· 4 min read

What end-to-end encryption means for a couple, in plain words

No maths, no jargon. What is actually locked, who holds the key, what our servers can see, and the one thing we can never do for you.

What end-to-end encryption means for a couple, in plain words

"End to end encrypted" is written on so many things now that it has started to sound like a sticker rather than a claim. So here is the whole idea in one image, with no maths in it at all.

Imagine you and your partner each have a copy of the same key to the same small box. You put a note in the box, lock it, and hand it to a courier, who carries it across town to your partner. Your partner unlocks it with their copy of the key. The courier is careful and reliable, and the courier also cannot open the box. Not because of a policy, and not because they promise not to, but because they do not have a key.

In this picture we are the courier. That is the honest description of what we do.

What is actually locked

In Duoheart, the things you would expect to be private are the things inside the box: your five daily answers, the conversation thread that grows under each one, your chat messages, the photos you send. They are locked on your device before they leave it, and unlocked on your partner's device when they arrive.

What we hold on our servers is ciphertext. That word means scrambled data: a long stretch of characters that has no meaning without the key. If somebody obtained our database tomorrow, what they would have is a pile of that. Not a diary, not a photo album, not a search-through-able record of your life. Just scrambled data.

Where the key comes from

This is the part that makes the difference between real encryption and the marketing version of it. The shared key is generated on your two devices when you pair. It is not created on our servers and handed down to you, because a key that passes through us is a key we could keep.

So there is no moment where we hold the thing that unlocks your conversation. This is also why you cannot ask us to read a message for you, or to check whether your partner really sent something, or to look up an old answer you have lost. It is not a support policy we could bend for a nice enough e-mail. There is nothing on our side to look at.

Privacy that can be undone by a support ticket is not privacy. It is a promise, and promises change when companies do.

The trade-off we will not hide

Every real security decision costs something, and anyone who tells you otherwise is selling. Here is what this one costs.

If both partners lose their devices, with no signed-in device left anywhere, the conversation cannot be recovered. Not by you, not by us, not by anyone. The key lived on those devices and it is gone with them. We cannot rebuild it from the ciphertext any more than a courier can reconstruct a note from the shape of the box.

We think that is the right side of the trade for an app that holds a couple's most personal writing. But we say it out loud, because finding out afterwards would be a horrible way to learn it. If your daily answers are something you want to keep for twenty years, keep the app installed on a device, and treat that device the way you would treat a photo album.

What encryption does not protect you from

It is worth being clear about the edges, because this is where people are most often surprised.

Encryption protects the message in transit and at rest on our side. It does not protect an unlocked phone lying on a table. Anyone who can open your device and open the app can read everything, because at that point they are you as far as the app is concerned. A screen lock and a passcode do more for your privacy day to day than any amount of cryptography.

It also does not stop your partner from doing anything with their copy. That is not a flaw, it is the definition. There are two ends, and both of them are a person. Encryption is a guarantee about the middle, not a promise about the other end. Trust between two people is still made the old way.

And it does not make the fact that you use the app invisible. We know an account exists, we know an e-mail address for the sign-in code, and we know that data moved. We keep that as thin as we sensibly can, but it is not nothing.

Why we chose this for a couples app in particular

Most encrypted apps are built for a broad idea of safety: journalists, activists, anyone who could be targeted. A couples app has a quieter version of the same need. The daily answers are the sort of thing you would only say out loud once, in the dark, to one person. Someone might write about a fear they have never told anybody, or about wanting a child, or about not wanting one.

That material does not need a dramatic threat to deserve protection. It just needs to stay between two people, permanently, without either of you having to think about it. Encryption by default is how you get to stop thinking about it. The beta install guide for iPhone and Android is at duoheart.app/get.

Questions people ask

Can Duoheart staff read our conversation?
No. The shared key is generated on your devices and our servers only ever store ciphertext, so there is nothing readable on our side to open.
What happens if I lose my phone but my partner still has theirs?
You can sign in again with an e-mail code on a new device and get back to the conversation. It is only the case of both partners losing every device at once that cannot be recovered.
Are photos encrypted too, or only text?
Photos sent in the chat are encrypted the same way the text is. They are locked on your device before they are uploaded.

Keep reading