Cryptography · August 7, 2026

Why we ask you to move your mouse

When you create your vault, Privt Voice asks you to wave your mouse around while a field of characters blooms across the screen, a step that can easily look like security theatre. This post explains honestly what it accomplishes, because a privacy product that is imprecise about its own claims does not deserve your trust.

See the ritual

This is the exact step from the app, re-created below rather than filmed. Move your cursor across the panel, or drag on a touch screen, and watch a key take shape out of your own motion.

Move your mouse to generate your keys
Privt Voice

The real onboarding step, not a video. Nothing you do here leaves your browser.

What actually happens

Your encryption keys need randomness, because unpredictability is the entire point. Your Mac already has an excellent source: a hardware random generator feeds the operating system's pool, and that alone is cryptographically sufficient. If we never asked for your mouse, your keys would still be strong.

When you move your mouse, we collect the coordinates and microsecond timings of hundreds of movements and mix them into key generation. The system's randomness and a hash of your movements are combined through a key-derivation function, and the result becomes your keys. By construction the mix can only add unpredictability, so even if your movements were somehow perfectly predictable, the keys would be no weaker than the hardware randomness alone.

The ritual is belt-and-braces: a hedge against the historically rare but documented case of a machine's random generator being subtly broken or backdoored.

Why keep it, then?

We keep it for two reasons. First, the hedge is real, it costs three seconds, and it adds a layer that came from a human hand rather than any silicon we have to trust.

Second, and we will admit this openly, the ritual makes a true thing visible. Your keys really are being born in that moment, on that machine, from randomness no one else could reproduce, and watching it happen tells the truth better than a progress bar ever could.

Where the key lives

So where does that key go once it exists? On a Mac with a Secure Enclave, it is sealed into that enclave the moment it is born. The enclave is a dedicated security chip, kept apart from the processor that runs your apps, and the key placed inside it cannot be exported and will perform its one cryptographic step only after the chip itself sees a live Touch ID.

Your Mac off your Mac Secure Enclave Touch ID your notes, sealed our servers other devices encrypts ciphertext the key never leaves
Minted on your Mac and sealed in the Secure Enclave, the key is used only in memory while you are unlocked, then wiped. Only ciphertext ever leaves; the key does not.

That is what lets the key protect everything while going nowhere. When you open a note, the enclave unlocks the key into memory for the instant it takes to encrypt or decrypt, and then wipes it. Your notes and transcripts are sealed under keys derived from it, so everything written to your disk, and everything synced if you turn on a Pro account, is already ciphertext.

The key itself never crosses onto the network, and it never reaches us. Three sealed wraps can let you back in, your Touch ID, your passphrase, and the twelve words you wrote down, and each of them only unlocks the key in place rather than handing us a copy to keep. On a Mac without an enclave the same key is sealed instead under a passphrase only you know, and the promise holds either way: whatever we store, on your machine or on ours, we are unable to read.

← All posts