Sealed from the start

Your data. Your key. Your call.

We built the architecture around one constraint: we should not be able to read your life even if we wanted to, even if we were bought, even if someone compelled us. Everything below is written to be checked, and nothing has shipped yet: each technical claim carries a tag saying whether it exists as prototype code or as a plan.

Only your device and an attested enclave ever see your data in the clear. We cannot read it, keep it, or hand it over.

The substance of your conversations, a photo library full of private moments, where you went and how you slept. This is not data that should sit readable on someone else's server. A normal cloud app could never responsibly ask for it. We designed around that before writing a line of product code, which is the only reason we can work with material this intimate at all.

This is the strongest claim we can honestly make. We make no other.

The whole architecture, in one picture

Four places your data can be. One key.

Your device seals everything before it goes anywhere, the way you seal a letter before posting it. We handle the envelope; we cannot open it, because the key never leaves your phone.

Your device

Your phone already encrypts everything it stores. We add a second lock on top, and the app sits behind Face ID or your passcode. Opening your phone is not the same as opening your life.

Key: yours alone

Reads it in the clear, once you unlock

The collector

The part of the app that fetches your data cannot read it. It works through the night with an envelope it cannot open, and only the app, once you unlock it, holds the key.

Key: none held

Never sees it in the clear

The enclave

When you ask for something that needs real computing power, a copy of just that data is unsealed inside dedicated, hardware-protected memory. It lives there for seconds and is never written to disk.

Key: none held

In the clear for seconds, in memory

Your cloud

Backups are encrypted on your device before they leave, and they land in your own iCloud or Google Drive. We hold no key to them.

Key: none held

Never sees it in the clear

Us

We see an envelope go out and an envelope come back. We do not see what is inside.

Key: none held

Never sees it in the clear

The key is made on your device and is never sent to us. Everything else on this page follows from that one fact.

For the technically curious

Every claim above, opened up.

Open the ones you want. None of these is a summary: each is the whole of what we can say about that layer today.

Storage: one random key, sealed twiceprototype

Your device generates a random 256-bit master key, encrypts the database with it, and keeps it in the hardware keystore: Keychain on iOS, Keystore on Android. Your password and your recovery phrase each wrap a separate copy of that key, which is what lets you restore on a new device. We never see any of the three, so there is no server-side key to steal or subpoena. It is the envelope model WhatsApp, Bitwarden and iCloud Advanced Data Protection all use.

One limit, stated plainly

The database key becomes available after the first unlock following a restart. A powered-off phone is sealed. A running, unlocked phone is a running, unlocked phone. No encryption design changes that.

Collection: separated from readingprototype

A background worker holds only your source credentials. It seals everything it fetches to a key it does not possess; the key that opens the seal sits in the main app behind your unlock. The part of our system that runs most often is the part that can read the least.

Backups: your cloud, not oursplanned

Your device encrypts backups before they leave, and they land in your own iCloud or Google Drive with the wrapped key copies alongside. Your password or recovery phrase is enough to restore. We hold no key to any of it, which also means we cannot recover a backup for you if you lose both. That is not a gap; that is the design.

Heavy processing: attested secure enclaveplanned

A chat-capable language model, and analysis that has to reach across years of a timeline at once, do not fit on a phone. Everything that can run on your device does, and this is the short list of what cannot. It will run in an EU-hosted trusted execution environment whose state your device cryptographically verifies before sending anything. Plaintext exists there for seconds, in memory, never on our disks. Before launch we intend to publish the shell that handles input and output and have an external audit confirm the published code is the running code. Until that audit exists, read this paragraph as a commitment rather than a proof.

Training: only if you donate itplanned

What you can donate is one thing and we will name it: a pseudonymous copy of your timeline reduced to a handful of numbers, never text, never messages, never photos. It takes an active choice from you every time, nothing is used for training by default, and nothing is ever sold or used for advertising.

What we will not claim

Overclaiming would be both dishonest and, under European consumer law, illegal, so here are the lines we hold.

  • We do not call your data anonymous.
  • We do not claim we stop being a data controller just because we cannot read it. Being unable to read something does not remove responsibility for it.
  • We do not say the GDPR somehow does not apply to us.
  • Account metadata, meaning your email and device identifiers, is ordinary personal data that we do hold and are accountable for.

Other people in your data

Your messages and photos contain people who never signed up for anything. We take that seriously and we constrain the product because of it: we never run facial recognition, and we never analyse what someone wrote to you to draw conclusions about them, their mood, or their life.

What the app remembers about the people around you is always your side of the story: who you spent a day with, who you had not called in a while. It describes your relationships, never the other person, and like everything else it stays sealed on your device.

Nothing about anyone is combined across users in the background; there is no mechanism for it. If we ever build sharing, it will mean you deliberately showing a piece of your own timeline to someone you choose, never our systems joining what two people know about a third.

What is built, and what is not

This is our target architecture, and parts of it are still in active development. The tags above say where each layer really stands, we move a tag only when the work is done, and we will not claim we have achieved something until we have. The thinking behind that habit is written down in our values.

Living document · updated as we build

Looking for the legal one? The privacy notice for this website, under Art. 13 GDPR, is here.

UnderstandUrself is a well-being and self-reflection tool. It is not a medical device and does not diagnose, treat, predict or provide early warning of any condition. If you are struggling, please speak to a qualified professional.