End-to-end encryption, explained for families
The Vault For Us team · 7 October 2026 · 4 min read
"End-to-end encrypted" is on a lot of boxes now. Here's what it actually means, what it costs, and why the cost is the point — written for the family member who did not volunteer to be the IT department.
Two kinds of locked
Almost every service you use encrypts your data. The question is who holds the key.
Most services work like a bank locker where the bank keeps a master key. Your files are locked to outsiders, but the company can open them — to show you your data on a new phone, to reset your password, sometimes to scan or index your files. You're trusting a promise: *we can look, but we won't.*
End-to-end encryption is a different arrangement. Your data is locked on your own device, before it's sent, with keys only your devices hold. The company stores sealed boxes it cannot open — not "chooses not to", cannot, the way your neighbour cannot read a letter that was never in their house. When we say even we can't see your documents, that's the mechanism, not a policy.
What that protects your family from
Quite a lot, it turns out:
- A breach at the company. An attacker who steals the server's contents steals sealed boxes. A bad day for the company; your documents stay documents only your family can read.
- The company itself. No employee can browse your files — not a curious one, not a tricked one, not one with a grudge.
- Pressure on the company. A company that cannot read your data cannot be talked, tricked, or compelled into handing over the contents. It can only hand over the boxes.
What it doesn't protect you from
Honesty requires this list too. E2EE does nothing about your own device being compromised — if someone can unlock your phone, they see what you see. And some information necessarily stays readable to the service so it can function at all: that your account exists, roughly how much you store, the titles and dates that power search and reminders. Any provider who claims otherwise is rounding up. We publish our exact list on the trust centre.
The part nobody advertises: recovery
Here's the consequence that matters most for a family, and the one glossy explanations skip.
"Forgot password" links work because the company can get into your data and re-attach it to a new password. That's the master key in action. A company that genuinely can't read your data also can't reset your way back into it. The two abilities are the same ability.
So with E2EE, recovery has to be arranged in advance, on your side. In Vault For Us that takes two forms. Your Recovery Kit — a code generated in your browser, written on paper, kept somewhere you'd keep a house key — can always unlock your data and set a new master password. And family itself helps: each member signs in from their own devices, so one person forgetting a password is an inconvenience rather than a catastrophe, and a member who can still sign in can approve a locked-out member's recovery.
What there isn't, ever, is a support ticket that gets your data back without the code. We can't offer that mercy, because the ability to offer it is exactly the ability we built the product not to have.
Is the trade worth it?
Genuinely, it depends on the data. For a playlist? Convenience wins; take the password reset. For passports, medical records, property papers and the family's credentials — the things that would matter most in the wrong hands — we think the answer is different, and that the mild ceremony of keeping one piece of paper safe is a fair price for "no one else can ever read this".
What we'd ask of any provider, us included: be told which kind of locked you're getting. Both can be legitimate choices. Only one of them should be describing itself as end-to-end encrypted.
The deeper technical version — the key hierarchy, the threat model — is on the security page, written to be checked, not admired.
The full technical version
How the encryption worksRelated reading
- The family password notebook is a single point of failureWhy the shared notebook of passwords fails exactly when your family needs it most — and a safer pattern for couples and families that takes one weekend.
- Could you find it in five minutes?The documents every family should be able to find fast — a practical checklist by category, how long to keep each, and an organising method that survives real life.
- If something happens to you, who can find anything?Digital legacy for ordinary families: what gets lost when one person holds all the knowledge, who needs access to what, and why a written handbook beats scattered memory.