← How it works
7.7 · SECURITY
Security tech — not a promise, an architecture.
Industry-standard encryption, a local vault, on-device LLM, telemetry off by default. This is what backs "we can't read your data".
Argon2id
PIN → key
AES-256
Data encryption
SQLCipher
Encrypted DB
Ollama
Local LLM
key derived from your PIN · never stored on a server · no one else can decrypt
// the problem
Most apps are "cloud-first": data on their servers, encryption keys they hold — you must trust blindly.
// how Apus solves it
Keys derived from your PIN via Argon2id, data encrypted with AES-256 in SQLCipher, sensitive AI runs locally. Telemetry off by default.
Privacy isn't a feature — it's the foundation.
You don't have to trust us — the architecture guarantees it.