Case Study | Thomas Schellekens at Qryptr

Thomas Schellekens spent eight years building an encrypted messenger on his own. By the end, the thing keeping him up wasn’t a bug or a soldering problem. It was a much quieter worry: did anyone else actually think this was worth doing? He came to Commons Caretakers for a UX audit of Qryptr. What he didn’t expect was the other thing it gave him – the feeling that people had looked at his project and decided it deserved their time.

“My main challenge was, I didn’t know if anyone would be interested. I think it’s a great idea, but a lot of people think that about their own ideas.”

Spend enough years on something that lives mostly inside your own head and you’ll recognise the doubt in that sentence straight away.

Thomas builds Qryptr. It’s a small device with one fairly stubborn job: writing and reading encrypted text messages on hardware that never goes anywhere near the internet.

Here’s the gap it’s built to fill. You can pile all the cryptography you like onto your phone or your laptop, but the moment the device itself gets compromised, none of that is worth much. So Thomas took the encryption off the phone completely. Qryptr is air-gapped. You type your message on it, it encrypts that message and turns it into a QR code, and you photograph the code with your phone to send it on. At the other end, someone scans it straight back into their own Qryptr. The keys and the plain text stay on the device the whole way. They never touch the network.

He’s been at this for eight years. He started out knowing nothing about electronics and picked the hardware and the cryptography up as he went, mostly on his own, partly because he likes building things and partly because he holds a fairly plain belief that people ought to be able to send each other a private message without asking anyone’s permission first. The one thing he couldn’t really judge, stuck in his own workshop, was whether any of it had actually landed.

The challenge

It was never the soldering that kept him up. The real worry, after that many years on something hardly anyone outside his own circle had tried, was whether the idea was as good as he reckoned it was, or whether he’d quietly poured eight years into a thing only he would ever use.

And then there’s the awkwardness, which is sort of the whole point. Qryptr asks a bit of you. A second device in your hand, a code to scan, a photo to take. That friction is the security doing its job, so you can’t just delete it and call the thing user-friendly.

“In the end it’s a separate device. So it’s never going to be super user-friendly.”

So the question was never how to make it slick. It was which bits of the friction he could quietly lift off the user. The keyboard, for a start, which is a proper nightmare to get right on anything this small and this cheap. The menus. The power button. Whether the thing gives you any sign at all that it heard you when you pressed it. A few friends had had a go on it, so he had hunches. What he didn’t have was a map.

Discovering Commons Caretakers

Qryptr runs on an NLNet grant, and Thomas is pretty open about what that meant to him. It was the first time anyone official had treated the project as something more than a bloke tinkering away in a basement. The money helped, obviously. What he hadn’t clocked was that it came with more than money attached. His contact at NLNet pointed out that grantees could also ask for a usability audit and a security audit. Actual hands-on work, from people who do this for a living.

“That’s something I basically get for free. It felt like a big luxury.”

That’s how he ended up working with Miroslav, a UX specialist. He boxed up the current device along with a couple of older builds, posted the lot over, and was told he could send across whatever questions he most wanted answered. Nearly all of his were about usability.

The process

What came back wasn’t a few notes scribbled in a margin. It was a proper written report, and the word Thomas keeps reaching for is honest. Which is also why it was useful. It pointed out the things he’d got right, which, oddly, was news to him; no one had ever told him that. And it didn’t go soft on the things he hadn’t. A few of the problems he’d already half-suspected, so seeing someone else write them down just made them official. Others he hadn’t seen coming at all. But the bit that did the most work was simpler than any single fix. The report put everything into some kind of order, so he finally knew what to go at first.

How the whole thing ran mattered nearly as much as what it turned up. Thomas had been through a European funding application once, and he hasn’t forgotten it. The forms. The hoops. The long wait, and not a lot to show at the end of it. This was the opposite of that. Post the device over, talk it through, get the device and the report back. Barely any paperwork worth the name. When the scarcest thing you’ve got is time, that kind of plainness counts for a lot.

“He tested it, he sent it back, he sent me the reports. It was just very, very practical.”

The outcome

The report landed in January. He’s been chipping away at it ever since, and Qryptr is slowly turning into the sort of thing you can pick up cold and work out. Ask him what actually changed, though, and he won’t start with the keyboard or the menus.

“I’m not working on this alone any more. It’s not just me in my basement, not sure if anybody’s ever interested at all.”

Some of that is a collaborator who found the project after catching a talk Thomas gave at a hacker conference, and who he now speaks to every week about what to build next. Some of it is the report, which has quietly become the shared reference the two of them work from, so he isn’t re-explaining the whole thing from scratch every time someone new turns up. There are pictures in it. He forwards it on whenever he wants to introduce the device to somebody.

More than a deliverable

To Thomas, the report was never just a punch-list. It was proof that people who actually knew what they were looking at had been through Qryptr and decided it warranted their attention. And that’s the part that never shows up on an invoice. After eight years of genuinely not knowing, the thing sitting underneath all that feedback was a quiet yes. The idea holds up. Keep going.

One word keeps coming up when he talks about it, and it’s acknowledgement. He also keeps circling back, still a bit disbelieving, to how unlikely the offer sounded in the first place. That kind of expertise, aimed at a volunteer project, for nothing. Mind you, he’s not the only one who reacts like that. I’ve run a fair few of these interviews now, and I get the same double-take from almost everyone. First the penny drops that it’s real, then comes the obvious question of why on earth more people haven’t heard of it.

Ask Thomas what he’d say to someone still on the fence, and the answer is about as short as answers get.

“I would say apply. Just go for it.”

Could Commons Caretakers help your project?

If you’re building something on your own, the hardest part often isn’t the next bug on the list. It’s the quieter one sitting underneath it: whether the thing is even worth finishing.

Commons Caretakers backs grantees of the NGI Zero programmes and the wider NGI ecosystem with practical, hands-on help. Usability audits, security audits, technical writing, accessibility work, and a fair bit more. Most of it starts with a single conversation. Occasionally with a device in a padded envelope.

Get in touch with Commons Caretakers →

Next Case Study: Tracy Gardner at Flock XR →


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *