Your entries live on your device
An entry is written to your phone and stays there. There is no copy on our servers waiting to be requested, subpoenaed or breached — the shortest possible answer to «what happens if the service is hacked».
The most private thing you can write down deserves an app that keeps as little as possible. Here is exactly what happens to your entries.
An entry is written to your phone and stays there. There is no copy on our servers waiting to be requested, subpoenaed or breached — the shortest possible answer to «what happens if the service is hacked».
When two devices are linked, entries are encrypted before they leave the phone. Our relay only helps the two devices find each other; the content passing through it cannot be read by us.
No email, no phone number, no password. Nothing identifies you, so there is no database of users to leak and no password reset for someone to abuse.
The code that opens the app — and the TOTP secret behind it — is generated on the device and stored in its secure keychain. It is never transmitted anywhere.
Anonymous crash reports: device model, OS and app version, and the technical trace of the error. No entries, no tags, no notes — a crash report cannot contain them, because the app never sends them.
Deleting your data removes it from the device. Since there is no server copy, there is nothing left to request afterwards — and nothing for us to hand over to anyone.
Whoever finds it faces the entry code, not your history. On a new device you start clean: without your code and without a linked partner device there is nothing to restore — that is the price of keeping no copies.
The privacy policy says the same thing in legal language.
Read the privacy policy