> ## Documentation Index
> Fetch the complete documentation index at: https://evakage.docs.thesteau.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy and storage

> What is encrypted, what remains, and what disappears.

Evakage is built for **temporary, end-to-end encrypted chat and file sharing**. Save files you want to keep.

## What can the server see?

The server handles connections, room membership, and delivery. It can see connected device identities, recipients, and relay sizes.

Messages and files are encrypted on the sending device and decrypted on the receiving device. Relayed content stays encrypted on the server.

## What is stored?

| Data | Where it stays | Lifetime |
| - | - | - |
| Chat history and files held in the app | Browser memory | Lost when that browser closes, reloads, or crashes |
| Pending relay content | Temporary encrypted server buffer | Until delivery, expiry, capacity cleanup, or restart |
| Device identity keys | Browser IndexedDB | Until browser data is cleared |
| Pairings, trust records, preferences | Browser storage | Until removed or cleared |
| Optional accounts and saved settings | Account database | Until deleted by the user or operator |

Accounts do not store messages, files, or device private keys.

Files you save outside Evakage remain on your device.

If another participant still holds a conversation, your browser may recover history after reconnecting. If every browser loses its in-memory copy, direct-only content is gone. [Self-chat](/guides/transfers#message-yourself) can recover from the relay within its expiry window.

See [messages and files](/guides/transfers#how-long-server-copies-last) for relay lifetimes.

## Verify who you connected to

Each browser has a persistent device identity. Evakage checks identity signatures before exchanging content. A changed identity appears as a new device.

Compare safety codes with the owner outside the app. Verification helps confirm ownership; the server's device list alone does not. See [device verification](/guides/devices#verify-a-device).

## Security limits

Evakage has not undergone an independent security audit. Device verification does not protect against a compromised server serving modified app code.

For technical details, read the [security model](https://github.com/thesteau/evakage/blob/main/SECURITY.md) and [review scope](https://github.com/thesteau/evakage/blob/main/maintainer/security-review.md).

## Usage and responsibility

Evakage is provided as is, without warranty. Users are responsible for what they share. Operators are responsible for access controls, updates, backups, and server security. Use it only where you have permission and comply with applicable laws.

Other deployments are not necessarily operated or endorsed by the author. See the [MIT license](https://github.com/thesteau/evakage/blob/main/LICENSE) for the warranty disclaimer and liability terms.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.