Logbook Beta on Sui Testnet. Learn more →
Documentation

Learn Logbook

Everything you need to create blockchain-verified surveys, understand the technology, and get the most out of Logbook.

DocsPrivacy in Groups
7 min read

Privacy in Groups

What the blockchain shows about a group, what is encrypted, who can read it, and where the protection ends.

#The Short Version

Who is a member, who the admins are and how the groups are linked is public, even when the group is private. Names, emails and the text of cards are not.

A private group hides what it is called and what its members say about themselves. It does not hide that an address belongs to it. If the fact of membership is itself sensitive, do not use a group.

#What Anyone Can See

For every group, private ones included:

  • The members as addresses, with when and how each joined and left, and whether an admin ended the membership
  • The owner and the admins, who removed whom, appointments of admins that wait and who made each, and an offer of the group to a new owner
  • The tree: which group hangs under which, requests to link, and paused links. A public parent gives away what a private subgroup belongs to
  • Applicants' addresses, those not accepted and those withdrawn included
  • How people join and whether a card is required
  • Invitation links: that one exists, its limit, its last day, whether it only opens an application, and how often it was used. Not the link itself
  • Lists: that a group keeps a list, each time its files change, and how many seats it has. Not the names of the seats or their links
  • Seats: which address holds a seat of a community, under an id that is a salted hash of the seat's name. Through the published form of a subgroup's list: which taken seats that subgroup lets in
  • Cards: that an address has a card, when it was written and how long each part is. An empty admins part shows that no email was given. Not what the card says
  • Campaigns: which groups a campaign is for, when it was created, its waiting period and its end; who responded and when
  • Sizes and times of every write
For a public group the name, the description and the card form are public too.

#What Is Encrypted

WhatWho can read it
Name, description and card form of a private groupThe owner, the group's own admins and its current members
The members part of a member cardThe card's owner, the owner and the group's own admins, and the current members
The admins part of a member cardThe card's owner, the owner and the group's own admins
The text of an application, and the card sent with itThe applicant, the owner and the group's own admins, while the application waits
The admins' copy of a list: names of seats, expected holders, emails, unused personal linksThe owner and the group's own admins
Title, questions, documents and answers of a campaign with a private group among its participantsAs for any private campaign: the participants and the creator, by the campaign's settings
Everything in this table is encrypted in the browser before it is sent. The contract, the blockchain and Logbook's servers see ciphertext.

#Who Decides Who Reads

Not Logbook. The keys are held by the Seal key servers: independent servers, 2 of 3 of which must agree on Testnet. A key server releases a key only after it has run the group contract's own check for the address that asks: is this address the owner, an admin or a current member of this group, right now?

"The group's own admins" is meant literally. Rights flow down the tree, so an admin of a group above can manage a group below. The keys do not follow: an admin from above reads none of the above until they take a seat among the admins of that group, and the seat shows in the group's public list of admins. A member of a subgroup does not read the private name of the group above either.

#What Happens When Someone Leaves

Removing a member, removing an admin or changing the owner starts a new key period for the group. The contract calls it an epoch and keeps two counters: one for what members read, one for what admins read.

  • What is written afterwards is encrypted for an identity the former reader never had a key for. A removed member is no longer served the group's key or any card. A removed admin is no longer served applications, the admins part of cards or the list
  • What they read before, they may have kept. Encryption cannot take back what was already opened
  • A card written before the change stays as it was until its owner encrypts it again. The page of the group asks for that with one button, and the text stays the same
  • The admins' copy of a list is sealed again with a new key after an admin is removed. Until an admin presses "Seal it again", the stored copy is one whose key the removed admin may still hold. The List screen says so at once
  • An admin who is removed and later appointed again reads again, also what was written while they were out

#Cards When You Leave

Leaving the group, or being removed, closes your card: nobody is served its keys any more, and it stays closed if you come back until you write it again. That is as close to deletion as a blockchain allows. The ciphertext stays in the history, and anyone who read the card earlier may have kept a copy.

#The Limits, Plainly

  • Membership is public. See above
  • Whoever controls a threshold of the Seal key servers reads everything encrypted with them. This is the trust all of Logbook's encryption rests on. Testnet key servers come without guarantees of service
  • The contract can be upgraded during the beta, and Logbook holds the key that upgrades it. An upgrade is a public transaction, but it can change who may decrypt what (see Smart Contract)
  • A card is a self-description. Nobody checks it
  • Public to private does not erase. A group that was public and goes private keeps its old name and description readable in the history of the blockchain
  • An admin from above can get in. They take a seat, visibly, and then read what the group's admins read. A group that links itself under a parent accepts this, and the screen that asks for a parent says so
  • A link is a key. Whoever holds an invitation link can join while it has places; whoever opens a personal link first takes the seat. The secret part stays after the # and never reaches a server, but a forwarded link works for whoever gets it
  • Logbook stores the list files, encrypted, and cannot read the admins' copy. If they are lost, taken seats survive and unused links do not (see Data Storage)
  • No check of identity is available yet. The World ID check and the email check need a Logbook check server that is not running