Security and transparency

Twokeep is designed so that the company running it cannot see your photos and videos. This page explains how, what the service can still see, and where the protection stops.

It describes the design as it is being built. Twokeep is not available yet, and details can change before launch.

Provider-blind storage

Photos, videos, their titles, request notes and mood tiles are encrypted on your phones before they are uploaded. Twokeep's servers store only the encrypted data. There is no master key, no support unlock and no copy of your keys held by us, so the developer, administrators and the hosting providers cannot decrypt your media with anything they hold. Reports sent to us never include readable media.

Mutual approval

The key for each photo and video is split into two halves, one for each of you. Neither half opens anything on its own. When you approve a request, your phone sends your half to your partner's enrolled phone for what you approved; you never assemble the full key yourself. Someone who takes one phone, or the service's data plus one phone, gets one half, not your media, except items you both chose to share permanently and, for up to 72 hours, an item your partner approved for a timed viewing window.

Device keys are created and kept in the phone's secure hardware and are checked when the phone is enrolled. Where the phone supports it, unwrapping your half of a key needs your face or fingerprint each time.

What the service can see

To run Twokeep, the service holds information that is not encrypted end to end:

The privacy page will set out the purpose and retention of each of these before launch.

What the service cannot do

Where the protection stops

Review status

No external cryptographic review of the Twokeep protocol has been performed yet. That review was set aside for now; the decision and its risks are recorded in the protocol repository (decision record 0005). An internal adversarial review of the specification and the code is planned before launch. We will update this page when the status changes.

Read the protocol

The full protocol specification will be published at github.com/QvverTechnology/twokeep-protocol. The repository is not public yet, so the link may not open for you.

To report a security issue, write to [email protected].