Skip to content

Operator accountability

Every time your tip is opened or acted on, the system writes a permanent record of who did it, when, and why. Operators can read your tip. That is how a tip gets acted on. What no one can do is read your tip in secret.

This page explains what those records cover, why they cannot be changed, and what they do not protect against.

When your tip is opened, the system permanently records who opened it, when, and why. The record is written before the tip is unlocked, so even a failed attempt to open a tip leaves one.

Each read is recorded separately. There is no way to bulk-read tips without leaving that trail. Printing a tip is recorded the same way, with its own stated purpose.

Every record goes into a permanent log. Nothing in that log can be erased or edited, not even by the people who run the platform. Entries can only be added.

This is what lets a program prove who accessed your tip and when. The log also outlives the tip: if a tip is later deleted, the record of who accessed it remains.

These records do not stop anyone at your program from reading your tip. They make every read visible.

An operator who opens your tip sees what you wrote. The protection is not that your tip is unreadable. The protection is that no read is invisible, and the trail cannot be erased afterward.

Accountability works after the fact. A record proves an access happened; it cannot undo one.

  • Encryption: how tips are sealed and who can open them.
  • Anonymity: what the platform does and does not know about you.
  • Retention: how long tips and records are kept.

Every guarantee on this page appears in the full register in How TypVault protects you.