End-to-End Encryption
TodoTicked offers optional end-to-end encryption (E2EE) for users who want an extra layer of privacy. When enabled, your sensitive content is encrypted on your device before it ever reaches our servers.
What Gets Encrypted
When E2EE is enabled, the following content is encrypted client-side:
- Task titles and descriptions
- Note content
- Journal entries
Metadata such as due dates, project assignments, and sync timestamps remain unencrypted so the app can continue to organize and sync your work.
Setting Up Encryption
- Open Settings in the TodoTicked app
- Go to Security
- Choose Enable End-to-End Encryption
- Create a strong passphrase (this cannot be recovered if lost)
- Confirm your passphrase and complete setup
Your master encryption key is wrapped with a key derived from your passphrase. TodoTicked never stores your passphrase.
Unlocking on New Devices
When you sign in on a new device with E2EE enabled:
- You'll be prompted to enter your encryption passphrase
- Once verified, your encrypted content becomes readable on that device
- Keep your passphrase safe — we cannot reset it without data loss
Changing Your Passphrase
You can change your encryption passphrase from Settings → Security. TodoTicked re-wraps your master key without re-encrypting all content, so the process is fast.
Best Practices
- Use a unique passphrase you don't use elsewhere
- Store your passphrase in a password manager
- Enable E2EE before adding sensitive content
- Unlock encryption on each device you use regularly
Need Help?
If you're locked out of encrypted content, contact support. For security reasons, we cannot recover your passphrase, but we can help you understand your options.