FAQ
The questions that come up before installing — and the ones people ask only later.
No. There is no registration, no login and no server holding anything of yours. The vault is a file on your device.
Then the vault stays shut. There is nobody who could open it — not us either, because your key never reaches our machines.
That is why setup offers several routes: files as part of the key, a fallback made of any two of three files, and a recovery code when you bind the vault to a place. What you write down is the actual spare key.
Completely. Creating, opening, editing, backing up — all without a network. Two functions reach the internet, and both only if you turn them on: the photo timestamp, and opening a time capsule. Sealing a capsule works offline.
For a timestamp: the SHA-256 checksum of a photo, never the photo. For opening a capsule: which round or beat is being asked for — never the note, never the key, never a share of it.
Nothing else. No analytics, no advertising ID, no crash reports.
Anything somebody should learn only later: a letter to a child for their eighteenth birthday, credentials a trusted person should get after a certain date, a note to yourself that should not tempt you today.
No, and that is the heart of it. The moment is decided not by your device but by a signature that two independent beacons publish only then. Before that it exists nowhere — not with us either.
A capsule is sealed so that two of three shares suffice: drand, a key server, and your recovery code. If one side goes down, the capsule still opens. If both beacons disappear for good, the recovery code is what is left.
Because they can do different things. The capsule code is one of three shares and opens nothing on its own while the beacons stay silent — so it sits in the vault harmlessly. The place code replaces the place entirely. Kept beside the lock, in a vault someone already has open, it would make the lock worthless. So it is shown once and stored nowhere.
About 150 m around the stored point by default. On the unlock screen the radius can be set to 300, 600 or 1200 m. This weakens nothing: the vault is bound to exactly one grid cell, and the radius only says how many neighbouring cells the device tries. The widest radius costs under half a second.
You will need the recovery code the app showed once while sealing it. Without it and without that place the note stays shut. So use place binding for things that belong where they are.
The construction has not been externally audited. That is why we write down exactly how it works — see the technical description — so that you, or someone you trust, can judge it. A published assessment is a different thing from a self-declaration, and while there is none we say so.
No. Not out of goodwill, but because there is technically no other end: your key is made on your device out of things we never see. A court could not compel from us anything we hold.
The same file holds two independent vaults with separate passwords. The second slot always exists — even unused, filled with random data of identical length. From the outside there is no telling whether a second one is there.
What it is not: protection against somebody who knows the app can do this. Whoever knows the file and this page knows a second slot might be there.
Android. There is no iOS version and none is currently planned.