Privacy, in plain language
This is a data notice, not a legal wall. It says what we store, what others see, and the one mistake we cannot undo for you.
What we store
- Ciphertext. Your file contents and filenames, encrypted on your device before they reach us. We cannot read them.
- Wrapped keys. The keys that decrypt your files, encrypted under a key derived from your passphrase. Useless to anyone who doesn't know it — including us.
- Metadata. File sizes, file counts, folder-tree shape, timestamps, and sharing relationships between account IDs. This is visible to us in plaintext, and we don't pretend otherwise.
- Your account record. The email address you signed up with, and access logs with IP addresses and timestamps.
What our identity provider sees
Sign-in runs through Clerk, our identity provider. Clerk processes your signup email address and your IP addresses. Clerk never touches your files or encryption keys — it authenticates you, and that is all.
What this site collects
Nothing. The page you are reading is static: no JavaScript, no cookies, no analytics, no trackers.
The one thing we cannot undo
There is no password reset for your data. No operator of this service can recover your files — that is the same architectural fact that keeps us from reading them. If you lose both your passphrase and your recovery phrase, your data is permanently unrecoverable. Write the recovery phrase down.
For the full picture — including what we could hand over under legal compulsion — read the security page.