No hand-waving, no "trust us." Here is the real pipeline, the algorithms, and what we can and cannot see.
Privatt is built so that, when you hold a key, we cannot read your data. Your keys are derived and used on your device, we store only ciphertext, and the one mode where we do hold the key says so plainly before you choose it.
In customer-held key modes, your files are encrypted on your device before they leave it, and decrypted back to plaintext only there. We never receive a key or a readable file.
A passphrase only you know is stretched into an encryption key with Argon2id, a memory-hard function built to make brute-force guessing slow and expensive. Your passphrase never leaves your device.
Each file is encrypted in your browser with XChaCha20-Poly1305, a modern authenticated cipher. Files are sealed in streamed chunks, so large uploads never need a plaintext copy and any tampering is caught before anything is decrypted.
Your keys are protected by a master key that is itself encrypted before it is stored. Whether files land in your own Google Drive or OneDrive or in Privatt storage, what we and your cloud provider hold is unreadable ciphertext.
Your files reach plaintext only on your device, in a background worker, and key material is wiped from memory when it is done. No one (not Privatt, not your cloud provider) can read your files along the way.
Every vault is encrypted. You decide who can open it: only you, only with Privatt, or both. Switch anytime.
Like a bank safe-deposit box, opening your vault takes two keys: yours (your passphrase) and Privatt's. Neither of us can open it alone, so stolen data is worthless without both. You keep a passphrase and a one-time recovery key.
Your key comes from a passphrase only you know, so Privatt can never read your vault. You enter your passphrase on each device and keep a one-time recovery key.
We hold your key, so you sign in from any device with nothing extra to remember and no risk of locking yourself out. Because we hold the key, Privatt can read your files (and scan them for malware); this option isn't zero-knowledge.
Not sure? Pick the Two-key vault. Nobody can read your files without your key, and you can switch modes anytime in Settings.
With a customer-held key mode (Your devices only or Two-key vault), here is the honest breakdown.
The exception is Managed by Privatt mode, which you choose deliberately: to sign in anywhere with nothing to remember and let us scan files for malware, Privatt holds the key and briefly handles your files as readable data. It is a convenience trade-off, it is not zero-knowledge, and we tell you before you turn it on.
We use standard, well-reviewed cryptography rather than anything we invented ourselves.
Our encryption envelopes are versioned, so we can adopt stronger algorithms over time without leaving your existing data behind.
The questions worth asking before you trust anyone with your files.
When you set up a customer-held key vault, you save a one-time recovery key. That key is the way back in. If you lose both your passphrase and your recovery key, no one can restore your data, not even us. That is the direct cost of a vault only you can open, and we would rather be honest about it than pretend otherwise.
For customer-held key modes, no. We never hold your key, so there is nothing on our side to unlock your vault with. Your recovery key is the only fallback. (In Managed by Privatt mode we do hold the key, which is exactly the trade-off that mode makes.)
Your files are yours. If they live in your own Google Drive or OneDrive, they stay right where they are. You can export your data at any time and disconnect whenever you like. Nothing is locked to us.
A zip password is usually a fast hash an attacker can guess billions of times per second, with no tamper protection. Privatt derives keys with memory-hard Argon2id, encrypts each file with authenticated encryption that detects tampering, and works across all your devices while keeping the key with you.
In customer-held key modes, no: files are encrypted before they leave your device and we only ever store ciphertext. In Managed by Privatt mode, files are briefly readable on our servers so we can scan them for malware, which is why that mode is labelled as not zero-knowledge.
No. We collect only what we need to run your account, and we never mine, profile, or sell the files you store. In customer-held key modes we couldn't read them even if we wanted to.
The same client-side cryptography that protects your vault also powers Send, our way to send confidential information to anyone.
Create your encrypted vault in minutes and choose exactly who holds the keys.