Nemi VaultRolling out

The folder we cannot read.

A vault folder is encrypted in your browser under a key generated on your device, which we have never held. Contents and file names are ciphertext to us, and we cannot decrypt them for anybody, including in response to a legal request.

Join the waitlistInstead of Hoping the provider behaves
01

The key never reaches us in usable form

It is unlocked by a passkey or a passphrase on your device. What we store is the wrapped version, which is meaningless without the thing that unwraps it.

02

Access is granted by a member, not by us

Adding somebody re-encrypts the key to them on an existing member's device. We route the result and cannot add ourselves to it.

03

A second lock, so a lost passkey is not the end

The same key is wrapped again under a recovery code shown once at setup. It is a second lock on the same door, not a back door: we hold only ciphertext, and the code never reaches us.

Ten apps. One account.

Nemi is opening in groups while the newer apps finish their rollout.

Join the waitlist