Security and transparency
Twokeep is designed so that the company running it cannot see your photos and videos. This page explains how, what the service can still see, and where the protection stops.
It describes the design as it is being built. Twokeep is not available yet, and details can change before launch.
Provider-blind storage
Photos, videos, their titles, request notes and mood tiles are encrypted on your phones before they are uploaded. Twokeep's servers store only the encrypted data. There is no master key, no support unlock and no copy of your keys held by us, so the developer, administrators and the hosting providers cannot decrypt your media with anything they hold. Reports sent to us never include readable media.
Mutual approval
The key for each photo and video is split into two halves, one for each of you. Neither half opens anything on its own. When you approve a request, your phone sends your half to your partner's enrolled phone for what you approved; you never assemble the full key yourself. Someone who takes one phone, or the service's data plus one phone, gets one half, not your media, except items you both chose to share permanently and, for up to 72 hours, an item your partner approved for a timed viewing window.
Device keys are created and kept in the phone's secure hardware and are checked when the phone is enrolled. Where the phone supports it, unwrapping your half of a key needs your face or fingerprint each time.
What the service can see
To run Twokeep, the service holds information that is not encrypted end to end:
- your account, your Apple or Google sign-in identity and your data region (EU or US);
- who shares a vault with whom;
- your enrolled devices and how strongly their hardware was verified;
- the size and checksum of each encrypted file, and its state;
- when requests, approvals, viewing sessions, playback-started events, capture incidents and removals happen;
- subscription and billing state.
The privacy page will set out the purpose and retention of each of these before launch.
What the service cannot do
- decrypt photos, videos, titles or notes;
- combine your half of a key with your partner's;
- add a phone to your account without a verified enrollment and approval from your existing phone or, if that phone is lost, from your partner after a safety-code check;
- approve a request on your behalf;
- keep a viewing session running without the viewer's app;
- recover your recovery key for you.
Where the protection stops
- The person who adds a photo or video already had the original. It stays on their phone, outside the vault.
- During an approved viewing, the viewer's phone puts the full key together for that session. A modified app could keep it, and a later expiry, removal or capture alert cannot take it back.
- A phone controlled by malware can use its protected keys or record what is on screen.
- The protection depends on the app we ship. A malicious future release could capture keys. Publishing the protocol and showing the build hash in the app help others check what we ship; they do not prevent this.
- Screen-capture detection is best-effort and depends on the phone and its system version. When it detects a screenshot or recording, the item locks and needs a fresh approval. A camera pointed at the screen is outside every control. We will not tell you “screenshots always blocked”: no app can promise that, and Twokeep does not.
- Your recovery key is kept in Apple's or Google's synced keychain and, if you choose, in a 24-word recovery phrase that only you keep. For recovery, Apple or Google is part of what you trust. Twokeep cannot recover it for you; without it, and without your old phone, your half of each key is lost and the media in that vault can no longer be opened by either of you.
- If you both choose “Share permanently” for an item, the recipient's phone keeps its full key. Revoking it stops the service and the Twokeep app from opening it, but not a copy that a modified app kept.
- Remove for both deletes the item from the vault for both of you. It cannot reach copies saved outside the vault.
Review status
No external cryptographic review of the Twokeep protocol has been performed yet. That review was set aside for now; the decision and its risks are recorded in the protocol repository (decision record 0005). An internal adversarial review of the specification and the code is planned before launch. We will update this page when the status changes.
Read the protocol
The full protocol specification will be published at github.com/QvverTechnology/twokeep-protocol. The repository is not public yet, so the link may not open for you.
To report a security issue, write to [email protected].