Privacy

Security & privacy

What is stored where, who can read it, and the few things only you can protect.

What is stored, and where

DataWhere, and who can read it
Unencrypted filesArweave and IPFS. Public: anyone with the transaction ID can read them.
Encrypted filesArweave and IPFS, as ciphertext. Nobody can read them without the file key.
File keysOnly where you keep them, and in the browser that uploaded the file. Never on our servers.
Identity secret (anonymous access)Only on your device, and in any backup you make.
Your file listOur index: the transaction ID, size and date of each upload, and the name of unencrypted files. Encrypted files are listed only as “Encrypted file”.
Your accountYour email address and storage balance. Card payments are handled by Stripe; we never see card details.

What we cannot do

  • Read your encrypted files, or learn their names or types.
  • Recover a lost file key or identity secret.
  • Delete or alter a stored file — nobody can; that is what permanent storage means.
  • Tell which member made an anonymous proof.

What only you can do

  • Keep your keys. Save each file key when it is shown, and back up your identity. A password manager is a good home for both.
  • Share carefully. A decrypt link is the key. Anyone who has it can read the file, forever. Share the verification link when you only need to prove the file exists.
  • Think before storing. Stored files cannot be removed. Encrypt anything you would not want public.

How it is built

Encryption is AES-256-GCM through your browser's built-in Web Crypto. Anonymous proofs are Groth16 zero-knowledge proofs over the BN254 curve, checked by a smart contract on Base. The code is open; the technical design is in the project's ARCHITECTURE.md.

Reporting a problem

If you find a security issue, please report it privately through Support rather than in public, so it can be fixed before it is known. The full legal terms are in the Privacy Policy and Terms.