support
Support
Contact
Email [email protected]. A person reads every message.
Never send a private key, a backup file or a passphrase, to us or to anyone. Nobody who genuinely helps you will ever need one. A public key, an error message or a screenshot of the error is fine.
Encrypted email and security reports
To write to us encrypted, use our OpenPGP key. PGPKit Pro finds it by email (Keys → Find → [email protected]), as does any app that supports Web Key Directory, or download it here. Check that the fingerprint matches:
182B D04E C047 ECC7 90AE 62AC 4D2B 1DBA B935 FD87
The same key covers [email protected] and [email protected]. Please report security problems to [email protected], encrypted to this key, and give us a chance to fix them before you publish.
Common questions
- A message will not decrypt.
- The error says why. Most often the message was encrypted to a different key from the ones on this phone, and the error names the key it wants. Ask the sender which of your keys they used, or import the right one. If it says the message was damaged, ask for it again as a file attachment rather than pasted text.
- I have a new phone.
- Keys are never synced or backed up automatically, on purpose. Open the backup file you saved, or choose More → Restore a backup, and enter the passphrase you chose for it. A paper backup can be typed back in from the same screen.
- I forgot my backup passphrase.
- It cannot be recovered, by us or anyone. That is what keeps the backup safe if someone else finds the file. If you still have the old phone, make a new backup from it with a new passphrase.
- A signature says “unknown signer”, “expired” or “weak algorithm”, not “invalid”.
- Those mean PGPKit could not fully establish something. They do not mean the message is forged. “Unknown signer” means you do not have the sender’s public key yet. “Expired” means the key or signature has passed its date, often because a clock is wrong. Only “invalid” means the signature does not match the message.
- Does it work with GnuPG, Thunderbird, Proton or OpenKeychain?
- Yes. Every build is tested against GnuPG, RNP (Thunderbird’s engine), GopenPGP (Proton’s engine) and Sequoia. Import their public key, and give them yours from the key’s page → Share public key.
- How do I stop “Made with PGPKit” appearing on messages?
- More → Privacy & data → turn off “Add ‘Made with PGPKit’”. It stays off until you turn it back on, and it is never added to keys.
- Can I send text to PGPKit from another app?
- Yes. Share text to PGPKit from any app. An encrypted message opens in Decrypt, a key in Import, and anything else in Encrypt. PGPKit also opens .asc, .gpg, .pgp and .sig files.
- Restore a Pro purchase.
- More → PGPKit Pro → Restore purchase, signed in with the same Apple Account or Google account you bought it with. Pro bought on iPhone does not carry over to Android, or the other way round.
- My phone has no Google Play.
- Use the direct download. It includes Pro at no charge.