Skip to content

Security

What we do to keep a family’s photographs private.

Heirloom holds the pictures people would be most upset to lose and least willing to see somewhere public. This page sets out the specific protections in place, in plain terms, and is deliberately free of claims we cannot back.

Protections

The measures, one by one.

Each of these describes behaviour that exists in the app today.

Encrypted in transit

Every request between the app and our servers travels over HTTPS (TLS). The app declares no non-exempt encryption beyond that standard transport.

Media is never publicly listable

Photos and videos are held in private object storage. The app receives short-lived signed links to the specific file it is about to show — there is no guessable public URL to a family’s photograph.

Passwords are hashed, never stored

Account and vault passwords are stored only as one-way hashes. Nobody at Heirloom can read your password, and neither can anyone who obtained the database.

Two independent locks

The Vault passcode is a separate credential from your account password. Compromising one does not open the other, and the Vault passcode is never accepted at sign-in.

Brute force is throttled separately

Failed sign-ins and failed vault unlocks are counted and locked out independently. Someone guessing at your Vault cannot lock you out of your account, and vice versa.

A password change ends every session

Resetting or changing your password immediately invalidates every token issued before that moment, on every device — not at the next expiry, but at once.

The Vault relocks itself

Leaving the app relocks the Vault. Returning to it requires the passcode or your biometric again, so an unlocked phone is not an unlocked Vault.

Biometrics stay on the device

Face ID, Touch ID and fingerprint unlock are handled by the operating system’s secure hardware. Heirloom receives a yes or no; it never receives your biometric data.

Deletion takes agreement

In a shared vault, removing an item requires more than one member to agree. Irreversible actions do not rest on a single tap by a single person.

Being straight with you

What Heirloom does not claim.

Security pages are easy to overstate. These are the limits, stated plainly.

  • Media is encrypted in transit and held in private storage, but it is not end-to-end encrypted. Our servers process your files in order to store, resize and serve them. Anyone telling you otherwise about an app with server-side thumbnails and web playback is overselling.
  • A forgotten Vault passcode cannot be read back to you by support, because we do not hold it. Recovery goes through the flow in the app.
  • Heirloom cannot protect a memory from a person you invited to see it. Deciding who is in a journey is the security control that matters most, and it is yours.
  • No service can promise it will never have an incident. What we can promise is what happens if we do — see the disclosure section below.

Your side

What you can do.

  • Set a Vault passcode that is not the same as your phone’s unlock code.
  • Turn on biometric unlock so you are not typing a passcode in public.
  • Review who is in a journey from its ••• menu before you add something you would not want all of them to see.
  • Change your password from Settings if you think a session is not yours — it ends all of them.

Responsible disclosure

Found something? Tell us first.

If you believe you have found a vulnerability in Heirloom, write to security@heirloom.setrick.com with enough detail to reproduce it. We will acknowledge your report, keep you updated while we investigate, and will not pursue legal action against researchers who act in good faith, avoid accessing other people’s data, and give us reasonable time to fix the issue before disclosing it.