How Sysslor protects your family

Privacy & Encryption

Sysslor uses end-to-end encryption so your family's chore details stay private. This page explains exactly what is protected, what the service can see, and what tradeoffs that creates.

What is encrypted

These data are encrypted on your device before reaching the server. The server stores only encrypted blobs it cannot decrypt:

  • Chore type details (names, descriptions, categories you create)
  • Chore template display content (instructions, notes, custom fields)
  • Occurrence display snapshots (task details shown to family members in the app)

What the service can see

To make scheduling, assignment, sync, and rewards work, the server stores some operational metadata in readable form:

  • Community names and membership roles (Admin, Parent, Kid)
  • Schedule and recurrence rules (when chores repeat)
  • Assignment targets (who a chore is assigned to)
  • Occurrence status (claimed, completed, approved)
  • Ledger balances and reward transactions

What the service cannot see

The server never has access to:

  • Chore names, descriptions, or any custom content you create
  • Template instructions, notes, or display details
  • Occurrence content shown to family members during their workflow

How encryption keys work

Encryption keys are generated on your device during first-time setup. They are stored exclusively in your device's secure storage — the server never receives them.

To share access with family members, keys are exchanged directly between devices using QR codes. No keys ever pass through the server.

If all devices in a community lose their keys, encrypted content becomes permanently unreadable. There is no backdoor and no recovery mechanism — that is the tradeoff for true privacy.

Recovery and support limitations

Because Sysslor cannot decrypt your family's content, we cannot recover lost chore descriptions, template details, or occurrence content. If you lose access to all devices that hold the community key, that encrypted data is gone.

Operational data (schedules, assignments, balances, memberships) remains intact and can be managed by community admins even if encryption keys are lost.