Your vault · amprenta
Transparency

"We see nothing"
is not true.

We see a few things, and it is more honest to list them than to leave the impression that the server is blind. Here is the full list.

The two columns

The two columns

We see

  • Your email address
  • Billing data, through Stripe
  • IP address and country
  • The timestamp of every action
  • The number of files and folders
  • The shape of the folder tree
  • The size of each file
  • The general category: image, video, document
  • The last modification date
  • Connected devices

We do not see

  • Your password
  • The vault key
  • File contents
  • File names
  • Folder names
  • Tags and notes
  • Photo EXIF data
  • Thumbnails in the clear
  • Your backup code

The left column is necessary so we can measure purchased space, show your list without downloading everything, and detect abuse. It is not an oversight, it is a trade-off we declare.

Why the general type, and not the exact one

Why the general type, and not the exact one

We store image, not image/x-canon-cr2. The difference matters more than it seems: the exact type of a file often says a lot about what is in it. A .kdbx means a password database. A .dcm means medical imaging. The exact type lives encrypted, next to the name.

What we can provide on a lawful request

What we can provide on a lawful request

On a lawful request from a competent authority we can provide exactly the left column: the email address, billing data, IP addresses, action timestamps, sizes, and the encrypted blocks as we store them.

We do not hold the decryption key, so we cannot provide readable content. Not on request, not under legal compulsion, not for a fee. This is not defiance of authorities, it is a technical impossibility arising from the architecture.