Skip to content
Pricing Download Open app
DocsAccounts & SecurityEnd-to-End Encryption

Accounts & Security

End-to-End Encryption Both

TapTidy includes optional client-side End-to-End Encryption (E2EE) for household data on Web and Android. When enabled, your household tasks, descriptions, and checklists are encrypted directly on your device before synchronization. The TapTidy server receives only ciphertext and cannot read your data.

Enabling E2EE

Household owners can enable E2EE under Settings → Privacy & security → End-to-End Encryption on Android or Settings → Privacy & security → Encryption on Web.

1. Authoring Device
Generates random AES-256 content key, HPKE-wrapped to trusted devices
2. Server
Relays encrypted payload envelopes without access to keys
3. Trusted Devices
Unwraps content key with device private key and decrypts locally

Device Keys & Revocation

Each registered browser or phone generates a unique cryptographic device keypair. You can view all active trusted devices in Encryption settings. Revoking a lost or retired device automatically triggers key rotation so the removed device cannot decrypt future changes.

Recovery Passphrase & Safety

Recovery Requirement: Because TapTidy servers hold no decryption keys, recovering encrypted data requires maintaining at least one active trusted device or saving the 12+ character recovery passphrase generated during initial activation. Always keep a secure record of your recovery passphrase.

Child PIN Compatibility

For household child members who log in via PIN codes on shared family devices, owners can select PIN Compatibility Mode. In this mode, tasks assigned to child members remain readable by child devices while adult-only household tasks stay fully encrypted.

Pro Feature: End-to-End Encryption is available with a TapTidy Pro subscription.