Records are encrypted on your device.
Source records are encrypted client side before they are written to your vault, rather than sitting there as readable documents.
Vault / models / permissions / deletion
Security is not a badge. It is a set of explicit decisions about what is stored, who holds the key, what reaches inference, what a model may claim, and how access ends.
The actual boundary
These statements are deliberately specific. “Private” should describe an inspectable system, not an atmosphere.
Source records are encrypted client side before they are written to your vault, rather than sitting there as readable documents.
A new device needs both an emailed sign-in code and the recovery key you saved.
Access to the email account alone does not open the vault.
On a query, your question and the source text authorised for that Space go to a private inference endpoint.
So we do not claim that document content never crosses that boundary. It does.
Calculations run on inspectable derivation logic where it is supported, and written summaries stay constrained by exact source quotations.
The challenge step confirms that a displayed quotation exists in the source it cites.
It does not validate an accounting, legal, medical or regulatory conclusion.
If the authorised record cannot support an answer, you get an insufficient-evidence result instead of an invented bridge across the gap.
User controls
Permissions and removal belong in the product, not in a buried policy page.
See which files and connected records a Space can use.
VisibleAuthorise sources per Space, not one undifferentiated account memory.
ControlledDisconnect a source or revoke a Space’s access when its job is done.
ReversibleRemove a Space and its active memory from the product controls.
User initiatedRestore access on a new device with your recovery key.
Recovery keySecurity as a product boundary
See how these boundaries connect to the derivation and receipt system, or explore a product journey without signing in.