Last updated 29 August 2026
You're writing about your marriage here — your goals, what's hard, what you want to protect and what you want to change. That's not something we take lightly, and it's not something we think a company should be able to casually read. So we built it so we can't.
Your answers are encrypted on your device before they're ever sent to our servers. The key lives only in your and your partner's browsers — we never receive it, store it, or have any way to reconstruct it. What sits in our database is unreadable ciphertext.
Concretely: our database, our backups, and anyone who got hold of either cannot read what you wrote. If our database were copied tomorrow, what came out would be gibberish. The one deliberate exception is Emcee — when you ask it for a prompt, that answer passes through our server in readable form for the length of that one request. That's explained below.
We'd rather tell you the edges of this than let the paragraph above imply more than it should. Your answers are decrypted in your browser, because that's the only place they can be read — so anything with a foothold therecan read them too, encryption or not. That includes a compromised or malicious version of this website being deployed, a security flaw in the site that lets someone else's code run in your browser, a browser extension with permission to read pages you visit, and anyone with access to your unlocked device.
What we've removed is the biggest and most boring risk — that your private answers sit in readable form in a database, waiting for a mistake, a leak, or a curious employee. We haven't removed the need to trust the code we ship you, and no design of this kind can.
Emcee, the AI facilitator that reads what you both wrote and asks the question that opens the real conversation, needs to see your answers to do that — but only for the moment it's generating that one prompt. When you submit a step, your browser sends that answer to Emcee for that single request; our server relays it to the AI model and returns the prompt, without ever writing your answer to a database or a log. The encrypted copy that gets saved for later is a separate thing entirely, and our server never has the key to open it.
That is the honest limit of the guarantee: for that moment, our server handles your words in the clear, and so does the AI model we send them to. What we've removed is the permanent readable copy — the record that would otherwise sit in a database for years. If you'd rather Emcee didn't see a particular answer, skip asking it for a prompt on that step; the rest of the session works the same.
When you set up your shared space, your browser generates one key for the two of you. You pass it to your partner directly — that's why it can't arrive in the invite email, since our servers would have to see it to send it. You each also get your own recovery code, and either partner's code opens the same shared data.
If you sign in somewhere new, or clear your browser, we'll ask for that recovery code — or for the shared key itself, if your partner still has it. Because we don't hold either one, we can't reset them for you the way we could reset a password. If both partners lose every copy, that data is genuinely gone, including to us. We think that trade is worth it, and we'd rather be upfront about it than pretend otherwise.
This protects everything you write during a session, your shared notes, and the running context Emcee uses across sessions. Your names, your email addresses and your team name stay readable to us — we need them to sign you in and show you the app. It also doesn't cover any future feature that needs to reach out to you when you don't have the app open; anything like that would need its own design, and we'll explain it here before it ships.
Questions about any of this? Read our Privacy Policy or just ask us directly — we're a small team and we'd rather answer than have you wonder.