Skip to content

Security model

Everything you sync is encrypted on your computer before it leaves, and the server stores only the encrypted result. The server has no key that can open it. This page explains how that works and where its limits are. The exact scheme, for developers, is in the technical security model.

Your password makes two keys. The login key signs you in and opens nothing; the local key stays here and opens your master key.
  1. When you sign in, the app turns your password into two separate keys on your computer. One is a login key, and it is the only thing sent to the server. The other, the local key, stays on your computer and decrypts your data. The password itself is never sent, and one key cannot be worked out from the other.
  2. The local key decrypts your master key. The master key is held only in memory while the app runs, never written to disk or logs, and never sent anywhere unencrypted.
  3. Every clipboard entry and note gets its own random key, and the item is encrypted with AES-256-GCM under it. That item key is then locked with your master key, and with the space key of each space the item is shared into.
  4. The server stores the encrypted items and the locked keys. Your settings are encrypted the same way before upload.
  5. Each device has its own key pair, kept in your system’s credential store: Windows Credential Manager, GNOME Keyring or KWallet. That is how a computer you have signed in on before can decrypt your data again after a restart without asking for your password.

Each encrypted item is also tied to its own ID, so the server cannot swap the encrypted content of one item onto another.

  • Your login does not decrypt your data. The server checks the login key when you sign in, but that key opens nothing. Resetting your password on the server side cannot expose your items.
  • Sharing does not re-encrypt anything. Sharing an item into a space locks that item’s key once more, for the space. The encrypted content stays as it is.
  • Removing someone from a space changes its key for everyone who is left. Older keys are kept so earlier items stay readable to the members.
  • Space keys can be checked. If the space owner has published a fingerprint of the space key, the app checks every key it receives against it and refuses one that does not match.

Save your recovery code

If you forget your password, this code is the only thing that can open your synced items on a new device. We cannot recover them for you.

K7QM2-9XF4P-RH3TW-6NBVY-8ZDGS-J45CX

CopySave as file
Continue

Your recovery code is made from random data on your computer, shown once, and stored nowhere. The server keeps a copy of your master key locked with that code, which is useless without it. That is why a password reset can keep your data: the code, or a computer you have signed in on before, decrypts the same master key under the new password. Making a new code replaces the old one, and the old code stops working.

Any one of these opens the same master key. With none of them, nobody can read your synced data.

If you lose your password and your recovery code, and have no computer that was signed in before, nobody can read your synced data, including us. The steps for each case are in How to reset a forgotten password.

The server needs some information to route and store your items, and it is not encrypted:

  • Your account email and display name, device names, and which devices are online.
  • For each item: whether it is a clipboard entry or a note, its type (text, image, HTML or file), whether it is pinned, its size, when it was created and changed, and which spaces it is in.
  • Space names, who is in each space, and who owns it.

It cannot see what an item says, its preview, your group names, your settings, or comments in a space. Those are all encrypted.

One clipboard entry as the server stores it. It can route and count the item, but not read it.
  • Your local data is not encrypted. History and notes are stored as plain files on your computer. Encryption protects what leaves it. If other people can get into your computer, use your system’s disk encryption.
  • Your device key is only as safe as your system account. Anyone who can sign in to your system account can reach your credential store, and with it your synced data.
  • Updates are signed. The app only installs an update whose signature matches the key built into it.
  • Google sign-in happens in your own browser, which then hands back to the app through an address that only exists on your computer. The app has no built-in browser window that could see your Google password.