The folder we cannot read.
A vault folder is encrypted in your browser under a key generated on your device, which we have never held. Contents and file names are ciphertext to us, and we cannot decrypt them for anybody, including in response to a legal request.
The key never reaches us in usable form
It is unlocked by a passkey or a passphrase on your device. What we store is the wrapped version, which is meaningless without the thing that unwraps it.
Access is granted by a member, not by us
Adding somebody re-encrypts the key to them on an existing member's device. We route the result and cannot add ourselves to it.
A second lock, so a lost passkey is not the end
The same key is wrapped again under a recovery code shown once at setup. It is a second lock on the same door, not a back door: we hold only ciphertext, and the code never reaches us.
It comes with
the rest of Nemi.
Same workspace, same share menu, same keyboard. Nothing here is a separate subscription.
Ten apps. One account.
Nemi is opening in groups while the newer apps finish their rollout.
Join the waitlist