Google knows the account
Google OAuth handles identity. The current UNIIC client does not send it recovery words, vault keys, or protected workspace content.
The workspace
Notes, rich-text documents, daily tasks, and encrypted Drive media now share one vault. Habits, languages, and boards remain planned.
FRIDAY · 17 JULY
Today’s focus
Build the calm core.
Quick note
A quiet surface for the idea that should not disappear.
ENCRYPTED ON DEVICE · LOCAL FIRST
03
Tasks today
02
Coming next
Privacy without theatre
Identity and encryption are deliberately separate. The implementation is a real client-side encrypted MVP, but it is not independently audited and it does not hide all metadata.
Google OAuth handles identity. The current UNIIC client does not send it recovery words, vault keys, or protected workspace content.
UNIIC creates a 24-word recovery phrase in the browser. It is the offline secret behind the vault hierarchy and cannot be reset by UNIIC.
Readable content exists in an unlocked browser. Servers receive authenticated ciphertext plus operational metadata during normal operation.
One system, many surfaces
A focused opening for tasks, notes, and what matters now.
Focused writing with encrypted local persistence and ciphertext sync.
A configurable daily dashboard with rollover, subtasks, and encrypted state.
Rich-text documents with encrypted sync and capability-based view or edit links.
Encrypted photo and video uploads, previews, downloads, shares, and albums.
Rhythms and streaks without an engagement algorithm watching.
Practice data that belongs to the learner, not an ad profile.
Visual thinking connected through encrypted objects.
The promise