Why anon.li is open source
A privacy tool asks people to trust a black box. Publishing the code was the honest alternative, so that is what we did.
When a product promises privacy, nobody should have to take the vendor's word for it.
Trust is the product
anon.li exists to keep things private: email aliases that hide your real address, files shared under end-to-end encryption, forms whose answers only the owner can read. Every one of those promises is a claim about what our servers can and cannot see — and a closed-source privacy tool asks people to believe such claims on faith.
An alias service sits in the middle of your mail. An encrypted file drop asks for your documents. If the code is hidden, the honest pitch is “trust us” — and “trust us” is exactly what the companies people are escaping kept saying.
Open source replaces the promise with something checkable. Anyone can read the code, follow what happens to a file between the browser and the server, and confirm that the keys never leave the device.
What is public, exactly
The application code is published under the AGPL licence, so anyone can inspect it, fork it, and keep improvements public. The site backs that up with the paperwork trust actually runs on.
- The full application code, under the AGPL licence
- A warrant canary, updated on a regular schedule
- A dedicated security address for vulnerability reports
- Sub-processors listed openly, so you know who else touches your data
Open code is not a security seal
Publishing code does not make it secure, and we try not to pretend otherwise. What it does is remove the asymmetry: the people looking for weaknesses now include people on our side.
A public repository is an invitation to be audited. Reports reach a dedicated security address, get acknowledged quickly, and fixes ship with the same visibility as everything else.
The encryption itself does not depend on secrecy either. Files and form answers are encrypted in the browser before upload, so even a fully compromised server learns nothing it can use. Open code simply lets you verify that claim instead of taking our word for it.
Why there is a free tier
Privacy tools that only paying customers can use end up improving life for a small club. The free tier keeps the useful parts — aliases, transfers, forms — available at modest limits, with paid plans raising them.
“A privacy product should earn its money from the people who use it, not from learning more about them.”
Frequently asked questions
- Is anon.li really open source?
- Yes. The application code is public under the AGPL licence, which also means any hosted fork has to publish its modifications. You are free to read it, audit it, or build on it.
- Doesn't public code help attackers?
- The product's security does not rest on secrecy. Encryption happens in your browser and the keys never reach the server, so there is nothing hidden to protect. Public code mostly means more friendly eyes on it, and vulnerabilities can be reported to a dedicated security address.
- How does anon.li make money?
- Through subscriptions. Paid plans raise the limits on aliases, transfer volume, and forms. The free tier is permanent, and the business model is the subscriptions — not data.