How end-to-end encrypted direct messages work
Direct messages between two people are encrypted on the sender's device and decrypted on the recipient's. In between — on our servers, in our database, in our backups — they are ciphertext, and we cannot read them.
What that covers
- One-to-one direct messages, including their file attachments
- The message history that syncs to your other approved devices
What it does not cover
- Project channels and comments, which are readable by the workspace and are searchable for that reason
- Task titles, descriptions and documents
- The fact that two people exchanged messages, and when
What it means in practice
- A new device must be approved from an existing one before it can read past messages
- Losing every device means losing that history, unless you saved your recovery phrase
- We cannot produce the contents of a direct message in response to a request, because we do not have them
The full picture — transport encryption, encryption at rest, who at Projectri can reach what, and how long we keep things — is on the security page.
Did this not answer it? Send us a message or write to support@projectri.com — a person reads every one.