Linen Linen

Security

How Linen is built · Brilliance Digital

The strongest privacy control is architectural: data that never reaches a server cannot leak from one. Linen is designed so the sensitive things stay on your hardware.

On your device

Between devices

Multi-device setup uses a zero-knowledge vault: your credentials are encrypted on-device with keys derived from a 12-word recovery phrase (BIP39 → HKDF → XChaCha20-Poly1305, bound to each entry). Our servers store ciphertext and a key-check value, nothing that can decrypt it. A lost phrase costs nothing but reconnecting your mailboxes.

On our servers

AI requests

AI actions run only when you invoke them, carry only the text you selected, and route through zero-data-retention channels. Token counts are logged for billing; content is not.

Reporting a vulnerability

If you find a security issue, write to support@linen.email with enough detail to reproduce it. We acknowledge within two business days, keep you informed while we fix it, and credit you if you would like. Please give us reasonable time to ship a fix before public disclosure.