Your computer stays yours.
Most services ask you to trust that they won't look at your data. We built Meradomo so that we can't. Here is precisely what that means, including the parts that are less flattering to us.
Last updated 17 July 2026
The one sentence: we cannot read your data. We do know who you are, which app you reached, and when.
The first half is a promise the design makes for us. The second half is the honest cost of carrying your data to you at all. We'd rather write both down than let you discover the second one later.
What we cannot read
When you set up Meradomo, your Mac creates its own private key. That key is made on your machine and never leaves it. Not to us, not to anyone. Everything a visitor sends and everything your Mac sends back is sealed with it.
Our shared front door, the part of Meradomo that lives on our servers and points visitors at your Mac, never holds that key. It moves sealed bytes it has no way to open. This is not a setting we chose or a rule we follow. There is simply nothing on our servers that could unseal your data.
So we cannot see your files, your photos, your notes, your passwords, what you clicked, or what any app sent back. Not because we promise not to look. Because there is nothing there to look at.
What we do know
Something has to know where to send your data, or it could never arrive. That something is us, and it means we can see a little:
- Your address, and which app. Your apps live at addresses like notes.yourname.meradomo.com, so when a visit comes in we can see which of your apps it is headed for, and when.
- Where the visit came from. A visitor's device connects to us directly, so we see its network address. We deliberately don't pass it on, so even your own Mac never learns it.
- How much, and when. Roughly how much data moved, and at what times.
- Whether your Mac is awake. That's how we know to show the away page.
- Your account. Your email address, your name, and whether your subscription is active.
That's the whole list. We never see what's inside, and there is no version of our system where we could.
When your Mac is asleep
There is exactly one moment when our servers hold a key for your address: when your Mac is offline and a visitor arrives anyway. We show them a short "this computer is asleep" page so they aren't left staring at an error.
Three things make that safe, and none of them rely on our good behaviour:
- It only happens when your Mac is not connected. There is no data in flight to intercept, because the other end isn't there.
- The key is held in memory for a short while and never written down.
- That page is a fixed, pre-written page and nothing else. The code that serves it has no ability to pass a request anywhere. It isn't a doorway that happens to show a message. It can only ever show the message.
The moment your Mac wakes up, we go back to moving sealed bytes we can't open.
Taking access away is immediate
If you disconnect an app or remove a device, that isn't a request that goes into a queue. Your Mac re-checks who is allowed continuously, so access stops within seconds, even in the middle of someone's session.
Where our guarantee stops
A security page that only lists strengths isn't telling you much. Here is where ours ends:
- Your Mac itself. Your data is readable on your own machine. That's the point of it being yours. We protect the journey, not the destination.
- People you invite. If you give someone access, they have access. You can remove it in seconds, but that's after the fact.
- Patterns, not contents. We can tell that you used an app and roughly how much. We just can't tell what you did in it.
- We are still in the path. We can't read your data, but we could refuse to carry it. A shared address means a shared front door.
- We run meradomo.com. Because your name sits inside our domain, a future us, or someone who broke into us badly enough, could in principle issue new keys for your address. Our software doesn't do this, and any such key would be published in a public log where it could be caught. If you'd rather not take our word for it at all, bring your own domain name, and that possibility disappears with it.
Read the details
None of the above is marketing shorthand. If you want the version with the engineering in it, covering the assets, the adversaries, and every claim traced to the thing that makes it true, we publish a full threat model.
See also our Privacy Policy for what we collect and your rights over it, and our Terms of Service.