This page covers this download site, and the two apps you can get from it — Fiducia Fistbump and Fiducia Whisper. Both are built so that the sensitive part never reaches us in a form we could read.
The short version
This site runs no analytics and sets no tracking cookies. Neither app requires an account. If you do sign in to sync, we hold your vault only as ciphertext we cannot open. Everything is hosted in the UK on renewable energy.
Who we are
Fiducia Fistbump and Fiducia Whisper are made by Fiducia Together Ltd, a company registered in England and Wales, company number 17428906, registered office 9 Merlin Grove, Leyland, England, PR25 1DA. For the purposes of UK data protection law we are the data controller for the information described here.
For anything on this page — including a request to see, correct or delete your data — write to privacy@fiduciatogether.uk.
This website
This site runs no analytics, embeds no third-party scripts and carries no advertising or tracking of any kind.
It sets one cookie, and only if you ask it to. If you change the reading settings — text size, spacing, colours, and the rest of the accessibility toolkit — your choices are stored in a cookie named fiducia_a11y so the pages keep looking the way you set them. It holds those preferences and nothing else: no identifier, and nothing that says who you are. It lasts 180 days, and clearing the settings clears it. There is no cookie banner because a cookie that exists only to deliver something you just asked for is not something you need to consent to.
When you download a file, our web server necessarily receives your IP address, the time, and which file you asked for, in order to send it. That is used to serve and secure the site and to keep it working — not to profile you, and never shared with advertisers.
The apps
Both apps are fully usable without an account. Used that way they make no network request to us at all, and we hold no record that you exist.
If you choose to sign in so that your devices stay in step, your vault is encrypted on your device with AES-GCM before it is sent. We store the ciphertext, a version number, wrapped copies of your vault key that we cannot open, your registered passkeys with the device names you gave them, and your username with a salted PBKDF2-HMAC-SHA256 hash of your password. We never receive your email address, and we never receive anything that would let us read the vault.
A complete breach of our database would yield ciphertext and a list of which devices exist — no usable password, and no working two-factor code. That is a property of the design rather than a promise about our conduct.
Each app has its own fuller policy
They differ in what they hold — Fistbump, for example, briefly records the IP address and approximate location behind an “is this you?” prompt so that you can judge it. Whisper's policy is at whisper.fiduciatogether.uk/privacy.html and Fistbump's at fistbump.fiduciatogether.uk/privacy.html.
What we cannot do
We cannot read your vault, reset your master password, or recover your data if you lose every device and every recovery code. That is the necessary cost of the design above, and it is why both apps ask you to keep a recovery code and an exported backup somewhere safe. If we could rescue you, so could anyone who successfully pretended to be you.
Where your data is, and what it runs on
This site, the downloads, and the sync service behind both apps are hosted in the United Kingdom with Krystal Hosting Ltd, a UK company based in London, on infrastructure we chose partly for its environmental standing. Krystal publishes that its data centres run on 100% renewable energy without relying on offsets, that it has been a certified B Corporation since 2023, that its UK facility operates at a power usage effectiveness of 1.1, and that it is a member of 1% for the Planet and the UN Race to Zero. Its hosting is verified as green by the Green Web Foundation.
Those are Krystal's own published commitments rather than something we audit ourselves; we name them because a claim about green hosting should be checkable, and you can check it at krystal.io/green.
Your data is not transferred outside the UK by us. We do not use an overseas analytics, advertising or profiling provider, because we do not use one at all.
How long we keep it
Your encrypted vault and account are kept for as long as your account exists. Delete your account and the ciphertext, the wrapped keys and the passkey records go with it. Revoking a passkey removes its wrapped copy of your vault key immediately.
Your rights
Under UK GDPR you have the right to access your data, correct it, delete it, restrict or object to how it is used, and to receive a portable copy. Both apps include an export that hands you a complete, decrypted copy on demand, which satisfies portability far better than a request queue would.
To exercise any right, write to privacy@fiduciatogether.uk. If you are unhappy with how we have handled it you can complain to the Information Commissioner's Office at ico.org.uk.
Children
Neither app is directed at children and we do not knowingly hold data about a child. Because neither requires an account and neither collects profile information, we hold no age data about anyone.
Changes to this policy
If this policy changes in a way that affects what we collect or what we can see, we will update this page and change the date below.
Last updated 31 August 2026 · Fiducia Together Ltd.
Fistbump & Whisper