The shortest accurate description is: the iPhones hold the private keys, protected media is stored as ciphertext, and the Garnet Thread service coordinates the shared place. The service is designed not to receive device private keys or plaintext photos, videos, previews, thumbnails, messages, or note bodies.
What is encrypted before storage?
The sending iPhone prepares and encrypts the files needed for sharing. That includes original photos, thumbnails, Live Photo and video previews, videos, and voice moments. Message bodies and standalone note bodies use their own encrypted envelopes. Private ritual details are also protected according to their feature-specific contracts.
Each protected item includes the cryptographic information the receiving iPhone needs to authenticate and decrypt it. The service moves those envelopes between the paired devices but does not receive the private device key.
What can the service still see?
Encryption does not remove the operational information needed to run a shared app. Garnet Thread’s service handles device and place identifiers, public device keys, channel and membership records, timestamps, encrypted file sizes and object locations, reaction choices and counts, delivery state, billing entitlement state, and other metadata required for synchronization, abuse prevention, lifecycle actions, and support.
This is why “the server sees nothing” would be an inaccurate promise. The intended privacy boundary protects the content of personal media and messages while allowing the service to coordinate the two-person place.
Who can access a shared place?
API requests are authorized as a registered device and scoped to its paired place. The service applies the same-couple boundary when loading channels, timeline entries, media metadata, messages, reactions, and rituals. Looking up another place’s resource does not reveal whether it exists.
The practical security of an unlocked iPhone still matters. Someone who can use an authorized, unlocked device may be able to view what that device can decrypt. Device passcodes, system updates, and careful handling remain part of protecting the shared place.
What happens if one person leaves?
Different situations need different exits. Garnet Thread’s product path distinguishes:
- Take a Break: pause notifications and hide widget content on one iPhone without changing the shared place.
- Leave: revoke the requesting device’s access.
- Safety Exit: immediately revoke the requesting device and clear its delivery state.
- Close Together: let both people confirm closure, followed by a grace and export window before permanent purge.
Local credentials and protected caches are cleared when an exit completes. Permanent closure removes the shared server-side place and its stored encrypted media after the supported lifecycle window.
How does moving to a new iPhone work?
A one-time device-move flow transfers an encrypted identity envelope directly to the replacement device. The service coordinates the move and rotates the old bearer credential, but it does not receive the source private key in plaintext. This avoids solving recovery by keeping a copy of everyone’s private key on the server.
What this model does not claim
- It does not claim that all metadata is hidden from the service.
- It does not make a compromised or unlocked iPhone safe from someone who can operate it.
- It does not guarantee that software will never contain a vulnerability.
- It does not replace ordinary device security, backups, or responsible sharing between the two people.
These limits are part of the privacy description, not fine print. A useful security promise should say both what the design protects and where its boundary ends.
See the privacy model in the product context.
Read how photos, videos, notes, channels, memories, rituals, and the Home Screen widget fit into one private timeline for two.
Explore the timeline guide