The hardest privacy feature was deciding what not to build
I expected encryption to be the hard part of building Senvra. The harder decisions were the convenient features I left out.
Account recovery, cloud sync and remote access all sound helpful. They also create an account system, a server and another place where private files can exist. I decided the vault should work without an in-app networking layer or Local Network access. Photos, files and notes stay on the device. Recovery uses an access key and an encrypted backup kept by the owner.
The same thinking shaped spaces. The app does not show a catalogue of real spaces at the entrance. A password is the route: one password opens one space. A wrong password does not reveal names, covers or how many spaces exist.
The business model follows that boundary too. Senvra is a one-time purchase, with no ads and no subscription. A local vault should not need recurring billing just to keep existing files available.
There are real tradeoffs. No server means no server-side password reset, and backup discipline matters. But I would rather make that limit obvious than quietly weaken the original promise.
I am the independent developer behind Senvra, which is launching here today. For other makers: which convenient feature was hardest to leave out because it crossed a product boundary?

Replies