Updated 2026-09-29
Your content is encrypted on your device before it's uploaded, wherever that's possible. To run the service, our servers still need some information in readable form. This page covers every app.
Vault, Notes, Calendar, Lists, Contacts and Budgets are end-to-end encrypted: your content is unreadable to us, though some structure and metadata (below) is not. Polls, Invitations, Registry and Forms are built to be opened by people who don't have an account, so our servers read more for those — each section below says plainly what stays sealed and what doesn't.
Account
We can see: your email address, when you sign in, your devices and sessions, your plan and billing records. We can't see: your master password or any of your keys.
Vault
We can see: how many items you have and their rough type, sizes, timestamps, folder and sharing structure, schedules on time-locked items, and your audit log. We can't see: item names, usernames, passwords, notes, file names or file contents.
Schedules are readable because our server enforces them with its own clock.
Notes
We can see: how your folders nest, sizes, when notes change, how many versions exist, and whether a note is shared. We can't see: note titles, file names, text, tags, links or attachments.
Calendar
We can see: when events start and end, repeat rules, reminder times and calendar colours. We can also read calendars you subscribe to by link, including holiday calendars, because our server fetches them for you. We can't see: titles and details of events in your own calendars, including events imported from files.
Event times are readable so that we can send reminders on time and work out repeating events. Reminder emails contain the time, never the title.
External calendars
We can see: the calendars and events you connect from Google, Microsoft or CalDAV. Our servers fetch and store them, encrypted with our own key rather than yours, so they can stay in sync. We can't see: nothing beyond what's already visible in those external calendars — they were never end-to-end encrypted to begin with.
Teams: Family, Business and Enterprise
When you join a team, you join through the owner's invitation and your account belongs to that team. Everything you store in it is end-to-end encrypted as above, with one addition:
A sealed copy of your account key is kept for the team's owner. Your device seals it to the owner's public key and signs it. Our servers keep it under a second layer of our own, and release it to the owner only if they remove you from the team or close the account. Then everything you stored in the team becomes theirs to review, keep or delete, flagged as coming from you. Until then, the owner can't read your private content.
That release is enforced by our servers, not by encryption alone: someone with full control of our servers, working with the owner, could release a copy early. You're shown this before you join, and Settings → Family (or Organisation) says since when a copy is held. Every release and every time the owner opens a copy is recorded in the audit log.
We can see: that a sealed copy exists, when it was made and whether it's current. We can't see: your key. The inner layer opens only with the owner's private key, which never reaches us.
Accounts for children
On a Family plan, a child's device seals a recovery copy of the child's account key to the owner, so the owner can help them back in. A recovery takes 24 hours, the child is emailed when it starts, and the child then chooses a new master password and Recovery Kit. See Accounts for children.
We can see: that a recovery copy exists, and every recovery started, cancelled or completed. We can't see: the key inside it or the child's content. The copy opens only on the owner's device.
Support
We can see: your account's settings and records, read-only, when our support team looks into a problem. If the account owner turns on support access in Settings → Support, support can also make changes and sign in as the owner until it's turned off. Every grant, revoke and support session is recorded, and you're notified by email. We can't see: anything encrypted with your keys. Support tools have no way to decrypt.
Keep this browser unlocked
We can see: whether you've turned on "Keep this browser unlocked" and for how long. We can't see: the device key that opens it. It's generated in your browser so that it can never be exported — not even by our own code — and it never reaches our servers. We only hold a matching encrypted envelope that the device key can open; without that key, the envelope is useless to us. See Auto-lock and the clipboard.
Lists
We can see: how many lists and items you have and their order, whether each item is done and when it was checked off, due dates, repeat rules and priority (if you set them), who an item is assigned to in a shared list, and the kind of list (groceries, to-do, checklist, packing). We can't see: list and item names, quantities, notes, links, or the suggestions and aisle choices Lists learns from you.
Contacts
We can see: how many contacts and groups you have, their record type, sizes, timestamps and sharing structure. We can't see: names, numbers, addresses, birthdays or notes.
Budgets
We can see: how many accounts, transactions and bills you have, their record type, sizes, timestamps and sharing structure. We can't see: amounts, payees, categories, balances or notes.
Polls
Polls are guest-facing, so our server reads more than it does for the apps above.
We can see: questions and ballots, so we can run the page and tally results. We can't see: who cast which ballot, when a poll is set to anonymous.
Invitations
We can see: RSVP status and headcount, so we can enforce capacity and send reminders. We can't see: meal choices, dietary needs and answers to your own questions — sealed in the guest's browser so only you can read them.
Booking
We can see: your booking page and its bookable types (title, description, durations and questions — public by necessity, since anyone with the link can see them), your working hours, and a guest's name and email for long enough to send them a confirmation. We can't see: the guest's answers to your own questions, which are sealed to your key alone.
Registry
We can see: item details and claims, so the public page can show what's still available. We can't see: your private notes and thank-you drafts.
Forms
We can see: every answer on a Standard-mode form, so routing, search and exports work. Standard or Private, file uploads are not yet encrypted — this is a known gap, not a design choice. We can't see: text answers on a Private-mode form. Those are sealed in the respondent's browser so only your reviewers can read them.
Why this list matters
A copy of our database would reveal what's in the "we can see" lists and nothing more. For the design behind this, and where it stops protecting you, read Zero-knowledge and its limits and the security page.