End-to-end encrypted sync means your data is protected even from us.
Data is encrypted before it ever leaves your device. The encryption happens locally.
Our servers only see random-looking encrypted data. We cannot read your content.
Your encryption key is derived from your passphrase. We never see it.
Attackers would only get encrypted blobs. Without your passphrase, it's useless.
| Service | Trust Required | Can Provider Read Data? |
|---|---|---|
| Google Drive | Trust Google completely | Yes |
| Dropbox | Trust Dropbox completely | Yes |
| iCloud | Trust Apple completely | Yes |
| Onelist | Trust no one (E2EE) | No - Impossible |
Your Device Onelist Cloud Your Other Device
──────────── ───────────── ─────────────────
1. Write entry
2. Encrypt with your key
3. Upload blob ──────────────► 4. Store blob ─────────────► 5. Download blob
(cannot read) 6. Decrypt with key
7. Read entry
┌─────────────────────────────────┐
│ │
│ 🔒 Encrypted in transit │
│ 🔒 Encrypted at rest │
│ 🔑 Only you have the key │
│ │
└─────────────────────────────────┘
Direct device-to-device sync via LAN or WAN. Uses vector clocks for conflict resolution. WAN discovery service included free.
Always-available E2EE sync. Works even when devices are offline at different times.
Run your own sync server. Full control over your infrastructure.