Security
Curfew keeps its local-first design when you add an account. The coordinator routes encrypted state; enrolled devices hold the keys.
Account protection
Sign-in uses Apple or Google in your system browser. Every interactive sign-in must then complete fresh two-factor authentication with TOTP or a one-time backup code. A social sign-in alone cannot open account, purchase, device, synchronization, linking, or MCP consent settings. Curfew does not offer a trusted-device bypass.
Encrypted synchronization
Curfew creates a random 256-bit account root key. Devices derive separate namespace keys, encrypt records with AES-256-GCM, sign writes with device keys, and enroll new devices through public-key envelopes. The service stores ciphertext and the minimum routing metadata; it never receives the account root key in plaintext.
Two different recovery tools
Better Auth backup codes recover sign-in only. Recovering encrypted Curfew data requires both an AAL2 sign-in and the separate Curfew Recovery Key. If every enrolled device and that key are lost, Hypertext Studio cannot decrypt or restore the synchronized content.
Remote unlock
Web unlock requires fresh two-factor authentication. MCP clients ask for approval by default; direct authority must be explicitly limited to chosen clients and devices. Each unlock includes a reason, lasts 5–60 minutes, and is audited. Tokens are audience-bound, scoped, revocable, and issued through OAuth 2.1 with PKCE.
Limits
Curfew is a self-control tool, not malware or device management. Operating-system power controls, force stop, another macOS account, recovery tools, and uninstall remain possible. Report a security issue privately to hello@hypertext.studio.