Where your data lives.

We do not display bought-and-paid-for seals: below is a plain account of how our machines are built and what we do to keep safe what you leave with us.

Passwords cannot be recovered

Hashed with scrypt and a per-user salt: not even we can read them back.

Our own servers, in Italy

Data lives on our own machines, not scattered across third-party services.

Always-encrypted traffic

HTTPS enforced everywhere, TLS 1.2 minimum, with protection against inbound attacks.

Hourly copies

The account database is copied every hour and also kept on a second disk.

Watched, not left alone

An automatic check every hour warns us immediately if it sees unusual activity.

No data sold

We do not sell, hand over or trade anyone's data. With anybody.

Where our applications run

Our applications do not sit on a rented service: they run on servers we bought, assembled and look after ourselves, in Italy. Every service lives inside its own separate container, so trouble in one does not drag the others down.

The service that handles accounts is locked down: it can talk to the internet to verify Google sign-ins and to send email, and to nothing else. If somebody did get in, they would not find an open door to the rest of the network.

How data travels

Everything going to and from your phone or computer travels encrypted: HTTPS is enforced, and old, weak versions of the protocol are switched off. In front of our servers sits a filter that absorbs attacks and throttles anyone trying to guess passwords in bulk.

The session that keeps you signed in is signed and stored in a cookie that the browser will not let page scripts read, nor send to other sites.

Your password

We do not keep it. What we store is a fingerprint computed with scrypt — a function designed to be slow and expensive to brute-force — with a different salt for each person. That fingerprint cannot be reversed: if you asked us what your password is, we could not tell you even if we wanted to.

If you sign in with Google, your password never even passes through us: Google is the one telling us it is you.

If something goes wrong

The account database is copied every hour and those copies are kept for a week; every night a copy lands on a second set of disks and stays for a month; the whole machine is backed up nightly to a dedicated backup server. Three different safety nets, not one.

An automatic check looks at what is happening every hour and sends us an immediate alert if it sees too many failed sign-in attempts or other oddities.

What we do not do

  • We do not sell or hand over data to anyone.
  • We do not put advertising trackers on our sites.
  • We do not use what you save to profile you.
  • We do not ask for data we do not need to run the thing you are using.

What you can do

The account is yours and you can take it back whenever you like: you can delete individual pieces of data or the whole account, from the app or by writing to us. The pages below explain how, app by app.

About certifications

We would rather write down what we do than hang up a sticker. Serious certifications — such as ISO 27001 — are issued by an external body after a real audit: the day we hold one, you will find it written here with its certificate number. Until then, what is above is all there is.

Questions about how we handle data? Write to us at [email protected].