Encrypted contents
Names, Letters, Together list, Story and photo, relationship date and dedications are opaque to the backend.
Private for project
The privacy of Duonook starts from a precise boundary: which contents the service must not be able to read and which technical information is needed to get that content to the right person.
In short
Names, Letters, Together list, Story and photo, relationship date and dedications are opaque to the backend.
Membership of the Nook, devices, catalog, ledger, receipts, times, dimensions and push endpoints are for authorization and delivery.
Authorized devices, local export and account deletion make the data lifecycle visible.
Each Nook corresponds to a cryptographic group and every authorized device is a member of it. Sensitive content is encrypted before leaving the device: the backend carries events and opaque copies, but does not have the keys to interpret them.
The perimeter includes names and nicknames, name of the Couple, date of the relationship, text of the Letters, elements of Togetherness, stages and photos of the Story and dedications of the gifts.
End-to-end does not mean “no data on the server”. Duonook covers the essential information to know which devices belong to a Nook, deliver an event, maintain the integrity of the catalog and ledger, verify receipts and send notifications.
This information may include anonymous identifiers and membership, device identifiers, selected avatars and moods, gift SKUs and status, reactions, wallet movements, game sessions, receipts, timestamps, item sizes and push endpoints. Private text and photos remain separate from this operational level.
Duonook does not promise that every byte is invisible to the service. It promises a verifiable technical boundary between the content of the pair and the data needed to operate the product.
Access to the content depends on the devices recognized by the Nook. Adding a new device goes through an authorization and the cryptographic state is initialized on the device, not reconstructed in clear text by the server.
Each person has a personal key that protects their encrypted vault. On a new phone just open Duonook, choose “Recover my Pair” and paste the key or scan the QR. Once complete, a replacement key is created and the old one stops working.
By design, losing all your authorized devices and your key makes the contents unrecoverable: this is a real consequence of encryption, not a media failure.
Notifications carry generic categories and links, not the text of letters or dedications. Widgets also receive minimal projection and do not expose notes or arbitrary content beyond the encrypted boundary.
From Settings you can export a readable copy of the data on the device. You can also delete the account: the backend removes encrypted material, memberships, sessions and devices, while the app destroys identities and local keys.