How it works
A drive your devices keep between them.
Your devices carry changes to each other and nothing else moves bytes at all. These are the five mechanisms that make that work, in the order a file meets them.
Every file sealed, segment by segment
Each file is sealed with XChaCha20-Poly1305 under a key of its own, as a stream of 64 KiB segments. A file of any size passes through without being held in memory, and only an intact segment opens, so what arrives is exactly what you saved.
No names in the clear
Each file carries a record sealed under the library key and named by a keyed hash of its path, so what travels between your devices, and what a bucket stores, is a hash where a name would be.
The library key never syncs
A device gets it once, inside the pairing link, and keeps it in the platform's own key store: DPAPI on Windows, the Android Keystore, and a file only your account reads on macOS.
Step by step
From a saved file to another device holding it.
Sealing
A file is sealed before anything carries it
Each file gets a key of its own and goes through XChaCha20-Poly1305 as a stream of 64 KiB segments, so a file of any size passes through without being held in memory. Only an intact segment opens, so what comes out the other side is exactly what went in.
Naming
The path is hashed, not written down
Each file carries a record sealed under the library key and named by a keyed hash of its path. What travels between devices, and what a bucket stores, names no file and no folder.
Pairing
A device joins by a code you hold up
A computer shows a code and the phone scans it, or the phone shows one and the computer reads it back. The pairing carries the library key, which is the one thing that never syncs: each device keeps it in the platform's key store — DPAPI on Windows, the Android Keystore, or a file only your account reads on macOS.
Finding
Nothing asks a directory where you are
A device knows the addresses the pairing gave it, and talks to those on 27950 for sync and 27951 for pairing. Discovery of every kind is switched off.
Fetching
A listing is cheap; the bytes come when you ask
Every file is listed everywhere. A folder left only in the app keeps its listing and gives that device its space back, and opening a file pulls it from whichever device or bucket has it. Keep on this device fetches ahead of time instead.
Storing
A bucket is an extra device that is always on
Attach an S3 bucket per device — AWS, MinIO, R2 or Ceph — and that device's disk becomes a cache of the size you choose while your files stay reachable with the other devices off. The bucket holds the same ciphertext under the same hashed names.
When two devices disagree
Both versions survive.
- Devices talk only to each other
- On 27950 for sync and 27951 for pairing, to the addresses a pairing link gave them. Discovery of every kind is switched off.
- Two edits, both kept
- A file changed on two devices while they were apart is kept twice, the second as a conflicted copy, so both days' work are still there.
- Fetch on open, or ahead
- A folder left only in the app keeps its listing and gives the disk space back. Opening a file pulls it from whichever device or bucket has it.
- Out of the phone's backup
- The drive lives in Android's no_backup directory, which Auto Backup always skips.