circleio
private groups

Protecting a group

Every circleio conversation is already encrypted at rest with its own key. A group that wants more can turn on any of three things, alone or together.

Where: in the web app, open the group → Members & settings → Protection (or "Protection" when you make a new group). From your assistant, just ask: "make the trip group's messages disappear after a day", "start a heavily encrypted group with Sam and Maya", "make this a core group".

Disappearing messages

Pick when new messages go:

  • Once everyone has read them. A message is deleted as soon as every current member has read it. If someone never does, it goes after 7 days anyway.
  • After 24 hours, after 7 days, or after 30 days.

A message stops showing the moment its time is up and is deleted from circleio's database within about a minute. Disappearing messages are never moved into the archive. The timer covers messages sent after it's turned on; any admin can set or change it, and the group sees who did.

Heavy encryption

Normally a group's key is locked with circleio's own server key, so the server can open the group for its members. With heavy encryption, the group's key is locked with a group key that only the members hold instead, and circleio keeps nothing that can open the group without it.

  • When it's turned on, circleio shows the group key once: 32 characters, like ABCD-EFGH-JKMN-…. Give it to the other members yourself, in person or somewhere other than circleio.
  • Each member unlocks the group once with the key. The web app can remember it on your device; assistants use the room_unlock tool.
  • circleio holds an unlocked key only in memory, only for the people who unlocked it, and forgets it 12 hours after their last use or whenever the server restarts.
  • While nobody has it unlocked, nobody can read the group — not the operator, not a backup, not someone with a stolen copy of the database and the server's key. That includes the group's name.

The trade-offs: no message previews, no search, no archive. circleio can't show the key again or recover it: if every copy is lost, so is the history. Only the group's owner can turn heavy encryption on or off.

Core groups: self-destruct if anyone joins

For a group that should only ever be the people in it now.

  • Turning it on cancels every invite link and pending join request, and no new ones can be made.
  • If anyone is ever added anyway, everything said in the group — messages, pinned notes, polls, tasks and archived history — is erased before they get in, and they're kept out. The members see one line saying who tried to join.
  • Any admin can turn it on. Only the owner can turn it off, so one admin can't quietly reopen the group.

What these don't do

  • circleio is not end-to-end encrypted. Your assistant reaches circleio as a server, so the server has to read a message to hand it to your assistant. Heavy encryption protects what's stored; a server that had been tampered with could still see what it serves while a member is using the group.
  • Backups. circleio's nightly backups keep erased and disappeared messages, still encrypted, until those backups are deleted after 14 days. If a group turns on heavy encryption later, backups made before the switch can still be opened the old way until they're deleted.
  • People. Anyone in the group can read, copy or screenshot what they're shown, and anyone you give the group key to can open the group.

The full details of what circleio stores are on the privacy page.