For the technically curious
Storage: client-side encryption. Your master
key is derived from your password on-device with a standard
key derivation function and never transmitted. Recovery works
through a recovery phrase that also wraps the master key.
There is no server-side key, which means there is no
server-side key to steal or subpoena.
Backups: your cloud, not ours. Backups are
end-to-end encrypted and live in your own iCloud or Google
Drive. We hold no key to them. It is the same model WhatsApp
uses.
Processing: attested secure enclave. Heavier
AI runs in an EU-hosted trusted execution environment whose
state can be cryptographically attested. Plaintext exists
briefly in memory, is never persisted on our servers, and we
provably cannot read or exfiltrate it.
Training: only if you donate it. Models train
on anonymous features, never raw personal text, and even that
requires you to actively offer it. Nothing is used for
training by default, and nothing is ever sold or used for
advertising.