Skip to content

Claims are cheap. Records aren't.

Every privacy-first company says the same six things. This page is the version you can check: what we shipped, what we took out, and the limits we publish instead of burying.

Products
1, in internal testing
Analytics SDKs
None in the project
Backend servers
None
Client work
We don't take any
The decision log

What we took out

Every removal we have made on a shipped product, in full — including the small ones. The homepage shows three of these; there is no fourth page where the rest are quietly kept.

Removed cloud sync entirely

The Firebase integration was deleted, not left dormant behind a flag. A vault that syncs is a vault someone else can be compelled to open.

Deleted the analytics screen

The route existed but nothing navigated to it, so it was shipping dead weight in every build. Charts and the charting library went with it.

Cut the AI chatbot

The placeholder screen was removed rather than kept as a promise. We do not know what the right version of that is yet, so there isn't one.

Removed a support email row

It printed the same address one tap away from where the bundled legal documents already printed it. Two of something is worse than one.

Editorial rules

Words we don't use

Every phrase below is banned in our product and site copy, and the ban is written into the source of that copy rather than left to taste. Most of them are meaningless. The rest describe something our software does not do.

Military-grade

There is no such standard. It describes a feeling about encryption rather than a property of it.

Bank-grade

A marketing tier, not a specification. Banks run everything from modern cryptography to mainframes.

Zero-knowledge

A specific cryptographic property, and not one our software implements. Using the word would simply be false.

End-to-end encrypted

There is no second end. Your data never leaves the device, which is a different claim — and the honest one.

Unhackable, bulletproof, hack-proof

Nothing is. Software that claims this is telling you it has not published its limits.

The record

Everything above is checkable on the product itself

We keep the evidence with the thing it describes rather than restating it here. Kinora publishes what it does not do, and every release it has shipped, on its own page — 4 releases so far.

What the software does not do

3 stated limits, published in the product, on this site, and in its own security documentation — in the same words.

What has actually shipped

Every release, from the first internal build to the current one, taken from the changelog rather than written for a website.

See the record