How your data is protected
Your profiles are encrypted on your computer before they are uploaded, with a key that comes from your password — and what the recovery copy behind "Forgot password" means.
On this page
Everything LoginDeck syncs is encrypted on your computer, before it is uploaded. This page says exactly how, and exactly what LoginDeck can and cannot do with what it holds — including the part that makes Forgot password possible.
🔑 How the encryption works#
- Your account has one vault key: 32 random bytes, made on your computer.
- Every record — each profile, each saved proxy, your tag and folder lists, your Flows, each session — is encrypted with that key using AES-256-GCM before it goes anywhere. The server receives a blob it cannot open.
- Each blob is tied to the record it belongs to, so the server can't swap one profile's data into another profile's row without the check failing.
- Your password is put through scrypt on your computer, which produces two halves. One half never leaves the machine and is what unlocks the vault key. The other half is sent as a sign-in token, and the server keeps only a hash of it. Your password is never sent and never stored, in any form that could be turned back into text.
That is why a second computer needs nothing but your email and your password: the password rebuilds the key.
📋 What the server can see#
Some things have to be readable for the product to work at all. In plain text, the server holds:
- your account email
- which folder each record is in — this is how "this member can see Client A and nothing else" is enforced, and the folder name is all the server learns about the profile
- how many records you have, how big they are, and when they changed
- which profile is open on which computer, and the names you gave your computers
- a hashed fingerprint of each computer's hardware, and a hashed form of your internet connection, both used for one free account per person
It does not hold your profile names, your fingerprints, your proxy addresses or passwords, your cookies, or your logins — those are inside the encrypted blobs.
🔓 The recovery copy, and what it means#
Since 16 September 2026 the server also keeps a sealed recovery copy of your vault key. It is sealed with a master key held by LoginDeck's server, and tied to your account so it can't be lifted into somebody else's.
That copy is the whole reason Forgot password works. Without it, a forgotten password would mean every profile on the account was gone for good, and there would be nothing support could do.
Being accurate about the trade-off:
- The recovery copy protects you against forgetting your password.
- It protects your data against a stolen backup, a copied data directory or a leaked storage bucket, because the master key isn't in any of those.
- It does not protect against someone with full control of LoginDeck's server, who would have the master key as well as the sealed copies. So LoginDeck can recover your data, and does not claim it is impossible for it to be read.
- Your password is still not recoverable and still not stored. "We can restore your data" and "we know your password" are different things, and only the first is true.
Treat this like any hosted account
Because a recovery path exists, a strong, unique password still matters — it's what stands between a copy of the server and your proxy credentials. LoginDeck asks for at least 12 characters.
💻 Where the key lives on your computer#
The Key line on your Account page tells you which of three states you're in:
| It says | What that means |
|---|---|
in this computer's keychain | Stored by the operating system — Windows DPAPI, or the Keychain on a Mac. The normal case. |
in a local file — no keychain available | The OS store couldn't be reached, so a local file is used instead. |
in memory only, until you quit | You didn't ask to stay signed in. The key goes when the app does. |
If that OS store disappears — for example when a disk image is restored onto a different machine — you'll be asked to sign in again.
🛡️ Cutting off a computer#
Changing your password re-wraps the vault key, which signs out every other computer signed into the account. That is the way to cut off a laptop you no longer have. The profiles already on that laptop are files on its disk and stay there; what stops is its sync.
See Change your password or email.
ℹ️ Good to know#
- Encrypted vaults are backed up to object storage as well as the server's own disk. Closing your account deletes both copies. See Close your account.
- If a record can't be decrypted on this computer, sync leaves it alone rather than destroying it, and the result line says "N record(s) could not be decrypted and were left alone".
- Cookies are never copied as a file between computers, because the browser encrypts them with a key belonging to that one machine. They are written back through the browser instead. See What syncs between your computers.
❓ Common questions#
Can LoginDeck read my profiles?
Not from the encrypted blobs alone, and not with a stolen backup. But since the server holds a sealed recovery copy of your key, and the key that opens that seal is on LoginDeck's own server, someone with full control of that server could reach your data. We would rather say that than claim otherwise.
What can LoginDeck see without decrypting anything?
Your email, your folder names, how many records you have and how big they are, which computer has a profile open, and your computers' names. Not profile names, fingerprints, proxy credentials or cookies.
What happens if I forget my password?
You can reset it by emailed code and keep every profile. That works because of the recovery copy described above. See Forgot your password.
Is my data encrypted while it sits on the server?
Yes. It arrives encrypted and is stored that way — the server never has a decrypted copy of a record.
Does turning sync off stop all of this?
Turning sync off means nothing is uploaded at all. Your profiles stay on your computer, protected by whatever protects that computer.