What end-to-end encryption means in Beeside
In the vault, your devices encrypt every entry before it leaves the phone. Beeside's server only stores scrambled data. Only devices you've approved can read it.
What the server sees
- Not readable: the type, title and content of each entry, so network name, password, username, code and note.
- Visible: which family an entry belongs to, when it was added, and the list of your devices with name and platform.
How it works
- Every entry is encrypted with XChaCha20-Poly1305 (libsodium).
- Each device has its own key pair. The private part stays in the phone's keychain: the iOS Keychain or the Android Keystore.
- There are three areas with their own key: family, kids and private. Kids' devices and the family tablet only get the kids' key.
- When you remove a device, Beeside renews the keys and re-encrypts all entries.
If every device is gone
The recovery key brings back family and kids' entries. It can't restore private entries. Without the key nothing can be read any more, not even by us.