Your browser
Titles, bodies, tag names, and todo titles stay encrypted on this device. Your passphrase unwraps them. Lock clears the key from memory.

Architecture
Tuck keeps the mind encrypted in the browser. Hosted pieces exist so accounts, inbound mail, and reminders still work when no tab is open — and so a second laptop can download the same ciphertext and unlock it with your passphrase.
How requests travel
Titles, bodies, tag names, and todo titles stay encrypted on this device. Your passphrase unwraps them. Lock clears the key from memory.
The native app uses the same vault wraps as the browser. Face ID unlocks a Secure Enclave key that unwraps the DEK. Widgets and the share sheet write pending captures; they never hold the raw DEK. Subscriptions stay on the website.
The website you sign into. It holds the vault UI, marketing pages, and an HttpOnly session cookie. It never sees your vault passphrase.
Email, password, and your send-to address. Encrypted vault snapshots can live here so a second laptop can download them. Hosted software cannot read thoughts.
You can publish a snapshot of one tuck as a link. That copy is opt-in so a recipient can read it without the vault. Trial accounts omit attachments on the published copy.
you@sendto.tuckthis.app arrives as ordinary email, then becomes a capture in your mailbox. That path is not the vault.
Trials, paid access, and reminder delivery keep working when no tab is open. They do not store note bodies.
Your vault passphrase and the plaintext recovery kit. A stolen session or inbox still cannot unwrap thoughts.
The trust split in more detail: passkey vs vault passphrase vs recovery kit.