M
Give Moltbot superpowered memory with one command
Install Now

Security Without Compromise

How we protect your data with end-to-end encryption and zero-knowledge architecture.

Our Security Philosophy

"Can't be evil" vs "Won't be evil"

We designed Onelist so that we cannot access your data, even if we wanted to. Even under legal compulsion, we have nothing to give because we cannot decrypt your data.

Encryption Details

Encryption Algorithm

AlgorithmAES-256-GCM
Key Length256 bits
ModeGalois/Counter

Key Derivation

FunctionArgon2id
Memory64 MB
Iterations3

Transport Security

ProtocolTLS 1.3
CertificateLet's Encrypt
HSTSEnabled

At-Rest Security

StorageEncrypted blobs
ProviderCloudflare R2
RedundancyOptional B2

What We Can and Cannot See

Data Visible to Onelist?
Email addressYes (for account)
Account metadataYes (billing, usage)
Entry contentNo - Encrypted
Entry titlesNo - Encrypted
Search queriesNo - Local only
File contentsNo - Encrypted
TagsNo - Encrypted

Recovery & Key Management

Passphrase

Your passphrase derives your encryption key using Argon2id. We recommend a randomly generated 5-word passphrase for maximum security.

Recovery Key

During setup, you receive a recovery key. Store this safely (photo, print, secure note). It can restore access if you forget your passphrase.

No Backdoors

If you lose both your passphrase and recovery key, your data cannot be recovered. This is by design. We have no master key.

Open Source Transparency

All Onelist code is open source. You can audit our encryption implementation yourself. We believe transparency builds trust.