Security architecture

How BageBook protects writing

BageBook uses browser Web Crypto APIs and authenticated Firestore rules. The exact protection depends on whether encryption is configured for the account.

What BageBook encrypts

When encryption is enabled, entry and screenplay content is encrypted with AES-GCM using a 256-bit key. Each encryption operation creates a fresh 12-byte initialization vector. The key is derived from the user PIN or master secret with PBKDF2-SHA-256, a random 16-byte salt, and 150,000 iterations.

Storage and synchronization flow

  1. The editor saves the entry locally in an authenticated user's IndexedDB database.
  2. Encrypted content is queued or synchronized to the user's Firestore path.
  3. Firestore rules require the signed-in Firebase user to match the user path and reject unauthenticated private data access.
  4. The app derives the key in the browser when the user unlocks the account.

What remains local

The encryption key is held in browser memory for the active session. Local IndexedDB databases are user-scoped by authenticated UID. Private entry content should not be treated as public content.

What BageBook does not protect against

BageBook does not protect a device compromised by malware, a PIN or master secret that has been disclosed, screenshots or copied text, browser extensions with page access, or information a user intentionally publishes through public profiles or published community writing. Encryption is optional in the current application, so users should verify their account settings.

These statements describe the current repository implementation and are not a security certification or guarantee. See the technical documentation and privacy summary.