Open App

Your data has nowhere to leak from

The most private thing you can write down deserves an app that keeps as little as possible. Here is exactly what happens to your entries.

Your entries live on your device

An entry is written to your phone and stays there. There is no copy on our servers waiting to be requested, subpoenaed or breached — the shortest possible answer to «what happens if the service is hacked».

Partner sync is encrypted end to end

When two devices are linked, entries are encrypted before they leave the phone. Our relay only helps the two devices find each other; the content passing through it cannot be read by us.

There is no account to steal

No email, no phone number, no password. Nothing identifies you, so there is no database of users to leak and no password reset for someone to abuse.

The entry code never leaves the phone

The code that opens the app — and the TOTP secret behind it — is generated on the device and stored in its secure keychain. It is never transmitted anywhere.

What we do collect

Anonymous crash reports: device model, OS and app version, and the technical trace of the error. No entries, no tags, no notes — a crash report cannot contain them, because the app never sends them.

Erasing is one action, and it is final

Deleting your data removes it from the device. Since there is no server copy, there is nothing left to request afterwards — and nothing for us to hand over to anyone.

If the phone is lost

Whoever finds it faces the entry code, not your history. On a new device you start clean: without your code and without a linked partner device there is nothing to restore — that is the price of keeping no copies.

The full text, without the summary

The privacy policy says the same thing in legal language.

Read the privacy policy