Entries live on your device and sync to us
An entry is written to your phone and sent to the server: otherwise it would not survive a lost phone or appear on a second device. On the server it sits depersonalised — no name, no email, no number beside it.
Partner correspondence is encrypted
Communication between partners is encrypted: our relay only helps the two devices find each other, and what passes through it cannot be read by us. The entries themselves reach the server depersonalised.
There is no registration, so there is nothing to steal
No email, no phone number, no password: the account is created by the device on first launch and holds nothing but a technical marker. There is no user database in which you could be found, and no password for anyone to reset.
The entry code never leaves the phone
The code that opens the app — and the TOTP secret behind it — is generated on the device and stored in its secure keychain. It is never transmitted anywhere.
What reaches the server
The entries themselves: date, duration, tags and the note if you wrote one. Nothing beside them — no name, no email, no number, no date of birth, only a technical device marker. Plus anonymous crash reports: device model, OS and app version, and the technical trace of the error.
What is erased and what stays
Deleting the app erases entries from the phone. The depersonalised copy on the server remains: it is tied to no person, so there is nothing for us to attach a deletion request to. There is no separate «erase everything from the server» action in the app.
If the phone is lost
Whoever finds it faces the entry code, not your history. On a new device your entries come back from the depersonalised copy — through the pairing code, not through an email or a number: we hold neither.