How we protect what you keep
We can't read your data. This page explains why, and where the limits are.
What happens on your device
When you create an account, your device turns your passphrase into a key, using Argon2id. That key opens a second key, which encrypts everything you keep with AES-256-GCM. Your passphrase and these keys never leave your device in a form we can use.
Each record is sealed to its place in your account, so a record can't be moved to another place or swapped for a different one without it being detected.
Documents are split into pieces and each piece is encrypted the same way, sealed to its document and its position. If any piece comes back altered or out of order, the app refuses to open it rather than show you something wrong.
What we can see
To run the service we hold a little in plain form: your email address, your passphrase hint, when you joined, and how many records of each kind you have and how big they are. The privacy notice lists all of it.
What we can't see
Your figures, your holdings, your Estate records, your documents and their names.
Reading statements
Your personal details are removed on your device before a statement's text is sent to Anthropic to be read. Under Anthropic's standard terms that text is deleted within 30 days, unless flagged for a policy breach or required by law. We don't keep it.
The limits
- We can't recover your passphrase. Your recovery kit is the only way back in.
- If someone learns your passphrase, they can open everything. Choose one you don't use anywhere else.
- Your passphrase hint can be seen by anyone who knows your email, so keep it vague.
- No independent auditor has reviewed our security design yet.
Where it runs
Our servers and database are in Frankfurt, Germany, hosted by Render. The privacy notice lists every provider and what each one handles.