How a CruiseBuddy share link works

A short walkthrough of what happens between tapping “share” and your friend opening the cruise.

  1. Your phone makes the key

    When you choose to share a cruise, CruiseBuddy generates a fresh strong encryption key on your device. That key is used to encrypt the cruise bundle locally before anything leaves the phone.

  2. Only ciphertext reaches our server

    The encrypted bundle, a nonce and a message authentication code are uploaded to cruise-buddy.app. We can’t read it, the key never leaves your device. Each share has an expiry date, after which the record is deleted.

  3. The magic link carries the key

    Your share link looks like cruise-buddy.app/share/… with the decryption key tucked into the URL fragment after the #. Browsers don’t send fragments to the server, so only people you give the link to can decrypt the cruise plan.

What sharing does and doesn’t do.

A plain-English summary of what shared cruises actually involve.

End-to-end encrypted

Your phone encrypts the cruise bundle with AES-256-GCM before upload. Owl Media has no way to read the contents.

Links auto-expire

Every share has an expiry date. After it passes, the encrypted record is deleted from our server, no permanent access.

You choose what’s included

Pick which trip details to share, the itinerary, ports, excursions, documents or just the basics. Anything you leave out never enters the bundle.

No account needed for recipients

People you send the link to don’t need to sign up. They open the link, the cruise decrypts in their browser, done.

Revoke any time

Change your mind? Delete the share from inside CruiseBuddy and the encrypted record is removed from our server immediately.

No tracking pixels

Shared pages don’t embed advertising trackers. We log only what we need to keep the service running.

Try sharing in CruiseBuddy.

Encrypted sharing is live in the Android closed beta, with the iOS App Store release available now.