Role and security

Understanding the Circle owner.

A neutral explanation for every participant: which decisions the owner can make, what the role cannot do, and what an ownership change means for access to data.

What the owner controls

A Circle has one owner identity. Its approved devices can perform administrative actions for that role.

Members and roles

The owner invites participants, manages supported roles, and can disable an identity’s future access to the Circle.

Entry points

The owner manages regular invitations, guest links, and other supported ways to enter the Circle.

Circle settings

The owner changes the name and available Circle policies within the limits imposed by the server.

Ownership transfer

The owner can voluntarily transfer the role to another active full member.

The product interface may add capabilities over time, but the role always applies to the whole Circle rather than to one chat or one device.

What ownership does not reveal

Becoming the owner does not itself transfer chat keys or add that person to every existing conversation.

Direct and group chats

The new owner can read only messages whose keys are already available to their identity as a participant in that chat.

Data on devices

A role change does not extract data from participant devices or remotely reveal content they have stored.

Circle metadata

The administrative role includes access to membership, roles, invites, devices, and other data needed to manage the Circle.

Not an absolute statement

If the owner already belongs to a chat or receives its keys through normal membership rules, they see it as a chat participant—not because they are the owner.

Circle owner and server administrator

These are separate powers, although one person may hold both.

Circle owner

Manages members, invitations, and product-level rules for one Circle.

Server administrator

Runs the infrastructure and Circles on the physical server, affecting availability, updates, backups, and technical logs.

Encryption remains

The server stores encrypted content without user keys, while still seeing operational metadata needed for service operation.

Emergency power

A server administrator can recover ownership when the former owner has lost access. The action is explicitly recorded and shown to participants.

How ownership changes

The method is always identified in the Circle system event.

  1. Voluntary transfer

    The current owner signs a transfer to a selected active member.

  2. Emergency recovery

    A server administrator appoints an active member, creates a new profile on their current device, or issues a one-time recovery link to another person.

  3. The former owner remains a member

    By default their identity becomes a regular member. If access is compromised, it can be disabled separately.

  4. Participants are notified

    Every active owner and member, but not guests, receives an event naming the former and new owner, method, and time.

An owner change changes the administrative role but does not itself transfer chat keys. See “What the owner controls” for the canonical list of powers.

Do you manage a Circle?

Practical tasks—creating a Circle, invitations, guest links, devices, and maintenance—live in a separate guide.