Encryption location and key custody are different questions

Client-side encryption means the file is encrypted on a device before upload. It does not, by itself, tell you whether the provider can recover the key. A service may encrypt in the browser and still operate a recovery system. When evaluating a zero-knowledge claim, ask who can obtain a usable key, which content is protected, and what metadata remains visible. Treat an encryption label as the beginning of that explanation, not a substitute for it.

How ZeroLatch separates Simple and Private

ZeroLatch encrypts uploaded files in the browser. Simple uses service-managed key recovery: the recipient verifies their email and does not need a separate secret. This gives ZeroLatch a technical recovery capability. Private uses a separate password or generated ZeroLatch recovery phrase to protect a random delivery key. That secret must reach the recipient through a separate arrangement. The account login password and the Private delivery secret have different jobs; resetting a login does not replace a lost Private secret.

What the encryption boundary does not cover

An encrypted file is only one part of the service. Account email, recipient address, schedule, ciphertext size and operational status may remain visible. A compromised device, mailbox or delivered browser application can create risks outside stored-file encryption. Encryption does not verify death, grant legal authority, ensure email arrival or replace a backup. The public security explanation describes the current recovery design, including the environment-held Simple wrapping key and the independent audit and managed KMS work that is still incomplete.

Choose a handoff you can actually maintain

For a family or business plan, start with instructions and document locations rather than collecting every secret into one place. Choose a recipient who can explain the plan back to you. If using Private, arrange the separate secret, keep an appropriate backup and rehearse access with a harmless file. With either mode, check that both people understand the check-in and safety period. Read the sample delivery for an explanation of the sequence; it does not perform real encryption or prove the recipient can decrypt your files.