How it works

The operating system is local and verified. Only your identity roams — encrypted, restored on login, wiped on power-off.

  1. Boot a local, verified OS. The phone runs an ordinary, content-addressed, OTA-updated OS based on LineageOS — stored on the device, verified at boot. It is not netbooted.
  2. Blind-login your profile. A name + passphrase derive your keys. A wrong credential or unknown profile is indistinguishable from a typo — there is no profile list to leak.
  3. Your state re-materializes. App list, app data, accounts, settings and files are restored from the encrypted store into a fresh, ephemeral space. App code is re-downloaded per device.
  4. Run, replicating encrypted deltas. While you use it, changes are encrypted on the phone and synced to the store — under keys derived from your passphrase that nowhere never receives.
  5. Power off → blank slate. The ephemeral data is sealed to the store, then wiped. The device holds none of your plaintext content at rest; log in on any nowhere device to get it all back.

See it in action

Unlock at the gate — your session restores into a fresh phone.

Your apps, messages, and files, back where you left them.

Questions

What is a nowhere phone?

A phone running our OS, where your identity lives encrypted in the network rather than on the handset. Log in with a name and passphrase and your session appears; power off and it's wiped from the device.

What happens if I lose it, or it's stolen?

Powered off, it holds none of your content — just the OS. A thief gets hardware, not your data. Log in on any other nowhere phone and everything is back.

What if I forget my passphrase?

Your data can't be recovered — not by you, not by us. There's no master key and no reset. Keep your passphrase (and the 12-word recovery code we show you) safe.

What's the difference between my passphrase, PIN, and security key?

They do three different jobs, and only one is the real key to your account:

  • Your passphrase is the root. It derives the keys that unlock your data, and we never receive it. There is no reset and no master key — keep it, and the 12-word recovery code we show you, safe. Lose both and the data is gone for good.
  • A hardware security key is the strongest addition. Enroll one (connected over USB-C or tapped over NFC) and signing in then needs your passphrase and a touch of the key — two factors, so a stolen passphrase on its own won't open your account.
  • A PIN is only for quick re-unlock. Set a short PIN to wake a session you're already signed into on the same phone, with guessing slowed by the phone's own hardware. It never replaces your passphrase — signing in fresh on any device, or after the phone powers off, always takes the full passphrase.

So: the passphrase is essential, a security key makes it markedly stronger, and a PIN is a convenience layered on top — never a substitute.

What happens when I leave my phone idle?

Your session is protected in stages, and you can tune the timing per profile:

  • Screen off — a quick lock. Your session stays in memory; your passphrase brings you straight back to where you were.
  • Idle a while (15 minutes by default) — sealed and set aside. Your session is encrypted into the store and cleared off the device, so only ciphertext remains at rest. Your passphrase unseals it in place — nothing to re-download.
  • Idle much longer (12 hours by default) — wiped. The local session is erased entirely, and you simply sign back in fresh from the network.

Both timers live in your profile's security settings: standby from 2 minutes up to an hour (or off), and auto-wipe from 1 hour up to a day (or only on power-off). Powering the phone off always wipes it.

Can nowhere read my data?

No. Your content is encrypted on the device under keys derived from your passphrase, which we never receive. We hold only ciphertext, and your usage isn't linked to your payment. See exactly what we do keep →

Can you link my payment to what I store?

No — and not by policy, by cryptography. When you buy credit, your device mints a storage token and has us blind-sign it (RFC 9474 blind RSA): we stamp it valid without ever seeing the token itself. Later, when that token is spent to keep your storage alive, we can confirm the stamp is genuine but can't tie it back to your purchase or your identity. Your payment and your storage sit on two sides of a cut we can't cross.

You pay card · identifiable You store pseudonymous no link blind-signed
Your payment is identifiable; your storage is pseudonymous. The blind signature severs the two — we can check a token is valid, never whose it is.
Which phones does it run on?

diaspore runs on Fairphone today, with Motorola, OnePlus, Nothing, Sony, and Xiaomi support on the way. endospore (the hardened edition) targets Pixel. Tell us your phone on the waitlist to help us prioritise.

What roams, and what doesn't?

Your apps, app data, accounts, messages, files, and settings roam. Some OS state and telephony don't yet — the supported set is growing.

Can I keep maps and files offline, and does it use up my storage?

Yes — and you choose per app, since things like offline maps can be large. In the Offline media settings you pick, for each app, one of three options:

  • Essential — downloaded when you sign in and kept on the phone, so it opens instantly and works with no signal. Best for maps you rely on.
  • Auto — fetched ahead of time in the background over Wi-Fi, so it's ready without spending mobile data. (You can allow mobile data too.)
  • On-demand — nothing is downloaded ahead of time; it streams from your encrypted store the moment you open it, and is only cached temporarily.

Your plan measures your footprint — what's sealed in your encrypted store — not what's sitting on the phone. Your maps and files count the same in the store whichever option you pick; the setting only changes how much is also kept on the device. On-demand items stream and cache only temporarily, so they don't permanently fill up your phone.

How much does it cost?

1 GB is free — cleared if the account sits unused for 90 days. Paid plans start at $0.99/mo (10 GB), up to 1 TB, with ~2 months free on annual, and paid storage stays as long as it's paid. You only spend credit on what you actually store.

How do the monthly and annual plans work?

Start free, then pay when you want more room. Whichever way you pay, you only spend credit on what you actually store, so a quieter month stretches further. Two ways to pay:

  • Subscribe monthly — it auto-renews on the same date each month and charges you again, so your storage never lapses.
  • Prepay a block of credit — a one-time purchase, a month or a year at a time, that doesn't renew; you just top up again when it runs low. Paying a year up front costs about two months less than twelve monthly charges.

Prepaid credit doesn't start counting until you enter the code on your phone, and a year's worth lasts a full year at your plan's size — longer if you store less.

Is it open source?

Yes — the OS, the client, and the architecture are open. diaspore · endospore

Two editions, one roaming store

diaspore (on LineageOS) is available now — Fairphone today, more phones soon. endospore (Pixel, on GrapheneOS) is the hardened edition coming later. Both share the same accountless, zero-knowledge store and plans.

Join the waitlist