Sign up
Pick a password. We generate your master key on your device, encrypted by that password, plus a 12-word recovery phrase only you ever see.
Privacy isn't a feature you find in a settings menu. It's the starting position. Everything we build follows from that.
Your files, your filenames, your patterns — traded for storage access. It doesn’t matter whether you’re on a free plan or a paid one. The arrangement is the same.
We think that’s the wrong trade.
Files are encrypted on your device with a master key only you hold. Your password unlocks that master key locally — we receive the password to authenticate you, but never your master key and never your 12-word recovery phrase. Lose both, lose the data. No backdoor, no exceptions. Encryption happens before anything reaches our servers in Falkenstein, Germany — so a breach there leaks only ciphertext.
That trade is the whole point.
Every feature starts from the same constraint: we cannot read your files. Everything built on top of that is designed to stay honest about it.
Files are encrypted on your device before they leave it. The server receives ciphertext. Nothing else.
Your master key lives in your 12-word recovery phrase, not on our servers. We can't read your files. The architecture makes it impossible, not just against policy.
Sign in with a passkey — nothing to phish, nothing to leak. Add TOTP two-factor for a second layer. Your account is as locked down as your files.
Send a link, let someone upload to your vault. You receive the files encrypted. The person uploading never sees what else is there.
Every client is open source. If we said one thing and shipped another, the code would show it.
Share files with a link that expires. The decryption key travels in the URL fragment — the part our server never sees. Revoke any link at any time.
Operated by Initlabs B.V., Netherlands. Stored in Europe. Dedicated EU infrastructure. EU law applies. No US Cloud Act exposure.
Pick a password. We generate your master key on your device, encrypted by that password, plus a 12-word recovery phrase only you ever see.
Drag, drop, done. Files are encrypted on your device before bytes leave you. We see opaque blobs; only you see your stuff.
Share a link. The decryption key travels in the URL fragment — the part our server never sees. Revoke any link, any time.
Your files, encrypted on your device, stored on EU infrastructure. Start on the web or the command line. Native apps are coming soon.
A small group of engineers got tired of cloud storage that asks you to trust the company holding the files.
We’re European. We’re building this out of the Netherlands. We do not run on US infrastructure, and we do not have a backdoor we can be quietly compelled to open. That isn’t a marketing line — it’s a property of the math: your files are encrypted before they ever leave your device, and the keys live in your 12-word phrase, not on our servers.
When we’re legally compelled by valid EU authorities, we hand over what we have — but what we have is opaque ciphertext. Without your password and 12-word recovery phrase, no one (including us) can read what’s inside. Read our security page →
One email when we go live. Then silence.