What we can’t read
Sealed before it leaves your desk.
Your sessions are sealed with a key made from a passphrase you choose. Each of your devices makes the key itself, from the passphrase you type there, and neither is ever sent to us: we hold no key of yours in any form. Each computer seals what its sessions say before sending it: prompts, replies, tool calls and their output, photos, titles, even the text of your alerts. Your phone opens it with the same key. There is no setting for this, and no way round it: we refuse anything that arrives unsealed.
- We can see
- that a session is running, on which of your computers, and when.
- We can’t see
- what you asked, what Claude said, or what it ran.
- We never have
- your password or your passphrase. Your own devices turn them into what is needed; neither leaves them.
- The catch
- we can’t reset what we never had. Your passphrase gets you past a forgotten password. Forget the passphrase, and what was sealed stays sealed.