Three doors closed by the architecture.
This journal touches the most intimate material there is. The only protection that holds is the kind you can’t revoke with a change of terms: what doesn’t exist can’t be demanded, sold, breached, or subpoenaed.
No name, no nickname, no photo, no contact, no date of birth, no social link. One free-text label you choose, and nothing more. That’s what makes GDPR article 9 workable in practice.
No search by person, no matching between users, no reputation signal. Doxxing and defamation would need features we didn’t build.
Your journal only ever goes up encrypted, under a key we do not hold. The service knows your account address, a digest derived from your password (never the password), your sessions without IP address or browser, and encrypted blocks of which it sees the count, the size tier and the rhythm of uploads. Our access logs keep the full IP address of each request. The waiting list keeps your address, your language and the sign-up date; a problem report, what its form announces. Nothing of what your journal contains.
How, concretely
Amure is a web application, with no store, no advertising and nothing that follows you. The account only serves to recognise you and to keep your encrypted data: a verified address and a password, never the content of your journal.
- End-to-end encrypted
- Your journal lives online so you find it on every device, and it is never readable there. Everything is sealed on your device before it leaves. Nobody but you can open it - not us, not our host, not anyone who asks us.
- One password, two branches
- Your password goes through Argon2id on your device, then splits into two keys, neither of which reveals the other. The first goes to the server to recognise you and opens nothing; the second never leaves your device and opens the key to your data.
- A recovery key
- Shown once, when the account is created, and never stored: we keep only a fingerprint. It reopens your journal if you forget your password, and you can draw a new one, which cancels the old. Without the password or the recovery key, nobody can give your data back: a service able to do so would be a service able to read it.
- No language model
- Nothing you write is sent to an AI, not to extract fields, not to rephrase. The sentences on screen come from deterministic templates.
- The server keeps sealed blocks
- Each piece of data leaves as an encrypted block, padded to a size tier. We see how many there are, their tier and the rhythm of uploads; never their type, their content or their exact size.
- Anonymous audience measurement, which you can turn off
- The application counts, with Plausible hosted by us and reached through our own server, the names of the screens opened and a few steps of the journey. Nothing else: not what you write, no dates, no data counts, no account or device identifier, no cookie, no referrer: our server relays the event without them. Plausible derives the country and device type from it, then forgets your IP address. It is on by default; one tap in the settings turns it off, and nothing leaves any more. Before you sign in, nothing leaves either. If your browser asks not to be tracked (Do Not Track, Global Privacy Control), it never leaves.
What this site measures
This site counts its visits with Plausible, an open source audience measurement tool that we host ourselves. No cookie, no identifier that follows you from one day or one site to the next, and never what you type in a form: only the address of the page is sent. A single, strictly functional cookie: lang, set only when you choose a language, holding only that choice and read by no measurement. The app has its own, narrower measurement, which you can turn off, described above.
- What is counted
- The page viewed and the one you came from, time spent and how far down the page you went, the campaign parameters (utm) of the link you followed and the site language.
- What is received and inferred
- Plausible receives the address of the page, the previous page (referrer), the screen width, from which it derives the device type, and the user agent, from which it derives browser and system. From the IP address, which it does not keep, it derives country, region and city. These are totals, never a record per visitor.
- What is never kept
- Neither your IP address, nor your email address, nor a cookie: the only one this site sets, the language one, is removed by our server before relaying. To count a visit only once, Plausible derives from the IP and user agent a salted hash that changes every day, then forgets both.
- Where it goes
- To us: events are sent to this site, whose server relays them to our own Plausible instance, which we run. It passes on your IP address, from which the instance derives the country and an anonymous daily count, without keeping it. Nothing is sold or shared, and the script is served by this site, with no third party.