Cloud storage ยท Privt 0.2
Your files, synced and encrypted
Privt 0.2 adds encrypted cloud storage for Pro. Files sync across your Macs, and the servers that hold them store only ciphertext. The key that decrypts a file exists only on your own devices, so a file stays readable to you and to no one else, including Privt.
Until 0.2, the Privt vault held two kinds of content: the notes you dictate and the meetings you record and summarize. Both were encrypted on your Mac under a key only you hold, and neither was ever readable by Privt. Version 0.2 extends the vault to arbitrary files, including documents, images, PDFs, and archives, encrypted in the same way. On Pro, those files also sync to every Mac signed in to your account.
Syncing files between machines is a common feature, and on its own an unremarkable one. What differs here is how the provider relates to the files it holds. In most cloud storage the provider can read your files, which means it can index them, scan them, use them to train models, profile you from them, and expose them in a breach. Privt is designed so that none of these are possible on the provider side, because the provider never holds a key that can decrypt your files. The sections below describe how that works.
What 0.2 adds
Everything Privt does on your Mac is free, and the main addition in 0.2 is free: you can store your own files in the vault, on-device, each one encrypted the moment it is saved under a key only you hold. This encryption is separate from macOS FileVault. FileVault encrypts the startup volume and protects it while the Mac is powered off or before first sign-in; once you have signed in, the volume is mounted and its contents are readable by the system and by the apps and processes running on it. A file in the Privt vault stays encrypted after that point. It cannot be decrypted with the FileVault volume key, and it cannot be read by another app on the machine, because the key that decrypts it is derived on-device from your passphrase and is never released to the operating system. Pro adds a cloud layer on top of this local protection: an encrypted backup of the vault and sync across your Macs, with each file encrypted on the device before it is uploaded.
What happens before a file leaves your Mac
When you add a file to the vault, it is not uploaded as a file. Privt first divides it into small fixed-size blocks on your Mac and encrypts each block under a key that never leaves the device. Only the encrypted blocks are uploaded, and only the encrypted blocks are stored. Privt does not hold the key that decrypts them, cannot derive that key from anything it stores, and never has access to the plaintext. Everything Privt stores for you is ciphertext.
Before a file leaves your Mac it is split into blocks, and each block is encrypted under a key derived from your passphrase. Only the encrypted blocks are uploaded. The key stays on the machine.
What end-to-end encryption means
End-to-end encryption has a specific meaning, so it is worth stating precisely. Your files are encrypted and decrypted only on your own devices, under keys that exist only on those devices, so the server cannot read the contents or the names of what you keep there. This is a property of the stored data rather than a policy, so it does not depend on our intentions or on who owns the company. If the entire database were copied, or if Privt changed hands tomorrow, the result would be the same: encrypted blocks that no one on the server side can decrypt.
The encryption uses standard, well-studied cryptography. Each block is encrypted with an authenticated cipher, XChaCha20-Poly1305, which keeps the contents confidential and attaches a tag that lets your Mac detect any change to a block in storage or in transit. The key is derived on your Mac from your passphrase through a deliberately slow key-derivation function and remains on the device. It is not escrowed with Privt, not stored with the blocks, and not transmitted when you sign in. What reaches the server is the encrypted output and nothing that can decrypt it.
Because the key stays with you, the server holds ciphertext and nothing else. There is no point at which a file is decrypted on the server to be processed, indexed, scanned, or previewed, because nothing arrives that could be. This is the difference between end-to-end encrypted storage and the more common arrangement in which a provider encrypts data at rest but holds the decryption key. Provider-held encryption protects against a stolen disk and an outside intruder, but not against the provider itself, which holds the key and can read the files whenever it chooses. "We encrypt your files" and "we do not look at your files" are both consistent with the provider being able to look. The distinction that matters is who holds the key, and in Privt that is only you.
The primitives, for anyone who wants them
None of this is our own cryptography. Privt composes primitives that are audited and widely used, from libsodium and Apple's CryptoKit, and every encrypted object carries a version tag, so the scheme can evolve, including a move to post-quantum algorithms later, without stranding data written today.
Content is encrypted with XChaCha20-Poly1305, the IETF construction, under a 192-bit random nonce. It is an authenticated cipher, so a changed byte is caught rather than quietly decrypted into garbage, and every item is encrypted under its own key, generated fresh at the moment you save. The encrypted length is padded up to fixed-size buckets, so even how large a thing you wrote does not leak.
Your passphrase is stretched with Argon2id, version 1.3, set to a desktop floor of 256 MiB of memory, three passes, a single lane, over a 16-byte random salt. Memory-hardness is the point of that setting: it makes each guess expensive on the very hardware an attacker would rent to make guesses at scale. From the passphrase we derive two independent 256-bit values under different salts. One wraps your key and never leaves the Mac. The other is an authenticator, and the server keeps only its hash. At no point do we receive the value that opens anything.
Underneath sits a short key hierarchy. A 256-bit root key is wrapped independently by three openers, any one of which is enough on its own: your passphrase through Argon2id, your twelve-word BIP39 recovery phrase through HKDF-SHA256, and, on a Mac with a Secure Enclave, a hardware key gated by Touch ID. The enclave wrap is an ephemeral P-256 key agreement with the enclave key, run through HKDF-SHA256 into AES-GCM, and the biometric check is enforced by the enclave itself at the moment the key is released, not by a flag in our interface. Re-enrolling a fingerprint invalidates that wrap on purpose, and the recovery phrase is the deliberate way back in. The root wraps an app key, the app key wraps the per-item keys, and the per-item keys encrypt your content. Nothing in that chain is reachable to us.
What our servers can and cannot see
Honesty about an end-to-end encrypted system means being specific about the edges, because "we see nothing" is rarely true down to the last bit, and a claim that overreaches is worse than one that is exact. Here is the precise shape of it. We can see how much encrypted storage an account is using, which we need in order to enforce the quota that comes with a plan, and we can see that encrypted blocks exist. We cannot see the contents of any file, we cannot see its name, and we cannot see its type. A PDF, a photo, and a zip archive of the same size are indistinguishable to us, because all we hold of each is a set of encrypted blocks and a running total of how much room they take.
The metadata we hold is what sync and billing genuinely require, and no more. Everything that describes what a file is stays encrypted on your side.
Deleting a file works the way the rest of the design would lead you to expect. When you remove a file, the encrypted blocks that made it up are reclaimed, and the space they held is returned to your quota. There is no separate legible copy for us to forget to erase, because there was never a legible copy to begin with, so removing your blocks affects nothing but your own storage.
Free stays free, Pro adds the cloud
The split is straightforward: everything that happens on your Mac is free and stays that way, from dictation to meeting capture to file storage in the local vault. The end-to-end encrypted cloud - encrypted backup of your vault and sync of your files and notes across your Macs - is what Pro adds, at $7 a month. What you are paying for is the storage and the sync, and the design is arranged so that paying for it never asks you to make us able to read your files.
Free
Pro
The sync itself is unremarkable, and it works well. What matters is that it works without the server ever holding a key to your files, so that the server-side copy is ciphertext. That Privt cannot read your files is a consequence of how the system is built, not an assurance you are asked to take on trust.