gldtgthr
← Back

How this actually works

In plain terms, with nothing left out — including the parts that are less flattering.

The short version

You are already being watched online. Every shop, every streaming service, every social app writes down what you look at, and most pass some of it to advertisers — whether or not you use us. We use the same information, not to sell you something, but to find the people who are into the same things you are.

The watching already happens. We're pointing it at people instead of profit.

What happens, step by step

  1. You browse, as normal. You look at a pair of trainers on eBay. A tub of something on Amazon. An episode on Netflix. A video. A profile.
  2. We read the label the site already put there. Shops and streaming services attach a hidden label to their pages — the product's name and code, the show's title, the video's ID. They do it so that Google, Facebook and advertisers can read it. We read the same label.
  3. Your computer works out what it means. That La Croix is a drink. Those trainers are footwear. That episode is television. This happens on your own machine, in a fraction of a second. Nothing is sent anywhere to work it out.
  4. It builds up what you're into, and how deep you're in it. Which specific things — which bands, which shows, which shoes — and how much time you actually give them.
  5. That only ever gets used against someone else's. Sport 98%. Art 100%. Every number is about two people — never a score of you on your own.

What the percentages actually mean

It's easy to read this as: we decide you're "a music person" and go looking for other music people. That isn't it.

You never get a score on your own. You won't be told you're 80% music — there's nothing to be 80% of. The number only exists between two people, area by area, and it's built from two things:

The second one surprises people. If music is your whole life and someone else listens to three bands, you are not a high music match — even if all three of their bands are in your top rotation. Three shared bands against sixty is a coincidence, not a shared life in music, and the maths is built so that comes out low.

It also means you needn't like every part of an area to match on it. You match on the corner of it you actually engage with.

What it looks at, and what it ignores

The extension can see the pages you open — it has to. But it only writes something down when the page has published a label for what's on it: the kind sites attach for search engines and advertisers.

Your email doesn't have one. Neither does your bank, your medical portal, your work documents, or a private message. Those pages produce nothing. Not a title, not an address, not a record that you were there.

PageWhat is kept
A product on AmazonIts name, brand and product code
An episode on NetflixThe show and the episode
A video on YouTubeThe title and the channel
Your inboxNothing
Your bankNothing
A private messageNothing
Any page with no published labelNothing

The honest bit about "it's already out there"

It would be easy to tell you none of this is new — that every one of these facts is already collected and passed around, so we're adding nothing. That's true of each fact on its own, and it isn't the whole truth. Amazon knows what you looked at on Amazon. Netflix knows what you watched. The advertising code in a shop's page already reports the exact product you viewed. None of that is us.

What is genuinely new is that these things end up in one place. No shop or ad network sees your Amazon, your Netflix and your YouTube together, and together they say more than any one of them does alone. Pretending otherwise would be the kind of thing we'd rather you didn't have to catch us doing.

So here is the actual claim, and it's a better one: that single place is your own computer. We never hold it. We couldn't hand it over, sell it, or lose it in a breach, because it isn't ours to hold.

What would ever leave your computer

Until you join, nothing. Reading pages and building up a picture never touches the internet.

When you join, your computer makes a pair of keys. One half is yours and never leaves the machine. The other half goes to the server so people can reach you. Along with it: a username you choose (not your real name), what you're open to — friends, romance, work — and this:

{ "items": [ { "h": "56e475aa2a159def", "w": 1.12 },
             { "h": "bf1b70e96e5ab38e", "w": 0.94 } ],
  "categories": { "music": 3.1, "film": 2.4, "food": 1.1 } }

Scrambled codes and interest scores — about half a kilobyte, a twentieth of a photo. No titles, no web addresses, no list of sites, no times or dates beyond the day.

You can see yours in the extension, exactly as it is sent. It isn't a summary of the real thing — it is the real thing.

After that, the only other thing that leaves is your messages — and those are locked on your machine before they go, with a key only you and the person you're writing to can make. The server stores something it has no way to open. Nothing else leaves. No analytics, no crash reports, no "usage data".

If someone stole the whole database

"We take security seriously" means nothing. Here is one person's entire record, as a thief would have it:

{ "handle": "aa_m2zf",
  "intents": ["friends"],
  "publicKey": { "x": "szUVRYoJOKfETZxW…", "y": "TJ_UVi-6BLXrA1y7…" },
  "signature": { "categories": { "listening.music": 6, "watching.drama": 3 },
                 "items": [ { "h": "0000000000000001", "w": 3 } ] } }

They would get a full picture of what someone is into. They would have no idea who that someone is. No name. No email address. No phone number. No location. Not one web address. No usable password or login. And every message would be an unreadable block of characters, because the keys that open them were never on the server to steal.

We test that by taking the whole database and searching it for anything that would give a person away — including a name written inside a message. If it ever turns up, the code doesn't ship.

How you actually meet someone

You see a username, an overall percentage, where the overlap lives — Sport 98%, Art 100% — and the specific things you have both looked at, named.

To take it further, you engage. Nothing happens until they engage back. One-sided interest gets you nothing: no message, no notification, no way to reach someone who hasn't reached back. When both have, a conversation opens.

You can block or report anyone, from inside the conversation. Blocking is immediate and works both ways — they disappear from your matches and you disappear from theirs, with no note explaining why.

How you know nobody is reading it

Your messages are locked before they leave your machine, with a key made from your two devices. We store the locked version and cannot open it. That much is straightforward.

The harder question is how you know the key belongs to the person you think it does — because we are the ones who hand it over. A dishonest version of us could pass you our own key instead and read everything without breaking any lock. So:

We test this by having the server turn hostile mid-conversation and swap someone's key for an attacker's. The app must refuse to send. If it ever doesn't, the code doesn't ship.

What we can still see: that your username and someone else's exchanged messages, and when. The contents are hidden from us. Who talks to whom is a harder problem, and we haven't solved it.

What we won't claim

The codes are scrambled, not unbreakable.

Two people's codes must match for any of this to work, so the scrambling can't be unique to you — and a determined server could work backwards to guess a common item. The fix is the two machines comparing lists directly, so the server learns that you matched and never on what. Until that's built, we won't call this part encrypted.

Categories are rough.

Deciding a page about trainers is "footwear" is simple word matching. It gets things wrong. You can see every guess and delete any of them.

A match is not a friendship.

Two people can share a taste in films and have nothing else in common. All we can honestly say is that the overlap is real, not a guess.

Two people who never check the number.

Remembering the key catches it being swapped later. It cannot catch a server that lied from the very first message, before there was anything to compare against. Nothing in software can — that is the one job the safety number does, and it only works if someone reads it out.

The lock is only as safe as your computer.

Your key lives on your machine. Anyone who has the machine has your conversations — including the old ones — and if you lose it they're gone, with no copy to recover.

Your internet connection still shows where you are.

Any website you visit can see the address your connection comes from, and so can ours. We don't record it. But we'd be overclaiming if we said a determined operator couldn't.

What you control

What you don't control — on purpose

You choose what you're open to — friends, romance, work. That's it. You can't pick who comes top, or tell it which of your interests should count for more. There's no dial for "show me people who like what I wish I liked".

You see the people you actually overlap with most, and that's it. If you want the picture to change, change what you spend your time on — the picture follows. That's the only lever, and it's the honest one.