Protect secret in parts.

Meros protects a complete secret record by splitting recovery into Splinters: garbled, protected shares that are useful only when enough valid parts come together.

No one phone, account, cloud service, or keeper holds the whole secret. Protected content stays local unless you intentionally move or share a Splinter.

Get Meros for Android
Meros mark

How Meros thinks about custody.

A Meros is the readable protected record. A Splinter is not a readable fragment of that record; it is protected recovery material. Meros makes that shape visible: what is local, what moved, and when enough parts can reveal.

01 Create

Create one readable Meros for a small secret that deserves deliberate custody.

02 Split

Threshold sharing turns it into Splinters that look like garbage alone.

03 Move

Move or share Splinters with trusted devices or keepers through foreground actions.

04 Reveal

Load enough valid Splinters to reconstruct the readable Meros only when needed.

Mechanics without the machinery.

Meros uses threshold sharing: one protected record becomes multiple cryptographic shares. One share is unreadable; enough matching shares can reconstruct the original under the app's recovery rules.

A readable Meros becomes garbled Splinters.

Before the split, the Meros is the complete protected content. After the split, each Splinter is deliberately garbled recovery material, not a readable piece of the secret.

Meros splits into aligned Splinters Readable Meros Splinter 7QF8 · K2A1 not readable Splinter B9C4 · Z1E0 not readable Splinter M4D2 · X8L6 not readable Full secret Recovery note readable as one Meros Splinter 7QF8 · K2A1 not readable Splinter B9C4 · Z1E0 not readable Splinter M4D2 · X8L6 not readable

Splinters move to trusted paths.

A Splinter can stay local, move to another trusted device, or be shared with a keeper. By itself it still looks like protected garbage, so custody is distributed without handing over the whole Meros.

Local Moved Owner-Gated Temporarily Loaded
Splinter moves to a trusted keeper Owner device Trusted keeper Meros Move Splinter keeper holds one garbled part B9C4 Z1E0 B9C4 Z1E0

Enough Splinters reveal the full Meros again.

When reveal is needed, Meros loads matching Splinters and checks policy gates. Enough valid Splinters reconstruct the original protected content; too few still look like garbage.

Enough Splinters recombine into Meros Load enough Splinters 7QF8 K2A1 B9C4 Z1E0 M4D2 X8L6 Full Meros Recovery note Full Meros Recovery note Reveal Meros

Local-first by default.

Protected content and Splinters stay on your device unless you intentionally move or share them. Meros does not use cloud sync for your secrets.

Platform honest.

Android is first. iOS is planned. Web is future and reduced-capability, not a full clone of a mobile Meros device.

What the user should always understand.

Meros is built around clear custody and recoverable trust, not vague storage. The labels are deliberately plain.

Full Meros

The readable protected record. This is the complete secret content before split and after successful reveal.

Garbled Splinter

A protected recovery share. One Splinter alone is not the secret and is not readable as a useful fragment.

Local

The Splinter is held on this device.

Moved

The Splinter has moved out through a visible custody action.

Owner-Gated

Owner approval is required before access continues.

Healthy recovery

Enough valid recovery paths are available.

Fragile recovery

Recovery needs attention before it can be trusted in practice.