Security

What we can and cannot see.

The short version: we hold encrypted data, and what we need to bill you and sync it. We hold nothing that turns that data back into files.

Encryption happens on the phone

Files are encrypted before any upload starts. The key comes from your vault password, on the phone, and is never sent anywhere.

Your account holds encrypted data

Signing in gives you somewhere to put the encrypted data and a way to pay for it. It does not give us, or anyone who compels us, a way to open a vault.

A recovery key for every vault

Each vault gets a recovery key when you make it. You can see it again inside the open vault, and you need it to open the vault on a new phone. Anyone who has it can open the vault, so keep it somewhere safe.

Vaults that leave no trace on the phone

A vault with Phone copy off keeps only a small locked header on the phone, in one of ten places that always look taken. Without the password, even the app cannot tell which places are in use. Such a vault never appears on the vault list, and opens only with its password or recovery key.

There is no back door, and no reset

If the password and the recovery key are both lost, the files stay encrypted for good. We would rather say that plainly than offer a way back in that would also work for someone else.

An independent audit and a write-up of the cryptography will be published here when they are ready. Until then, treat this page as a description of the design, not a certificate.