Security model
Everything you sync is encrypted on your computer before it leaves, and the server stores only the encrypted result. The server has no key that can open it. This page explains how that works and where its limits are. The exact scheme, for developers, is in the technical security model.
How your data is locked
Section titled “How your data is locked”<<never sent>>
Password
<<opens nothing>>
Sync server
<<in memory only>>
Master key
<<one per item>>
Item key
<<AES-256-GCM>>
Your item
<<credential store>>
Device key
<<one per space>>
Space key
- When you sign in, the app turns your password into two separate keys on your computer. One is a login key, and it is the only thing sent to the server. The other, the local key, stays on your computer and decrypts your data. The password itself is never sent, and one key cannot be worked out from the other.
- The local key decrypts your master key. The master key is held only in memory while the app runs, never written to disk or logs, and never sent anywhere unencrypted.
- Every clipboard entry and note gets its own random key, and the item is encrypted with AES-256-GCM under it. That item key is then locked with your master key, and with the space key of each space the item is shared into.
- The server stores the encrypted items and the locked keys. Your settings are encrypted the same way before upload.
- Each device has its own key pair, kept in your system’s credential store: Windows Credential Manager, GNOME Keyring or KWallet. That is how a computer you have signed in on before can decrypt your data again after a restart without asking for your password.
Each encrypted item is also tied to its own ID, so the server cannot swap the encrypted content of one item onto another.
What this means for you
Section titled “What this means for you”- Your login does not decrypt your data. The server checks the login key when you sign in, but that key opens nothing. Resetting your password on the server side cannot expose your items.
- Sharing does not re-encrypt anything. Sharing an item into a space locks that item’s key once more, for the space. The encrypted content stays as it is.
- Removing someone from a space changes its key for everyone who is left. Older keys are kept so earlier items stay readable to the members.
- Space keys can be checked. If the space owner has published a fingerprint of the space key, the app checks every key it receives against it and refuses one that does not match.
Recovery
Section titled “Recovery”Save your recovery code
If you forget your password, this code is the only thing that can open your synced items on a new device. We cannot recover them for you.
K7QM2-9XF4P-RH3TW-6NBVY-8ZDGS-J45CX
Your recovery code is made from random data on your computer, shown once, and stored nowhere. The server keeps a copy of your master key locked with that code, which is useless without it. That is why a password reset can keep your data: the code, or a computer you have signed in on before, decrypts the same master key under the new password. Making a new code replaces the old one, and the old code stops working.
<<through the local key>>
Your password
<<shown once, stored nowhere>>
Recovery code
<<signed in before>>
Known computer
<<the same one each time>>
Master key
If you lose your password and your recovery code, and have no computer that was signed in before, nobody can read your synced data, including us. The steps for each case are in How to reset a forgotten password.
What the server can see
Section titled “What the server can see”The server needs some information to route and store your items, and it is not encrypted:
- Your account email and display name, device names, and which devices are online.
- For each item: whether it is a clipboard entry or a note, its type (text, image, HTML or file), whether it is pinned, its size, when it was created and changed, and which spaces it is in.
- Space names, who is in each space, and who owns it.
It cannot see what an item says, its preview, your group names, your settings, or comments in a space. Those are all encrypted.
<<in the clear>>
server can read<<encrypted on your computer>>
server cannot readLimits
Section titled “Limits”- Your local data is not encrypted. History and notes are stored as plain files on your computer. Encryption protects what leaves it. If other people can get into your computer, use your system’s disk encryption.
- Your device key is only as safe as your system account. Anyone who can sign in to your system account can reach your credential store, and with it your synced data.
- Updates are signed. The app only installs an update whose signature matches the key built into it.
- Google sign-in happens in your own browser, which then hands back to the app through an address that only exists on your computer. The app has no built-in browser window that could see your Google password.