Oct 2026 · Product · 5 min read

Thehandoffproblem

Everyone has the photo. Nobody can share it.

A package lands on the wrong porch. The finder knows an address, the owner knows a tracking number — but there’s no directory of doors, and posting it publicly is a privacy problem wearing a good deed.

Handback is built on an awkward truth: the helpful thing is also the dangerous thing. So the system is designed to leak nothing — even when it works.

The system knows less than it seems

A finder photographs the label — never a name, never a lookup. The app runs OCR on the photo itself, matches name-and-address against claims privately, and the finder’s result looks identical whether or not anyone matched.

Only the verified recipient ever learns a package exists. Nobody can probe the system for “did my neighbor report my parcel” — the answer is a shrug, by design.

The Handback capture flow — two photos of a label
Two photos of the label — the app reads it, nobody else does

Two photos, one code

Capture is deliberately tiny: front of label, back of label, done. From there the handoff is a meetup arranged in-app and confirmed with a rotating pickup code — the finder only hands the box to the person who holds it.

ID verification through Didit is the gate that makes the whole thing safe: the person claiming has to be the person on the label.

The pickup code that confirms a handoff
The handoff — a rotating code beats a handshake

Where it sits now

Version 1.0 is live on the App Store and Google Play, backed by a gateway that rate-limits and screens requests before they ever reach the API — App Check, Redis limits, a private core that does matching with Postgres trigrams.

Private recovery turns out to be mostly an exercise in saying less. The neighborly part is easy; the privacy part is the product.

Have a trust problem to design?

We build products where privacy is the feature, not the patch.