Structural Guarantee

Privacy

This is not a privacy policy. This is an architecture statement.

Your records. Your device. Nobody else.

There is no server.

There is no database.

There is nothing to breach.

There is nothing to subpoena.

There is nothing to sell.


How this works

When you create a workpad record, it encodes directly into a URL. That URL is the record. It travels through whatever messaging channel you choose — SMS, WhatsApp, email. When the recipient opens it, the app decodes it locally.

At no point does any server receive, store, process, or transmit your data.

This is not a promise. This is the architecture.


What we cannot do

We cannot read your records. The encoding happens on your device. The decoding happens on the recipient’s device. We have no infrastructure between those two points.

We cannot recover your records. If you lose your device and have no backup, the records are gone. That’s the tradeoff. Sovereignty means responsibility.

We cannot comply with data requests. There is no data to hand over. A government could demand our records and receive nothing, because nothing exists.


Comparison

  Traditional SaaS Workpads
Your data stored on Their servers Your device
Who can read it The company, their employees, hackers You and your recipient
What happens in a breach Your data is exposed There is no breach surface
What they sell Your usage patterns Nothing. We can’t see them.
What happens if they shut down Your data may be lost Your records still work. It’s a URL.

The tradeoff

Sovereignty costs convenience. There’s no “forgot password” because there’s no password. There’s no “sync across devices” because there’s no cloud. There’s no “customer support can look at your account” because there’s no account.

You’re in control. Fully.

They sell your data. We can't even see it.