Zero-knowledge, by construction.
Not a promise. A property of the architecture.
What we do
- AES-256-GCM for every shard, unique 96-bit nonce per chunk, auth tag verified on read
- Argon2id key derivation (64 MB memory, 3 iterations, 4 lanes) — tunable in /app/settings/encryption
- Per-file data keys, wrapped by your master key, so rotating your passphrase doesn't require re-uploading anything
- SHA-256 per shard, verified at write and at read
What we never do
- We never transmit your passphrase or master key
- We never hold a copy of your file content — shards go browser → Google, directly
- We never request full Drive scope
- We never store your manifest on our servers unencrypted
- We never sell, share, or analyze your data. There's nothing to analyze.
What Gyggle protects against
| Threat | Protected? |
|---|---|
| Gyggle servers compromised | Nothing useful to steal |
| Google inspects your Drive | Ciphertext only |
| Network interception | TLS + client-side encryption |
| Lost device | Keys require your passphrase |
| Forgotten passphrase | Not recoverable. By design. |
| Account permanently banned | Mitigated by replication — enable 2× for full safety |
The passphrase tradeoff
We cannot reset your passphrase. Nobody can. If you lose it, your shards are mathematically unrecoverable.
So Gyggle gives you three outs:
- Recovery Kit — a printable PDF with your wrapped key and instructions → /app/settings/encryption
- Social Recovery (Pro) — split your key across 3 trusted contacts, 2 required to reconstruct
- Portable Export — manifest + reconstruction script, so you're never locked to us
Do not skip this. Generate your Recovery Kit during onboarding. Every year we get emails from people who didn't.
Verify, don't trust
Client code is open source and auditable. Reproducible builds published each release. The manifest format is a documented open spec. Check our work: github.com/gyggle
Read the Compliance & Acceptable Use policy