
"End-to-end encrypted" gets used loosely. Here's what it means for Duoheart, specifically.
When you and your partner pair, your devices generate a shared secret key that never leaves your devices in plain form. Every message, every daily answer, every photo is locked with that key before it's sent - our servers only ever see the locked version.
That means if our database were somehow exposed tomorrow, what would leak is unreadable ciphertext - not your conversation. We built it this way on purpose: the safest data is data we never had.
The tradeoff is real, and we think it's the right one: if you lose every device holding your keys, we cannot recover your conversation for you. Privacy that can be bypassed by a support ticket isn't really privacy.