Families

Share what matters. Keep the rest yours.

Personal and shared vaults use explicit owner, organizer, editor, and viewer roles without giving the service a universal decryption key.

Clear boundaries

Membership, role changes, invitations, and secret-free event history are default-deny and audited without recording vault contents.

Recipient-only sharing

Current local workflows seal selected vault keys or exact item snapshots to the intended recipient. Emergency and organizer-assisted recovery remain disabled until their external gates pass.

Development availability

Household sharing and recovery workflows are implemented for synthetic local validation, but no family plan, public service, or recovery promise is currently offered.