A plain account of how your locker is protected, who can reach what, and what we can and cannot see. Written to be read by the person who has to approve it.
Every locker is invite only. Nothing in it is public and nothing is searchable. The administrator decides who gets in and what each person can do, one person at a time.
There are no passwords to steal, guess or reuse. Members sign in with a single-use link sent to their own address.
Two layers protect the data itself.
Every connection between a member’s device and the locker runs over TLS. A coach on hotel wifi cannot be read off the network.
Stored data is encrypted at rest on Cloudflare’s infrastructure, with stored files encrypted using AES-256 in GCM mode under Cloudflare-managed keys. This is on by default and requires no configuration.
Your locker is private among its members. It is not invisible to us.
Your files and messages sit on infrastructure we control. That means we are able to access locker content when we need to fix a technical fault, respond to a report of misconduct, or comply with a lawful request. We do not read your locker for any other reason.
Treat your locker like a workplace tool, not a private phone. Never post passwords, Social Security or tax numbers, banking details, or anything else you would not want a parent, an administrator or a court to read.
The locker keeps a record of the things that matter later.
Where a locker serves minors, the administrator is an adult and the moderation controls stay switched on by design — staff approval on member posts, a report queue, and a full record of who posted what. A room that cannot be moderated is not safer; it is only less answerable.
If you believe a locker has been accessed by somebody who should not have reached it, or you have found a weakness in the platform, tell us through the contact page and we will answer it ourselves.
Last reviewed 13 August 2026. This page describes the platform as it stands today. We do not describe protections that are not yet in place.