You can let people reach you at a phone number or an email address. To do that you must first prove the value is yours, because a number nobody proved could be used to collect requests meant for whoever really holds it.
Add the value to your card, then tap Verify. A six-digit code is sent to it:
The code expires in ten minutes. It can be received on any device that has that number — it does not have to be the phone running CHANNEL — and typed in here.
A verified value is a claim: this is mine, leave invitations for me here. Some values cannot carry that claim, so CHANNEL refuses them before it sends a code.
The editor says so while you are still typing, and the check is made again on our server before any code is sent.
The list of public numbers is kept on the server rather than inside the app, so a wrong entry can be corrected without a new version of the app. It starts empty, and a number goes in only once it is confirmed to be listed on a public site: locking a real person out of their own number is worse than the thing the list guards against.
A tick means this phone proved control of the value, by the route shown (Verified by text, by call, by email). A call and a text are different proofs; the app records which, and never pretends one is the other.
A value you have not verified is inert: it is not published, and nobody can reach you at it. This is deliberate.
Carriers give an unused number to somebody new, so proving a number today is not proof for ever. The right to collect what is left at a number lasts thirty days.
When that runs out the value stops being published. Nobody can reach you at it, no invitation is collected there, and your card says so: Not being published. Prove it again to keep being found this way, with a Verify Again button beside it. Take a fresh code and it is published again. Nothing else is touched: your contacts, your conversations and your keys never depended on it.
A thing that has stopped working should say so rather than sit there looking fine.
With Find me by on for a verified value, anyone who knows that number or address can simply write to you. They do not send a request and then wait to send the message: their first message is the invitation.
You see it as a request with the name they call themselves and the value they used. Accept creates the contact and their message arrives seconds later, sealed. Decline refuses it. Block refuses it and refuses anything else from that sender, and the block outlives the request. They are not told either way.
The words they wrote are not in the invitation. Our server could read an invitation, since there is no key of yours to seal it to yet, so nothing but their name, their key and the value is put in it.
Our server keeps no list of who is verified, and no list of numbers. A request left at a number is addressed to a slot derived from the number itself; only a phone that has proved the number can collect from that slot. The number is used to compute the address and is never stored beside your identity.
Two profiles on the same phone may not both present the same number or address. The app refuses the second tick, because two identities answering at one address would reveal that they share a phone.
A profile nobody can find can still message anyone it has paired with, but nobody can start a conversation with it. Give each profile you want to be reachable at least one value of its own with Find me by on. If you put every number and address you have on one profile, there is nothing left for the others, which is what a handle is for: each profile can hold one, so a profile with no number of its own can still be reached.
A tick says this phone proved the value is yours. Find me by says people may reach you at it. They are separate switches on purpose: a verified number can stay private, and it can still vouch for you elsewhere. A handle works on exactly that: it needs a verified number or address behind it as proof that a real person holds it, and that value stays private unless you turn Find me by on for it as well.
A handle is a name you choose that people can reach you at without knowing your number or your address. It is the one value here meant to be given out freely, and you can change your number without telling anybody.
Claiming one. Settings › Handle. Type the name and tap Claim this handle. Three to twenty characters, lowercase letters, digits and underscores. Some names are kept aside so that nobody can use one to look like us.
You need a proven value first. Until a phone number or an email address on your card is verified, the button does nothing and the screen says so. That proof is what stops one person taking every name. It is never published, and nobody can work back from your handle to it: what our server keeps for a name is a keyed hash it can only recognise when the owner presents the proof again, not your number.
Writing to someone at a handle. Put @name on their card the way you would a number, and write. CHANNEL works out where to leave the invitation from the name itself, so there is no directory to ask and no route that answers who is @name. Writing to a name nobody has claimed looks exactly the same as writing to one somebody holds, which is the point.
One each, ten in all. Each profile can hold its own handle, up to ten across the phone, and nobody else can hold one you hold. A handle gets no tick and no Verify button on your card: there is nothing to text, and it is claimed in Settings rather than proved.
Giving one up. Give up this handle releases it. It stays yours for thirty days, so a change of heart is not a change of owner. After that it reaches nobody at all, and nothing is forwarded.
English is the reference text; any translation is a convenience. Help is stored on this phone and never contacts anyone.