P.S. I Love You
Security

You trust us with what matters most

Messages for your children, your voice, your passwords. That deserves an honest story about how we protect it — not empty reassurance, but what we actually do.

One thing first, because it's the heart of everything below: PSILY is built so that we ourselves can do as little as possible. Not because we don't trust ourselves, but because what no one can open can't be stolen, extorted, or accidentally leaked. That principle runs through every choice on this page.

On the way to us: encrypted connection

Everything between your browser and PSILY travels over an encrypted connection (TLS). On public wifi, no one can eavesdrop or alter your message in transit. Your browser also refuses to ever open PSILY unencrypted — even if you accidentally type the wrong address yourself. That setting applies a year ahead and renews itself with each visit, so the first visit on a new device is the only theoretical weak moment, and never again after that.

The security certificate that makes that connection possible renews automatically. If it ever fails silently, our own monitoring raises an alarm three weeks beforehand — well before any visitor would notice.

At the door: hackers, bots, and DDoS attacks

All traffic to PSILY first goes through Cloudflare, one of the world's largest protection networks. It filters out attack traffic before it ever reaches our own server. A DDoS attack — where someone takes down a site by flooding it with requests — is caught there at a scale no single server can handle.

A common mistake is for the own server to remain directly reachable anyway, so an attacker can simply bypass that protection. For us, that can't happen: our server categorically refuses every connection that doesn't come through Cloudflare. Admin access is further limited to one fixed address and works only with a cryptographic key — passwords are simply disabled, so there's nothing to guess.

Your password: unreadable, even to us

Your password is stored nowhere. What we save is an irreversible calculation of it, made with a method that is deliberately slow and memory-intensive (scrypt) and gets its own random addition for each user. If anyone ever got our database, there would be no passwords in it, and the usual approach — trying billions of passwords per second — would yield nothing useful. When checking your password, we also compare in a way that reveals no information through timing differences.

Two-factor verification — we strongly recommend it

The vast majority of accounts taken over anywhere on the internet are lost because the password was leaked elsewhere and reused. Two-factor verification makes that nearly impossible: besides your password, you need a code that only you receive at that moment.

With PSILY, that works simply via your email or an SMS — no separate app you have to install and understand. You choose what you prefer. You get backup codes you can save in case you lose your phone.

It's not required. You can skip it every time you log in and just continue. We'll keep suggesting it though, because we'd rather you spend two extra seconds than ever lose your memories. PSILY administrators don't have a choice: two-factor verification is mandatory for them.

Your messages: who can actually see them?

Your messages are stored encrypted on our servers in Frankfurt, within the European Union. They are therefore fully subject to European law and do not go to servers outside the EU.

More important than where they are stored is who can read them: nobody at PSILY. There is no screen, no button and no administrator function with which an employee can open the content of your messages. That is not a promise about good behavior, but a choice in the design: that possibility simply does not exist. What an employee can see is whether an account exists, how many messages it contains and whether delivery was successful — the administration around it, never the content.

Also: after activating an account, everything is locked. From that moment on, even the legitimate owner cannot change or withdraw anything. What you have prepared stays exactly as you left it.

The digital vault: encrypted in your browser

For your most sensitive matters — passwords, documents, a personal video — there is the digital vault. It works fundamentally differently from the rest, and the difference is worth understanding.

The encryption happens here in your own browser, with a passphrase that you choose and that is never sent to us. What our server receives and stores is a block of ciphertext that we cannot do anything with. There is no master key, no back door and no recovery procedure. If the passphrase is lost, the vault becomes unreadable forever — even for us. That sounds harsh, and it is; at the same time it is precisely what makes the vault so secure. A key that we would have could also be stolen.

When delivering to your recipient, three independent things are needed: a code via SMS, a code via email, and your physical passphrase that you have shared outside PSILY. Whoever has two of them cannot get in. Read how that works in practice on the page about the digital vault.

The cloned voice cannot be used against you

A cloned voice has become a real means of fraud. Therefore, the voice of an AI Clone at PSILY can only speak its own answers and never a text that someone gives it — that boundary is in both the AI and the technology underneath. The detailed explanation is on the page about the AI Clone.

If something goes wrong anyway: backups and recovery

Every hour we make a complete, encrypted backup: the entire database, and in the same round also the new files such as videos and recordings. Every hour its own copy, so not just the latest version. They are stored in a different location than the server itself, so one problem never affects both.

What that means in practice: if something goes seriously wrong, in the worst case one hour of work could be lost — not a day. For something people build on for years, we think that difference is worth it.

A backup you have never restored is an assumption, not a certainty. That is why we periodically perform a real recovery test: the copy is actually restored and checked. That way we know it works on the day it needs to work.

Every night we check ourselves

Security is not a state but maintenance. New vulnerabilities appear daily in software that everyone uses, certificates expire, settings shift. That is why we have an automatic check running every night that looks at exactly that:

That check only reports if there is something. A report that every morning says everything is fine, nobody reads after two weeks — and that is exactly when you miss the night when something goes wrong.

Everything remains yours — even if we disappear

You can download everything you have with us at any time with one click: messages, videos, recordings, contacts. In ordinary file formats that you can open without PSILY. And should PSILY ever cease to exist, there is a worked-out procedure for that with at least six months notice. That is described in the frequently asked questions.

Found a vulnerability?

If you discover a security issue, please let us know via [email protected] instead of making it public. We respond quickly, keep you updated on the solution, and greatly appreciate it. Feel free to investigate, but stay away from other users' data and don't take the service offline.

Want to know what data we process about you and why? That's in our privacy statement.

Start with peace of mind

Create a free account and see for yourself how it works.

Create an account for free
Free to start · no credit card required