Privacy

We can’t sell what we can’t see

Privacy here isn’t a policy promise — it’s the architecture. There’s no account and no readable data on the server, so there’s nothing to mine, sell, or leak.

What the server never sees

  • Your events or any content
  • Names of people or spaces
  • Who belongs to a space
  • Your recovery phrase or any key
  • An email address or password (there are none)

What it does handle (metadata)

  • Opaque, random-looking identifiers
  • The size and timing of encrypted blobs
  • Your IP address (as any web server does)
  • A version number and change counter per document

The two exceptions, named

A family calendar asks for two things a purely device-to-device app never does, and both are worth stating outright rather than leaving in a footnote.

  • Reminders tell the server when to wake you. It holds a time and an opaque id — never what the reminder is for — and the wake-up it sends carries no content at all. Your device decrypts and writes the notification.
  • Emailed invites leave the encryption. An email cannot be end-to-end encrypted to someone who holds no key, so an invite is plaintext and passes briefly through the server’s outbox. It is off until a family turns it on, and off for every person without an address saved.

How both actually work →

Start using Family Manager

No sign-up, no email, no password. Open it and go — your data is encrypted before it leaves your device.