Sealed from the start

Your data. Your key. Your call.

We built the architecture around one constraint: we should not be able to read your life even if we wanted to, even if we were bought, even if someone compelled us. Everything below is written to be checked, and we say plainly which parts are shipped and which are still being built.

Only your device and an attested enclave ever see your data in the clear. We cannot read it, keep it, or hand it over.

THIS IS THE STRONGEST CLAIM WE CAN HONESTLY MAKE. WE MAKE NO OTHER.

01

Why this matters more here than almost anywhere

The substance of your conversations, a photo library full of private moments, where you went and how you slept. This is not data that should sit readable on someone else's server. A normal cloud app could never responsibly ask for it. We designed around that before writing a line of product code, which is the only reason we can work with material this intimate at all.

02

In plain language

Your phone seals everything before it goes anywhere, like sealing a letter before posting it. We handle the envelope; we cannot open it. The key is derived on your device from your password and never reaches us.

When you ask for something that needs real computing power, a copy of just that data is unsealed inside a dedicated, hardware-protected enclave. It lives there for seconds, in memory, and is never written to disk. We see an envelope go out and an envelope come back. We do not see what is inside.

03

For the technically curious

Storage: client-side encryption. Your master key is derived from your password on-device with a standard key derivation function and never transmitted. Recovery works through a recovery phrase that also wraps the master key. There is no server-side key, which means there is no server-side key to steal or subpoena.

Backups: your cloud, not ours. Backups are end-to-end encrypted and live in your own iCloud or Google Drive. We hold no key to them. It is the same model WhatsApp uses.

Processing: attested secure enclave. Heavier AI runs in an EU-hosted trusted execution environment whose state can be cryptographically attested. Plaintext exists briefly in memory, is never persisted on our servers, and we provably cannot read or exfiltrate it.

Training: only if you donate it. Models train on anonymous features, never raw personal text, and even that requires you to actively offer it. Nothing is used for training by default, and nothing is ever sold or used for advertising.

04

What we will not claim

Overclaiming would be both dishonest and, under European consumer law, illegal, so here are the lines we hold. We do not call your data anonymous. We do not claim we stop being a data controller just because we cannot read it; being unable to read something does not remove responsibility for it. We do not say the GDPR somehow does not apply to us. Account metadata, meaning your email and device identifiers, is ordinary personal data that we do hold and are accountable for.

05

Other people in your data

Your messages and photos contain people who never signed up for anything. We take that seriously and we constrain the product because of it: we never run facial recognition, never identify anyone in a photo, and never build a profile of a third party. Photos are used as timeline content that makes a past day navigable again, never read as a signal about how you felt.

06

What is built, and what is not

This is our target architecture, and parts of it are still in active development. We will update this page as each layer ships, and we will not claim we have achieved something until we have. If you want to understand the thinking behind that habit, it is written down in our values.

LIVING DOCUMENT · UPDATED AS WE BUILD

UnderstandUrself is a well-being and self-reflection tool. It is not a medical device and does not diagnose, treat, predict or provide early warning of any condition. If you are struggling, please speak to a qualified professional.