mirror of
https://github.com/AppFlowy-IO/AppFlowy.git
synced 2026-03-24 04:46:56 +00:00
[GH-ISSUE #8438] [FR] End-to-End Encrypted Sync & Encrypted Local Storage #3837
Labels
No labels
2024
2025
2026
acct mgmt
AI
automation
bug
calendar
ci
CJK
cloud
code-block
collaboration
copy-paste
database
data migration
data sync
deploy
desktop
develop
develop
documentation
duplicate
editor
editor-plugin
emoji
export
files
flutter-only
follow-up
formula
good first issue for devs
good first issue for experienced devs
grid
hacktoberfest
HACKTOBERFEST-ACCEPTED
help wanted
i18n
icons
images
importer
improvements
infra
install
integrations
IR
kanban board
login
look and joy
mentorship
mobile
mobile
needs design
new feature
new feature
non-coding
notes
notifications
onboarding
organization
P0+
permission
platform-linux
platform-mac
platform-windows
plugins
program
pull-request
Q1 25
Q1 26
Q2 24
Q2 25
Q3 24
Q3 25
Q4 24
Q4 25
react
regression
rust
rust
Rust-only
Rust-only
Rust-starter
Rust-starter
self-hosted
shortcuts
side panel
slash-menu
sync v2
table
tablet
task
tauri
templates
tests
themes
translation
v0.5.6
v0.5.8
v0.5.9
v0.6.0
v0.6.1
v0.6.4
v0.6.7
v0.6.8
v0.7.1
v0.7.4
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.8.0
v0.8.4
v0.8.5
v0.8.9
web
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
AppFlowy-IO/AppFlowy#3837
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @nikunjkumarnakum on GitHub (Jan 18, 2026).
Original GitHub issue: https://github.com/AppFlowy-IO/AppFlowy/issues/8438
Description
I would like AppFlowy to support full data encryption both at rest (on-device storage) and in transit (sync), ensuring that user data is protected end-to-end and remains private across devices.
AppFlowy is positioned as a privacy-focused, local-first productivity tool. However:
Data stored locally on the device is not fully encrypted at rest
Synced data is not end-to-end encrypted
This means that:
Anyone with access to the device’s file system can potentially read user data
Servers involved in sync may have access to unencrypted content
For users handling sensitive personal, professional, or confidential information, this creates a significant privacy and security concern.
Impact
Security & Privacy
Prevents unauthorized access to user data at rest and during sync
Reduces risk in case of server compromise or filesystem exposure
Enables zero-knowledge storage and sync
User Experience
Adds optional authentication flows (passphrase, bio-metric unlock)
Minimal day-to-day impact once unlocked
Clear trade-offs between convenience and security
Product Impact
Strengthens AppFlowy’s positioning as a privacy-first, local-first tool
Differentiates AppFlowy from mainstream note-taking apps
Encourages adoption in security-sensitive communities and organizations
Aligns well with open-source and self-hosted use cases
Additional Context
No response