“Private and secure” gets said in one breath so often that the two words have blurred into one. They aren’t the same thing — and the difference decides who can actually see your information. The short version: security keeps intruders out; privacy decides who’s allowed in at all. Security is the lock on the door. Privacy is deciding who gets a key — and who even knows what’s inside.
Once you see the distinction, a lot of confusing product claims suddenly become easy to read. Here it is in plain English.
Two different questions
Every product that holds your information answers both, whether it says so or not:
Security
"Can the wrong people get in?" Protection against intruders — encryption, strong logins, alarms, audits. It's about keeping attackers away from what's held.
Privacy
"Who's allowed to look at all?" Control over exposure — who may see, collect, keep, and share your information, including the company holding it.
Security is a property of the walls. Privacy is a property of the rules — and of who holds the keys.
You can have one without the other
This is where the confusion does real damage, because the two failure modes look nothing alike:
Secure, but not private
Most of the internet. A company defends your data expertly against hackers — while reading, profiling, and monetizing it itself. The walls are excellent; you're just not the one they serve.
Private, but not secure
The diary in a drawer, the passwords in a notes app. Nobody's supposed to look — but nothing actually stops whoever finds it. A promise with no enforcement.
Neither half is enough on its own. Security without privacy builds a beautifully guarded warehouse of your life — that someone else controls. Privacy without security is a polite request that survives exactly until someone impolite shows up.
What having both actually looks like
There's one design that delivers both at once — because it changes who holds the keys:
Encrypted on your device
Your data is scrambled before it goes anywhere — intruders who break in find nothing usable. That's the security half.
Only you hold the key
Not the provider, not its staff, not anyone who compels it. Nobody can look without you. That's the privacy half.
You choose every exposure
Sharing becomes a decision you make per person and per detail — not a default someone else set for you.
That design has a name — zero-knowledge encryption — and it's the point where security and privacy stop being separate features and become one architecture.
How to tell what a product actually gives you
Three signals for each — and one red flag that fools almost everyone:
Security signals: encryption in transit and at rest, two-factor authentication, independent audits, a way to report vulnerabilities. These tell you the walls are real.
Privacy signals: data minimization (it asks for less, not more), no selling or sharing with partners, real deletion, and — the strongest — zero-knowledge design, where the provider can't read your data at all.
The question that cuts through: "If this company wanted to read my data tomorrow, could it?" If the honest answer is yes, you have security at best — privacy is running on trust.
The red flag: "we have a privacy policy" offered as proof of privacy. A policy is a description, not a protection — it tells you what a company chooses to do with what it can see. Real privacy means there's nothing for the policy to decide.
We refused to pick one. Simply Once is built zero-knowledge and end-to-end encrypted, so the same design that keeps intruders out also keeps us from ever seeing what you store — and every share is a choice you make, field by field, person by person. Security and privacy, one architecture. You can see exactly how it works on our security page.