Client-side encryption
Content is encrypted locally using modern authenticated encryption. Persistent media objects use independent per-file keys referenced from protected Entry data.
Security model
SovaSpace encrypts user content on the device before cloud storage. This page states the protection model, the metadata that still exists, and the risks encryption cannot remove.
Core claim
Entry titles, tags and documents are authenticated inside encrypted Entry objects. Attachments, media and separate supporting files such as subtitles and annotations use encrypted object formats. NURSOVA’s service layer coordinates accounts and sync but is not designed as a plaintext content store.
Content is encrypted locally using modern authenticated encryption. Persistent media objects use independent per-file keys referenced from protected Entry data.
Encrypted objects are written to locations created by SovaSpace in the customer’s Google Drive. Unrelated Drive files are outside the requested access model.
Cloudflare infrastructure handles account, device, subscription and sync-control facts. It necessarily sees limited metadata, not plaintext Entry bodies or media bytes.
What remains visible
Any security claim that ignores metadata is incomplete. These categories can remain visible to the relevant provider or to NURSOVA.
Google account identity, Sova account identifiers, device identifier and display name, platform, session state and subscription status.
IP address, request time, error class, encrypted object identifiers, approximate sizes, counts, timing and Google Drive quota usage.
Google can observe the existence, approximate size and timing of stored objects even when SovaSpace uses identifiers that do not reveal meaningful filenames.
An unlocked device, operating-system compromise, clipboard contents and files deliberately exported as plaintext remain outside the protection provided by cloud encryption.
Secret Space
Secret Spaces keep independent unlock state and apply stricter rules when the app leaves the foreground. They are intended to reduce accidental exposure and separate especially sensitive work.
On Windows, Standard Space can restore a trusted session from OS-protected secure storage. Application auto-lock is a privacy cover; it is not a substitute for operating-system account security, secure boot, device encryption policy or physical control of the computer.
Secret Space on Android
The screens show current configuration and behavior. Secret Space protects an in-app boundary; it does not defeat a compromised or already unlocked device.




Recovery
The Windows Cold Backup workflow creates a verified encrypted control package. Complete disaster recovery also depends on the required encrypted objects remaining in Google Drive or in a user-managed external encrypted mirror.
The control package is checked before commit and opens read-only and offline.
Customers decide where to keep the package and any external encrypted object mirror.
Backup viewing and migration operate without editing the original package.
Windows recovery workflow
These screens show the current Windows workflow. A verified control package is one part of the recovery plan, not a claim that every large encrypted object is inside that package.




The Privacy Policy explains data categories, service providers, retention and deletion in detail.