The Daily Inscription
No forms, no submit buttons. Stamping a symptom onto the Ledger feels like ink on heavy paper — and the moment it lands, it's encrypted on your device.
Locket is an encrypted period and symptom journal. Every entry is sealed on your phone — we couldn't read it if we wanted to, and that's the point.
Your data lives in an AES-256-GCM encrypted database on your phone. We have no server-side copy. Not because we deleted it — because it was never there.
Arriving in a post-launch update: hand your clinician one encrypted snapshot by QR code. The key travels inside the code itself — never through our servers. One scan, one handoff, and the Ledger seals again.
When one-shot sharing arrives, the snapshot your clinician receives is a FHIR R4 bundle — the standard hospital systems already use, coded in LOINC and SNOMED, not screenshots and CSVs.
No forms, no submit buttons. Stamping a symptom onto the Ledger feels like ink on heavy paper — and the moment it lands, it's encrypted on your device.
One file, closed with a password only you know. Save it to your own cloud, email it to yourself, drop it on a USB stick. Restore on any phone with that password — your Ledger comes back exactly as you left it.
Leaving should be as protected as staying. One action destroys your encryption key and wipes every entry from your device — no half-erased state, no readable remains. Your history is yours to keep, and yours to burn.
A Clue or Flo export, Apple Health on your iPhone, or a spreadsheet you keep yourself — Locket reads them all. Apple Health is read-only: we can look at what you allow, never touch it.
Locket shows you every entry it found before anything is saved. Approve, and your history is transcribed into encrypted Inscriptions — sealed as it lands. Change your mind? One tap undoes the whole import.
Once inscribed, your history is sealed — private, permanent, and entirely yours. We have no decryption key. We cannot read it, even if we wanted to.
Here is why.
Local encryption. Every entry is sealed on your phone with a single audited primitive — one algorithm, no homemade crypto.
Your key is 256 random bits, minted on first launch and held non-migratory in the iOS Keychain / Android Keystore. It is not derived from your biometrics — Face ID only opens the app. It never leaves your device unencrypted, and it never migrates to another device inside a backup.
If the encrypted store cannot initialize, Locket refuses to run rather than fall back to plaintext.
Clinical output standard. Share payloads are designed as FHIR R4 bundles, coded in LOINC and SNOMED — no translation layer between you and your clinician.
Integrity anchoring, in progress. Locket is designed to anchor tamper-evidence hashes of your encrypted Ledger to a distributed ledger — only hashes, never data, never keys.
Zero server-side plaintext. Our servers never hold your entries — there is no readable copy to hand over.
The decision to keep every byte on-device wasn't a product choice — it was the only ethical architecture for reproductive health data in a post-Dobbs world.
How do you show a clinician your history without giving anyone standing access? A plain-language walkthrough of Locket's one-shot share: a key that travels inside the QR code and never touches a server.
Your cycle data should speak the same language as your clinician's records system. We built Locket's share format against the FHIR R4 spec — coded observations, not screenshots.
"We built Locket so that trusting us is unnecessary."
Be one of the first 100 on the waitlist and lock in lifetime access pricing.
Your email app should open with a pre-filled message — press Send to join. If nothing opened, email support@lockethealth.com.
One email when we launch. No marketing drip, and your address is deleted on request.