Zero-knowledge, by construction.

Not a promise. A property of the architecture.

What we do

  • AES-256-GCM for every shard, unique 96-bit nonce per chunk, auth tag verified on read
  • Argon2id key derivation (64 MB memory, 3 iterations, 4 lanes) — tunable in /app/settings/encryption
  • Per-file data keys, wrapped by your master key, so rotating your passphrase doesn't require re-uploading anything
  • SHA-256 per shard, verified at write and at read

What we never do

  • We never transmit your passphrase or master key
  • We never hold a copy of your file content — shards go browser → Google, directly
  • We never request full Drive scope
  • We never store your manifest on our servers unencrypted
  • We never sell, share, or analyze your data. There's nothing to analyze.

What Gyggle protects against

ThreatProtected?
Gyggle servers compromised Nothing useful to steal
Google inspects your Drive Ciphertext only
Network interception TLS + client-side encryption
Lost device Keys require your passphrase
Forgotten passphrase Not recoverable. By design.
Account permanently banned Mitigated by replication — enable 2× for full safety

The passphrase tradeoff

We cannot reset your passphrase. Nobody can. If you lose it, your shards are mathematically unrecoverable.

So Gyggle gives you three outs:

  1. Recovery Kit — a printable PDF with your wrapped key and instructions → /app/settings/encryption
  2. Social Recovery (Pro) — split your key across 3 trusted contacts, 2 required to reconstruct
  3. Portable Export — manifest + reconstruction script, so you're never locked to us

Verify, don't trust

Client code is open source and auditable. Reproducible builds published each release. The manifest format is a documented open spec. Check our work: github.com/gyggle

Read the Compliance & Acceptable Use policy