End-to-end encrypted
Your phone encrypts the cruise bundle with AES-256-GCM before upload. Owl Media has no way to read the contents.
Encrypted sharing
CruiseBuddy lets you send a magic link to your travel companions so they can see the cruise plan you choose to share. The interesting part is what doesn’t happen: nobody at Owl Media ever sees your trip details, not even us.
A short walkthrough of what happens between tapping “share” and your friend opening the cruise.
When you choose to share a cruise, CruiseBuddy generates a fresh strong encryption key on your device. That key is used to encrypt the cruise bundle locally before anything leaves the phone.
The encrypted bundle, a nonce and a message authentication
code are uploaded to cruise-buddy.app. We
can’t read it, the key never leaves your
device. Each share has an expiry date, after which the
record is deleted.
Your share link looks like
cruise-buddy.app/share/… with the
decryption key tucked into the URL fragment after the
#. Browsers don’t send fragments to the
server, so only people you give the link to can decrypt
the cruise plan.
A plain-English summary of what shared cruises actually involve.
Your phone encrypts the cruise bundle with AES-256-GCM before upload. Owl Media has no way to read the contents.
Every share has an expiry date. After it passes, the encrypted record is deleted from our server, no permanent access.
Pick which trip details to share, the itinerary, ports, excursions, documents or just the basics. Anything you leave out never enters the bundle.
People you send the link to don’t need to sign up. They open the link, the cruise decrypts in their browser, done.
Change your mind? Delete the share from inside CruiseBuddy and the encrypted record is removed from our server immediately.
Shared pages don’t embed advertising trackers. We log only what we need to keep the service running.
Encrypted sharing is live in the Android closed beta, with the iOS App Store release available now.