What's InsideHow It WorksThe SciencePrivacyPricingStart Free →

Privacy

Private means
we can't read it either

Not a policy we promise to follow. An architecture that can't do otherwise.

q2#Vf 8xLw a1&Zr k9$T e7Mn* p4@Hs c6Jy! u3^W z5&Qk d0Xf# m8Rt~ g2Nv t1Ye$ w9Kc+ b4Ao% s7Ui h3Pd! n6Gz@ r0Lq& j5Em v8Bx# f2Sw* y7Cj$ o4Kn 1 Sealed on your phone 2 Ciphertext is all that travels 3 Opened on their phone
Three steps, no exceptions — the middle only ever holds what it can't read.
The problem

Your most private life currently lives on services that can read it — and several of them make their money doing exactly that. A promise not to look is worth whatever the company is worth on the day somebody makes an offer for it. We would rather not be able to look.

The machinery, with the numbers on

Everything on this page is a thing the code does, not a thing we promise.

AES-GCM, 256-bit, on your device

Every private field is sealed before it leaves your phone, with a fresh random 96-bit nonce on every single write — never reused, never derived from anything guessable. What reaches our servers is ciphertext and an initialisation vector. It is never the words.

AES-GCM 25696-bit IV, per writeSealed client-side
RSA-OAEP 2048 between you

The couple's shared key is wrapped to each partner's public key with SHA-256, so it crosses between your two phones without ever existing on a server in a form anyone could use.

PBKDF2, 100,000 rounds

Your recovery phrase is stretched with SHA-256 a hundred thousand times before it becomes a key — so guessing at it costs real time, not milliseconds.

The private key never travels in the open

It is generated on your device and stored in that device's own database. When you move to a new phone or write down a recovery phrase, a copy leaves wrapped under a secret we never see. We could not hand it over if somebody asked us to.

A write refuses without the key

Not “falls back to plaintext”. Refuses, loudly. The one failure mode that would quietly undo all of this is the one the code will not do.

No quiet phone-homes

Fonts, icons and every asset are served by us. Opening the app does not announce itself to an analytics service, a CDN, or an ad network. It talks to one backend — ours, hosted on Google's Firebase — and that is all.

Nothing counts you

No analytics, no measurement IDs, no advertising SDKs, no third-party telemetry anywhere in the app. Not throttled — absent.

You can check the lock yourself

When your key unlocks, the app prints its fingerprint — six characters derived from the key itself. If yours and your partner's match, you are provably in the same box. If they ever stopped matching, you would see it before we did.

Fingerprint on unlockSame six characters, both phones
What stays readable, and why we say so

Timestamps, ids and status flags stay in the clear, because otherwise the app could not sort or find anything at all. The words, the photos, the video, the voice notes and the sessions are the encrypted half — which is the half that would matter if anybody ever got in.

Media never touches the roll

Photos and video record inside the app. They do not land in your camera roll, and they do not land in your photo library's cloud sync.

Deletion takes the media with it

Closing your account sweeps the stored files too, rather than orphaning them in a bucket. Expiring flirts are deleted on a schedule — gone, not hidden.

A new phone goes through you

A one-time sync code moves your keys between your own devices — wrapped under that code, relayed for minutes, then purged. A recovery phrase covers the day both phones are gone.

And the ring around it

Cryptography only holds if the ordinary parts of the app agree with it.

Your keys, made on your phone

When you set up, your device generates its own key pair. The private half never travels in the open. Pairing with your partner derives a shared key strictly between your two devices.

Media stays inside

Photos and video record inside the app and never land in your camera roll. Shared links open in the Lock Box — a private viewer that keeps no history.

Turn anything off

Feature toggles remove entire sections — Date Night, Discussions, the daily question — for your account. Your experience, your call.

The AI stays inside the walls

The guides work with what you've chosen to share, inside your account — your words don't train outside models, and your relationship doesn't feed a profile that follows you around the internet.

Where privacy has limits

We say so instead of pretending

Your network can still see which sites and services you connect to — that's true of every app, and no marketing page should tell you otherwise. Anyone holding your unlocked phone can read what's on its screen. Encryption protects the content of what you share with each other; it can't protect a password taped to the fridge. Honest edges, stated plainly.

While you're here

The reason all of this exists. A channel only the two of you can open.

Messages, photos, video and voice notes that no third party holds a key to — which is what makes it the place you say the thing you would not put anywhere else.

See the private channel →

Flirt like nobody’s watching
— because nobody is

Start Free →

This website is not the app

Two different places, two different rules

Inside the app, nothing watches you. No behavioural tracking, no measurement IDs, no advertising SDKs, no third-party telemetry — your content is encrypted before it leaves your phone and we could not read it if we wanted to. That is the architecture, and it does not change.

This marketing website is a different thing. It is how people find us, and if we buy an advert we need to know whether it worked. So these pages can use standard advertising measurement — the same pixels every business uses — and only after you say yes. Decline and you lose nothing; the site works identically. Nothing measured here ever reaches your account, and nothing from inside the app is ever sent out here.