Last updated: 5 August 2026

How Closer Couples protects your data

This is the public version of our security model. The short version: private relationship content is encrypted on your device with a key Closer Couples does not hold, so our servers cannot read it.

The honest trade-off. Because we cannot read your content, we also cannot recover it for you from our side. If both partners lose their devices and the recovery phrase, the encrypted content is gone.

The model in one diagram

When you create a couple, your device generates a strong couple key. Private content is encrypted before it leaves the device. Your partner's device holds the same couple key, so they can decrypt what you choose to share with them. Our servers only see encrypted blobs.

Closer Couples encryption flow: your phone encrypts private content with the couple key, uploads an encrypted blob to Closer Couples servers, and your partner phone downloads the encrypted blob and decrypts locally with the same couple key. Closer Couples holds encrypted bytes and service metadata, not the couple key or plaintext private content.
The couple key stays on approved devices. Closer Couples stores encrypted bytes and service metadata, not plaintext private content.

Where the keys live

What the server can and cannot do

Sensitive actions such as pairing, recovery, premium state, therapist approvals, and game integrity are enforced by backend rules and server-owned writes. The app cannot grant itself access by lying to the API.

The server can see: account email, relationship graph, timestamps, subscription state, push tokens, crash reports, and the encrypted form of private content. Basic service metadata stays visible where it is needed to operate Closer Couples.

Your display name and profile photo are encrypted once you pair. Before that there is no couple key to encrypt them with, so while an invite is open your photo is readable — that is what lets the person you invited see a real face and know they typed the right code. When you pair, both are re-encrypted and the readable copy is deleted.

The server cannot: read private answers, messages, memories, game answers, or encrypted backups; grant itself the couple key; or recover content if both partners lose every device and the recovery phrase.

Threat model

Closer Couples is designed so a database compromise does not expose the private content you wrote.

Out of scope: a partner sharing content outside the app, a compromised phone operating system, or phishing that gives someone both your sign-in credentials and recovery phrase.

Recovery, in plain words

You and your partner receive the same recovery phrase. Keep it somewhere private. If you lose a phone, the phrase can restore your couple key, and partner-assisted restore can help move the key to a new device after an out-of-band code check. If both partners lose every device and the phrase, Closer Couples cannot decrypt the content for you.

Therapist sharing

A therapist never gets the couple key. Therapist sharing requires the therapist, Client A, and Client B to approve the same scope before selected context can transfer. Clients can revoke future access, and messages, media, sexual questions, and blocked packs are outside the therapist export scope. The plain-language overview is on the For Therapists page; the clinical limit notes are on the HIPAA and clinical data page.

Reporting a vulnerability

If you have found a vulnerability, email [email protected] with "Security" in the subject. Please give us a reasonable window to fix it before public disclosure. We will not pursue action against anyone who reports in good faith and does not access other people's data.

See also: Why Closer Couples · Privacy Policy · HIPAA · FAQ · Support