FriendBack to Friend

Security

Last updated 20 July 2026

Friend holds your keys and acts for you. Most apps ask you to trust them with that. We would rather build Friend so that you do not have to. This page says plainly how your data is protected today, and, just as plainly, what we are still building. If a protection is not finished, it is in the second list, not the first.

What is protecting you now

Your data is walled off from everyone else’s

Everything Friend holds for you, your memory, your documents, your people, your keys, is reached only through your own signed-in session, resolved on our server. The database functions that could look up an account or read a document are locked to our service role alone; the anonymous key your browser carries cannot call them. We checked every one of the privileged functions, closed the ones that were open, and revoked the leftover table permissions that could have become a hole later.

Your secrets are encrypted, and every use is on the record

A key or token you connect is sealed with its own encryption key before it is stored, and that key is itself wrapped by a master key held only in our server’s memory. A copy of the database alone reveals nothing. Friend decrypts a secret only for the instant it needs it to act for you; it is never shown back to you on screen, never placed in a message the model writes, and never logged in the clear. Every single time one is decrypted, a line is written to your trail saying so.

A readable trail of what Friend did for you

You can read that trail. Your activity log shows every action Friend took with one of your secrets: when it was stored, each time it was used and for what, and when it was removed. It is yours to see, in plain words, whenever you want.

You can take everything, or delete everything, in one click

From your account you can export your complete data as a single file, or delete your account for good. Delete really deletes: your rows, your uploaded files, and your sign-in, and, if you choose, your data in every other Ecodia app you use your Friend in, with each one confirming before your sign-in is removed. Nothing is left behind quietly.

Poisoned content cannot make Friend act behind your back

Friend reads documents you give it and pages it browses, and some of that text may try to give Friend instructions. Two things stop it. High-confidence injected instructions are cut out of that content before the model ever sees them. And when a turn has taken in any outside content, Friend will not quietly use one of your connected accounts to act on it; that kind of action is held for your approval instead of firing. A poisoned page cannot turn Friend into a way in.

The connection is locked down, and we keep almost nothing about you

Friend is served only over a strict, modern encrypted connection, with browser protections that stop content-type tricks, limit what the page is allowed to do, and hold back what is shared when you follow a link out. Our error monitoring is set to keep no personal data: the text of your chats, your cookies, your sign-in details and your identity are stripped before anything is recorded, and where we count activity we count it, we do not name you in it.

What we are still building

These are real and in progress. We list them here because it would be dishonest to let the section above imply them.

  • Secrets sealed to your phone’s hardware. Today the master key that unwraps a stored secret lives in our server. We are moving the most sensitive ones onto the secure chip in your phone, so that even we cannot open them without your device.
  • Per-app connection keys. We are replacing the single shared key that links Friend to the other Ecodia apps with a separate, revocable key for each app, so no one key can reach across all of them.
  • A hardware approval before high-risk actions. A face or fingerprint check on your phone, backed by that secure chip, before Friend does anything with real consequences: spending money, sending on your behalf, or revealing a secret.
  • A second lock at the database itself. Isolation today rests on our code always asking only for your rows. We are adding a rule inside the database so that even a mistake in our code would be refused rather than leak.
  • Strict content blocking. We already watch for anything a page tries to load that it should not. After a quiet observation window we will switch that from watching to blocking.

Reaching us

You can export or delete your data yourself, any time, from your account. If you would rather we did it, or you have found something that worries you, write to us at our contact page. We would rather hear it early.

Terms·Privacy·Security·ContactFriend, by Ecodia