Features
Privacy, shown.
This page describes OSL v1 — the product we are building. Some of it works today and some of it is still being finished, and we keep one dated page that says exactly which is which: see what works today. Every animation here is an Illustration drawn to explain the idea, not a recording of the app.
Server protection Beta
The server never has
the real message.
Stored records reveal only the cover.
This is how protected text works today, verified on QA builds and not yet on the release build. The connected service stores the encrypted item and never receives the readable text. Today that item is visibly an encrypted block; making it look like an ordinary message is arriving at v1. It does still see who you talked to and when. The drawing below shows what a stored record looks like when someone opens it.
Before-send warning
Pause before it leaves.
OSL catches a sensitive draft before it reaches an unencrypted box.
The check runs on your own machine and your draft never leaves it. The wording is plain about consequences rather than moral, and the decision is always yours — OSL pauses, it does not refuse. Arriving at v1.
Before and after disclosure
Two moments. Two safeguards.
PWS acts before disclosure. Burn acts after disclosure. They are separate planned safeguards for two different moments; after information leaves your device, OSL can only clean up reachable OSL or service-held copies and report the result.
Before disclosure
Privacy Warning System
PlannedPWS acts before disclosure. It is designed to pause a sensitive draft before it leaves your device, explain the risk in plain language, and leave the final send decision with you.
After disclosure
Burn
PlannedBurn acts after disclosure. It is a Planned cleanup and cooperation flow for reachable copies and reported outcomes, with no promise about copies outside OSL.
Burn does not revoke recipient keys or control copies outside OSL. A recipient device, connected service, export, backup, screenshot, camera, or already viewed content can remain.
- Local deletion.Delete the local OSL state that this device controls.
- Authenticated cooperative peer request.Ask the other OSL client to delete its copy; the peer must cooperate.
- Host deletion attempt.Ask the connected service to remove its hosted item without claiming the service complied.
- Unavoidable copies and screenshots.Copies, screenshots, exports, and backups outside OSL can remain.
Link protection
Share the link. Lose the trackers.
OSL strips the tracking parameters out of a link before you share it, so the person who receives it cannot be followed back to you.
Arriving at v1.
Scrub
Find usernames you left behind.
It checks only username text in a local export you choose.
Planned for v1: Free Scrub will start with the phone export demo shown here, review only username text from that file, then prepare manual review steps you can follow yourself.
It does not connect to services, change accounts, delete anything, or run while you are away. AutoScrub automatic deletion is Planned and unavailable; no provider is currently qualified end to end.
Expiry
Readable until expiry.
Set how long a message stays readable in OSL. When the timer ends, OSL stops showing the readable text and what remains in the app is the encrypted item.
Worth being precise about what a timer can and cannot do: it stops OSL from showing you the message. It does not destroy a key, and it cannot reach a copy, screenshot, export or backup that already left your device. Arriving at v1.