How it works

Encryption you don't have to trust us on.

Most apps ask you to believe they'll keep your data safe. Threadlock is built so belief isn't required — your data is locked before it ever reaches us, with keys only you hold. Here's exactly how.

The core idea

Zero-knowledge, by design.

"Zero-knowledge" means we have zero knowledge of your content. Your messages, files, notes, and passwords are encrypted on your own device — turned into unreadable code — before they're ever sent to our servers. The key that unlocks them never leaves your device and is never shared with us.

So even if someone broke into our servers, or a court ordered us to hand over everything, all they'd get is scrambled data we can't unlock. We didn't just promise not to look — we built the system so we can't.

Step by step

What happens to your data.

You create a message or file

Everything starts on your device — your phone or computer — where only you have access.

It's encrypted locally with AES-256

Before anything leaves, it's scrambled with AES-256 — the same encryption standard trusted by banks and governments worldwide. The key is derived from your passcode and stays on your device.

Only the locked version travels to us

We receive and store an unreadable encrypted blob. We never see the original — not the text, not the file, nothing.

It's unlocked only on the recipient's device

The data stays encrypted the entire way. It's only decrypted at the other end, by someone who holds the right key. End to end.

Under the hood

The protections built in.

🔐

AES-256 encryption

Military-grade, industry-standard encryption on your content — the gold standard, unbroken in practice.

🔑

Keys only you hold

Your encryption keys are derived on your device from your passcode. We never receive or store them.

🧩

PBKDF2 hashing

Passcodes are put through PBKDF2 key-stretching — never stored in plain form, hard to brute-force.

🕵️

Decoy & duress modes

Optional protections that show a fake vault under coercion, so a forced unlock reveals nothing real.

⏱️

Self-destructing sends

Secure Send links can expire or delete after one view — no lingering copies left behind.

🚫

No tracking, no ads

We don't profile you, sell data, or run ads. There's no business reason for us to hoard your information.

Full transparency

What we can — and can't — see.

🔒 We cannot see

  • The content of your messages
  • Your files, notes, and vault entries
  • Your passwords or the keys that unlock them
  • Anything encrypted on your device before it reaches us

📇 We do store

  • Your username and email — to run your account and reach you
  • Encrypted blobs we cannot read the inside of
  • Basic safety data (roles, bans) to keep the platform secure
  • Minimal metadata needed for the service to function

🤝 Our honesty promise

We will never tell you Threadlock is "unhackable." No system is, and anyone who claims otherwise is selling you something.

What we will tell you is the truth: the things you lock stay locked, because we designed the system so we can't open them. The things a service genuinely needs to function — like your email address to send you a notification — a server has to be able to read, and we're upfront that this is true of every app, not just ours.

Real security isn't a marketing claim. It's an architecture you can understand — and we'd rather explain it honestly than dazzle you with promises we can't keep.

Ready to take back your privacy?

Encrypt. Send. Protect. — the way it should have been all along.

Open Threadlock →