Skip to content

For developers ​

zeitkapsl is open source and licensed under the GPLv3. If you want to see exactly how your photos are encrypted, audit the cryptography, or build the apps yourself, everything is public.

Source code ​

The full monorepo lives on Codeberg:

codeberg.org/zeitkapsl/zeitkapsl

Because all encryption happens on the client, the client source is where the privacy guarantees actually live, and you can verify them there rather than taking our word for it.

How the code is organised ​

Every app shares as much logic as possible through a common core, so the security-critical code exists in one auditable place instead of being reimplemented per platform.

ModuleWhat it is
core/Shared Go library: sync, crypto, search, and on-device machine learning. Compiled to native bindings for mobile via gomobile.
android/Android app (Kotlin + Jetpack Compose).
ios/iOS app (Swift + SwiftUI).
desktop/Cross-platform desktop app (Go + Wails + Svelte).
cli/Command-line client (Go).
web/Web app (SvelteKit). The only app that does not use the shared core.
server/Backend (Go + PostgreSQL). Stores only encrypted data and metadata.

All cryptographic primitives live in core/pkg/crypto, and the client interface the core exposes is in core/pkg/core.

Building from source ​

Each module builds on its own and has its own README with the exact steps. As a rule of thumb:

  • The core, CLI, desktop, and server are Go projects.
  • The desktop and CLI need ffmpeg (video) and libvips (thumbnails) installed on the system, the same external tools the CLI setup in installation describes.
  • The web app is a SvelteKit project.
  • The mobile apps build with the standard Android and iOS toolchains against the gomobile-generated core bindings.

Start from the repository README, then open the README in the module you want to build.

Reporting security issues ​

Found a vulnerability? Please report it privately to security@zeitkapsl.eu rather than opening a public issue, so we can fix it before it is disclosed. Follow the full policy in SECURITY.md. See the security architecture for how the system is designed.

GPLv3 Licensed