FAQ · asked often, answered plainly

Fair questions,
answered plainly.

The ones people actually ask — about the keys, the envelope, the helpers, and what happens on the bad days. The technical detail lives on the Trust page.

01What does zero-knowledge actually mean for me?

It means we do not have the keys to your pouch. Only you do. Everything is encrypted in your browser before it reaches us; what we store is a sealed box of scrambled data. If someone broke into our servers, that’s all they would find. There is no master key — not for staff, not for anyone.

02What happens if I forget my passphrase?

Use your recovery key — the one we asked you to write down and put somewhere physical. It works, and then the pouch re-seals with a fresh key.

Lose both, and the honest answer is the hard one: the pouch stays sealed, to you and to us. We cannot reset it, because being unable to is the security guarantee. Keep the recovery key with the passports.

03Is my data encrypted before it leaves my computer?

Yes. Encryption happens in your browser, before network transfer. By the time a record reaches our storage it is already sealed. In transit and at rest, it stays that way.

04What encryption do you actually use?

Plainly: the boring, proven kind.

  • AES-256-GCM — authenticated encryption, so records are both unreadable and tamper-evident.
  • PBKDF2 with 600,000 iterations — your passphrase is stretched hard against brute-force guessing.

The full model is published on the Trust page, including what we hold and what we can’t see.

05How is co-owner sharing different from the handover envelope?

Co-owner sharing is for now — a spouse or partner sharing the whole pouch with you, adding and updating records together, revocable any time.

The handover envelope is for some day — a sealed selection of records that opens for a named person only when the conditions you set are met. One is a second key to the same door; the other is a letter in the safe. The Handover page walks through both →

06How does the envelope know when to open?

By three fixed conditions you set in advance: a quiet period of 14 to 365 days, a written request from your named person once that period has passed, and a no-objection delay of 7 to 90 days before it opens. Before the quiet period completes we try to reach you — answer once and the clock resets. The envelope’s key is split in two, and neither half opens it alone.

07How do the helpers touch my records without leaking them?

They read only the feeds you connect, forward, or upload — never the sealed pouch itself, which they can’t open. Each one classifies or gathers into a proposal; nothing changes a record until you approve the task. Turn the help off, and none of it runs. The house rules are here →

08Can I keep personal and business things together?

Yes — that’s deliberate. If you run a side business, its suppliers, payroll, and client handover notes live on their own shelves in the same pouch, under the same encryption, covered by the same envelope. One place, clear edges.

09Do you use trackers or sell my data?

No advertising trackers, no analytics resellers, no data sales of any kind. We collect the minimum needed to run the service — essentially your email address for signing in. We couldn’t sell your records if we wanted to: we can’t read them.

10What happens to my pouch if PicoPouch shuts down?

You get your records out, readable, with notice — a commitment in the terms rather than a promise in a blog post. And since everything is sealed with your keys, a winding-down company is holding boxes it cannot open.

Asked something we haven’t? Write to hello@picopouch.app — a person answers, usually within a few days.