last day still works until it expires), and the address can be used to sign up again.
You can sign in once your address is verified. If the link has expired, try to sign in: we send a new link. The sign-in page can also send one again.
Signing in
Sign in with your email address and password. If you have set up two-step verification, you are then asked for your second step.
After several wrong attempts, sign-in for that address pauses for a short time. This protects your account from password guessing.
Resetting a password
Use Forgot password and enter your email address. We email a reset link that works once, within 30 minutes. To protect your privacy, the page shows the same message whether or not the address has an account.
Setting a new password signs you out everywhere, so anyone using your old password loses access.
Two-step verification
Two-step verification is optional. You can add an authenticator app, which shows a new six-digit code every 30 seconds, or a passkey, from your account's security settings.
When you add your first second step, you get a set of recovery codes. They are shown once. Keep them somewhere safe and offline: each code works once and lets you sign in if you lose your authenticator app or passkey. You can generate a new set at any time, which stops the old codes working.
Before sensitive changes, such as a new password or email address, we ask you to confirm it is you again.
Passkeys
A passkey lets you sign in with your device's screen lock or a security key instead of typing a password. You can add passkeys from your account's security settings, use one to sign in or as your second step, and remove any you no longer use.
Passkeys need JavaScript in your browser. Everything else on this site works without it.
Signing in to the desktop app
The Querlyn app signs in through your web browser, so you never type your password into the app. Choose Sign in in the app, sign in here if you aren't already, and confirm the device name the app shows. The browser then hands you back to the app.
Only confirm a sign-in you started yourself, just now. We email you when the app is signed in. You can see every desktop sign-in, and sign them all out, under Sign-ins. Changing your password signs the app out everywhere.
Installations and offline activation
Each computer running the app is a device on your account. Activating the app on a device uses one of your installation slots. Your 30-day trial starts with your first activation. Under License you can see which devices hold a slot and free one for a new computer. Removing a device under Desktop devices signs it out and frees its slot.
A computer without internet can be activated offline: the app saves a signed request file, you paste its contents on the offline activation page from any connected computer, and you carry the license file back. Offline computers only learn about license changes when they next connect.
Account recovery vs. vault recovery
Resetting your password recovers your account. It never recovers encrypted vault data: only your trusted devices or your recovery kit can decrypt that.
Encrypted sync and vaults are planned and not available yet.
Encrypted sync
Sync is not available yet. This describes how it works once it is.
Sync keeps your Querlyn connections, saved queries and settings in an encrypted vault. Your devices encrypt everything before it leaves them; Querlyn's servers store only that encrypted data plus what they need to keep it in order (sizes, revision numbers, dates), and cannot read it.
- A new device joins a vault only when one of your trusted devices approves it — compare the short code both devices show before approving.
- Your recovery kit is the way back in if you lose every trusted device. Keep it safe: Querlyn cannot recover a vault without it or a trusted device.
- Connections (without their passwords), SSH routes, saved queries, snippets and settings sync once you set sync up; database passwords and query history sync only if you turn each on.
- Each account has a storage limit. When it is full, new changes stop syncing until you remove items; everything already stored stays available to download.
Exporting your data
- Account data: download a JSON file from your account page with your profile, sign-in sessions and methods, devices, licenses, vaults and sync usage. It never contains passwords, keys or encrypted content.
- Vault archive: from the Sync page, create an encrypted vault archive. It contains only encrypted data; opening it needs one of your trusted devices or your recovery kit. An archive can be downloaded for 7 days, through a link that works for five minutes at a time.
When a sync subscription ends
Your devices stop uploading changes, and everything on your devices stays as it is. For 30 days you can still download and export your synced data; renewing during that time restores sync.
After that, deletion of synced data is not scheduled: the schedule has not been decided. Before any deletion, you will receive an email naming the date, sent at least 14 days in advance, and the date is shown on the Sync page.
Deleting a vault or your account
You can delete a vault's synced data from the Sync page after confirming your password or passkey, or delete your whole account from your account page. Deletion removes the data from Querlyn's servers shortly after; the Sync page shows its progress.
Copies on your devices, and archives or exports you downloaded, are not affected and cannot be erased remotely. Deleted data leaves our backups only when those backups expire.