What end-to-end encryption means in Beeside

Vault3 min read · updated October 2026

In the vault, your devices encrypt every entry before it leaves the phone. Beeside's server only stores scrambled data. Only devices you've approved can read it.

What the server sees

  • Not readable: the type, title and content of each entry, so network name, password, username, code and note.
  • Visible: which family an entry belongs to, when it was added, and the list of your devices with name and platform.

How it works

  • Every entry is encrypted with XChaCha20-Poly1305 (libsodium).
  • Each device has its own key pair. The private part stays in the phone's keychain: the iOS Keychain or the Android Keystore.
  • There are three areas with their own key: family, kids and private. Kids' devices and the family tablet only get the kids' key.
  • When you remove a device, Beeside renews the keys and re-encrypts all entries.

If every device is gone

The recovery key brings back family and kids' entries. It can't restore private entries. Without the key nothing can be read any more, not even by us.

Did this help?

If not, write to us and we'll help.