Sahife

Security and disclosure

Last updated 29 September 2026

How your tasks are protected

Your task content is encrypted on your device before it is sent, with a key that only your devices, your Recovery Key and your passkeys can unlock. Our servers store the encrypted data, what is needed to sync it (record identifiers, sizes and times), and your account information, such as your email address and signed-in devices, which we can see. We cannot read your tasks, and we cannot recover them for you.

We are honest about the limits. The web app’s code is delivered by our server, so you are trusting us to deliver it unmodified; a compromised browser or extension can read what you see on screen. The privacy policy lists exactly what the server can see.

Reporting a vulnerability

If you believe you have found a security problem in Sahife, email security@sahife.app. Please include what you found, how to reproduce it and what an attacker could do with it. You don’t need to have a finished exploit.

Safe harbour

We will not take legal action against research done in good faith that follows this policy:

In scope

The Sahife web app and API (sahife.app and its subdomains), the encryption and sync design, and this website. Reports about missing best-practice headers without a real impact, or about outdated browsers, are welcome but usually not treated as vulnerabilities.

Machine-readable contact details: /.well-known/security.txt.