Privacy & Encryption
Sysslor uses end-to-end encryption so your family's chore details stay private. This page explains exactly what is protected, what the service can see, and what tradeoffs that creates.
What is encrypted
These data are encrypted on your device before reaching the server. The server stores only encrypted blobs it cannot decrypt:
- Chore type details (names, descriptions, categories you create)
- Chore template display content (instructions, notes, custom fields)
- Occurrence display snapshots (task details shown to family members in the app)
What the service can see
To make scheduling, assignment, sync, and rewards work, the server stores some operational metadata in readable form:
- Community names and membership roles (Admin, Parent, Kid)
- Schedule and recurrence rules (when chores repeat)
- Assignment targets (who a chore is assigned to)
- Occurrence status (claimed, completed, approved)
- Ledger balances and reward transactions
What the service cannot see
The server never has access to:
- Chore names, descriptions, or any custom content you create
- Template instructions, notes, or display details
- Occurrence content shown to family members during their workflow
How encryption keys work
Encryption keys are generated on your device during first-time setup. They are stored exclusively in your device's secure storage — the server never receives them.
To share access with family members, keys are exchanged directly between devices using QR codes. No keys ever pass through the server.
If all devices in a community lose their keys, encrypted content becomes permanently unreadable. There is no backdoor and no recovery mechanism — that is the tradeoff for true privacy.
Recovery and support limitations
Because Sysslor cannot decrypt your family's content, we cannot recover lost chore descriptions, template details, or occurrence content. If you lose access to all devices that hold the community key, that encrypted data is gone.
Operational data (schedules, assignments, balances, memberships) remains intact and can be managed by community admins even if encryption keys are lost.