← All guides

Privacy

What is end-to-end encryption, in plain English

You’ve probably seen the phrase “end-to-end encrypted” on WhatsApp, on your banking app, maybe on a note-taking tool. It sounds reassuring. But most people have no idea what it actually promises, and a lot of companies use it loosely because it sells.

Here’s the honest version, without the jargon.

The basic idea

Encryption turns readable information into scrambled nonsense that only the right key can unlock. Your customer list, your invoices, your revenue numbers: all of it becomes gibberish unless someone holds the key to turn it back.

The whole game is about who holds that key.

End-to-end encryption means the key lives with you and only you. Your data gets scrambled on your device before it goes anywhere, and it can only be unscrambled on your device (or another one you control). The company running the service never holds the key, so it physically cannot read what you’ve stored. Not “won’t”, not “promises not to”. Can’t.

That’s the “end to end” bit. It’s protected the whole way, from your end to the other end, with no readable stop in the middle.

Three things that all get called “encryption”

This is where the marketing gets slippery. There are three different setups, and they are not the same.

Encrypted in transit

Your data is scrambled while it travels between your device and the company’s servers. This is the padlock in your browser bar (HTTPS). It stops someone snooping on the coffee-shop wifi from reading your traffic.

But once it lands on the company’s servers, it’s often unscrambled again. In transit only protects the journey, not the destination.

Encrypted at rest

Your data is scrambled while it sits on the company’s servers. If someone physically stole the hard drives, they’d get gibberish.

Sounds good, but there’s a catch: the company still holds the key. They decrypt your data whenever they need to, to show it to you, to run analytics, to respond to a legal request. At-rest encryption protects against thieves and hardware theft. It does not protect your data from the company itself.

True end-to-end

The company never holds the key at all. Your data is unreadable to them at every stage. This is the only setup where “we can’t read your data” is literally true rather than a policy.

Most business software gives you the first two. Very few give you the third.

Why “the company can’t read it” actually matters

If a company can read your data, then so can:

  • Any employee with the right access, on a bad day
  • Anyone who breaches their servers
  • Any government or court that compels them to hand it over
  • Any future owner if the company gets bought or goes bust
  • Any analytics or “AI training” pipeline they quietly bolt on later

“We take your privacy seriously” is a promise. It can change with a new privacy policy, a new CEO, or a data breach nobody spotted for six months. True end-to-end encryption removes the need to trust the promise, because the capability to read your data simply doesn’t exist.

What this means for business tools

Consumer chat apps are one thing. But think about what your business software holds: your customers’ names and contact details, your pricing, your margins, your bank figures, unpaid invoices, supplier terms. That’s not just your privacy on the line, it’s your customers’ too, and under UK GDPR you’re responsible for keeping it safe.

A tool that can’t read your data can’t leak it in a breach, can’t sell it, and can’t be forced to reveal it, because there’s nothing readable to reveal. That’s a genuinely different security posture from “we encrypt at rest and pinky-promise”.

This is the whole point of : it’s genuinely end-to-end encrypted, so even we can’t read your business data. Your customers, your numbers and your invoices stay yours.

The honest trade-off

End-to-end encryption isn’t magic, and it has one real cost worth understanding: password recovery.

If the company can’t read your data, they also can’t reset your access to it. With a normal service, “forgot password” works because they hold the keys. With true end-to-end encryption, if you lose your password and any recovery method you set up, your data can be genuinely unrecoverable. Not even the company can get it back.

Good tools soften this with recovery keys, trusted devices or backup codes. But the underlying tension is real: the same thing that stops the company reading your data also stops them rescuing you if you lose your key.

So the practical advice is simple. When a service is truly end-to-end encrypted, treat your password and recovery codes like the keys to a safe. Write the recovery key down, store it somewhere sensible, and don’t lose it.

That small bit of responsibility is the price of your data actually being yours. For anything holding your business and your customers, it’s a price worth paying.