← Private AI Lockers

Security & Privacy

A plain account of how your locker is protected, who can reach what, and what we can and cannot see. Written to be read by the person who has to approve it.

Access control

Every locker is invite only. Nothing in it is public and nothing is searchable. The administrator decides who gets in and what each person can do, one person at a time.

Sign-in

There are no passwords to steal, guess or reuse. Members sign in with a single-use link sent to their own address.

Encryption

Two layers protect the data itself.

In transit

Every connection between a member’s device and the locker runs over TLS. A coach on hotel wifi cannot be read off the network.

At rest

Stored data is encrypted at rest on Cloudflare’s infrastructure, with stored files encrypted using AES-256 in GCM mode under Cloudflare-managed keys. This is on by default and requires no configuration.

What we can see, in plain language

Your locker is private among its members. It is not invisible to us.

Your files and messages sit on infrastructure we control. That means we are able to access locker content when we need to fix a technical fault, respond to a report of misconduct, or comply with a lawful request. We do not read your locker for any other reason.

Treat your locker like a workplace tool, not a private phone. Never post passwords, Social Security or tax numbers, banking details, or anything else you would not want a parent, an administrator or a court to read.

What is recorded

The locker keeps a record of the things that matter later.

Rooms with young people in them

Where a locker serves minors, the administrator is an adult and the moderation controls stay switched on by design — staff approval on member posts, a report queue, and a full record of who posted what. A room that cannot be moderated is not safer; it is only less answerable.

For practices and clinics: a locker is for staff communication — schedules, coverage, training, policies and announcements. It is not a HIPAA-covered service, we do not enter into Business Associate Agreements, and patient information must never be posted in a locker.

Reporting a problem

If you believe a locker has been accessed by somebody who should not have reached it, or you have found a weakness in the platform, tell us through the contact page and we will answer it ourselves.

Last reviewed 13 August 2026. This page describes the platform as it stands today. We do not describe protections that are not yet in place.