What we can see, and what we can't
Most products that say "your data is safe" mean they promise not to look. We mean we hold no key that would let us.
- End-to-end encrypted
- No third-party requests
- Export anything, any time
- Passkey sign-in only
What the server holds
| We can read it | We cannot | |
|---|---|---|
| Your name and email | Yes | |
| Phone numbers you add for WhatsApp alerts | Yes — only to send those alerts | |
| Which plan you're on | Yes | |
| When you last signed in | Yes | |
| Document titles, categories and dates | Yes — they power search and reminders | |
| Document contents and files | Never | |
| Notes, health records, credentials | Never | |
| Photos and uploaded files | Never | |
| Bug reports you send us | Yes, by design |
The questions people actually ask
What happens if you get breached?
Your encrypted content stays encrypted — the keys are derived on your devices and never leave them. What an attacker could take is the metadata in the table above. We commit to telling affected families within 72 hours of becoming aware of a breach, and to notifying CERT-In within 6 hours of becoming aware of an incident where Indian law requires it.
Can you recover my account if I lose everything?
No — and that's the honest cost of the guarantee above. Your Recovery Kit is the only path back in, which is why we make you save it at signup rather than burying it in settings.
What happens if I stop paying?
After a failed payment, nothing is deleted for 90 days — reading and export keep working the whole time, and we warn you before anything is removed. Renewing at any point stops the clock.
Read the full security design
The key hierarchy, the threat model, and what each of them costs you.
Security