Devices
A member’s account is held on their devices. It contains the authority to use their memberships and the information needed to recognise those relationships after recovery.
There is no central email-and-password account in the membership protocol. A payment provider may separately require billing or account information.
Separate identity per creator
The account derives a distinct membership identity for each creator. A credential for one creator therefore carries a different identifier from a credential for another.
Comparing those identifiers alone does not reveal a shared member. This does not conceal other correlations: payment information, reused contact details, network activity or a member’s own disclosures. The account root remains sensitive because control of it can expose or recreate the derived identities.
Adding a device
Pairing transfers account authority to another device through an encrypted exchange. The existing device approves the recipient, and the person pairing them compares the displayed confirmation before accepting the exchange.
The comparison binds approval to the intended device. An encrypted transfer to the wrong recipient is still a disclosure.
The transferred account material lets the new device recover the membership identities and holdings available to it. Further evidence or content may still need to be obtained from the relevant services. Pairing an account does not replicate every remotely stored file.
Device certificates and shared secrets
The design also defines certificates that grant a device a limited capability under a root identity. A limited certificate and a copy of account-wide secrets are different forms of authority.
Revoking a certificate can end the grant it describes. It cannot make a device forget a root secret already copied to it. The prototype’s device replication must therefore not be described as cryptographically safe removal of a compromised root-holding device.
Backup
A member backup encrypts account and subscription material under a recovery code held by the member. Restoration requires the usable backup data and its code.
Losing one device need not lose the account if another authorised device or a usable backup survives. Losing every usable copy loses the ability to act as the original membership identity. There is no central reset service that can recreate it from an email address.
Possession is the other side of recovery: someone who obtains sufficient backup material may gain the account’s authority. A backup is part of the account’s security boundary, not merely a list of subscriptions.
Creator recovery
Creators also depend on their signing authority, audience encryption secret, publishing state, history and content files. Restoring a member account does not establish that all of these have been restored.
Creator recovery must preserve both authority and data. A valid signing identity cannot decrypt content whose audience secret has been lost, and a valid history cannot recreate unavailable files.
Member-facing vocabulary
The member-facing vocabulary is account, devices and backup. The documentation explains the underlying authority where it matters; subscribing to a creator should not require knowing a cryptographic key format.