Skip to content
TapTidy
E2EE on Pro
HomeFeaturesEncryption

Feature

Encrypt on your device first. Then the server stores only ciphertext.

With end-to-end encryption (E2EE), TapTidy Pro turns a task's title and description into ciphertext on your device before upload, on web and Android. You no longer have to trust our servers with those fields. The protection is technical, not only a policy.

AES-256-GCM On-device keys Private share support

Opt-in on TapTidy Pro, on web and Android. Covers task title and description. Approve each new device through Trusted Devices (Beta). On web, turn it on under Settings → Privacy & security → Encryption.

Diagram showing a task title and description encrypted on your device and stored as ciphertext on the server.
The important boundary is simple: plaintext lives on your device, ciphertext lives on the server.
Title & description encrypted before upload (web and Android) Key rotation support No task data used to train AI

Encrypt locally

A task's title and description are encrypted on your device, on web and Android, before the data is sent upstream. Other fields — dates, tags, notes — are not encrypted yet.

Store ciphertext

For those encrypted fields the hosted service stores ciphertext, not readable text. That narrows what the server can inspect for your task title and description.

Decrypt on your device

The key is generated and held on your device. Additional devices you approve receive the key wrapped to them through Trusted Devices (Beta), so your encrypted fields decrypt on each approved device.

What changes

The main value is not the algorithm name. It is what the server can no longer read.

End-to-end encryption matters because it changes what has to be trusted operationally. It does not eliminate every security concern, but it does remove routine server-side visibility into task contents.

What TapTidy can still know

  • Your account identity and subscription state
  • Device registration and sync timing
  • Operational metadata needed to run the service

What it cannot read under E2EE

  • Your task title and description (when encryption is enabled)
  • Shared private-link payloads (the key stays in the link fragment)

Other task fields — due dates, tags, notes — are stored server-side and are not covered by task encryption yet.

Plan fit

Where the stronger privacy protection begins.

The Free tier gives you the standard hosted experience. Pro is where the stronger task-content boundary starts.

Encryption capabilities by plan
Capability Free Pro
End-to-end task encryption (web and Android; title & description; multi-device in Beta) Not included Included
Private share with encrypted payloads Not included Included
Telemetry off by default You can turn telemetry off Telemetry is off by default

Encryption FAQ

The questions that matter after the headline claim.

Most skepticism here is healthy. These are the practical boundaries people usually want explained in plain language.

TapTidy Pro can end-to-end encrypt a task's title and description, on web and Android. The data is encrypted on your device with AES-256-GCM before upload. The server stores only ciphertext for those fields. Encryption is opt-in. Approve each new device through Trusted Devices (Beta). Other fields (dates, tags, notes) are not encrypted yet.

The server does not need to read your tasks. So it should not store them in readable form by default.

TapTidy Pro is built for people who want that boundary to be stronger than a policy statement.

See Pro privacy features Security page covers the broader model around storage, telemetry, and trust boundaries.