dy.ing threat model

threat model

the short version: notes, file contents, and ordinary direct-message bodies are encrypted on your device before they reach us. stored inbox mail is also sealed to your public key, but our SMTP service first receives it as ordinary plaintext. public profiles, necessary metadata, and outbound email are server-visible as described below.

below is the longer, more technical version: what that protects, what it doesn’t, and the rules we hold ourselves to. last reviewed 2026-08-29 · alpha quality.

what we protect against

what we don't pretend to defend against

invariants

these are the contracts. any PR that violates one is rejected.

$ see also: privacy · terms · acceptable use

account custody protocol

Create your recovery key.

Your account is sealed to this browser. The recovery phrase is the only independent key.

Generating account material.

Key derivation and recovery checks run locally before the account is created.