What is zero knowledge architecture?
In short:
Zero knowledge describes a service that stores your encrypted data but holds none of the keys to it. We run the machines. What is inside them, we have no way of knowing.
🔐 The storage locker

Think of a secure storage building.
- The ordinary cloud. You rent a locker and the manager keeps a spare key, in case you lose yours. Which means he can open it whenever he likes, look inside, or let somebody else look.
- Zero knowledge. You rent a locker and bring your own padlock. Nobody else has that key. The manager lets you into the building and cannot open your locker. Asked what is inside, he can answer truthfully: no idea.
⚙️ How it works
In an ordinary app you send your password to the server, the server checks it and unlocks your data for you.
Here the two jobs are kept apart:
- Proving who you are. Part of your password is scrambled and sent to the server, purely so it knows to let you in.
- Opening the notes. The other part stays on your device and produces the encryption key, which never leaves.

The server keeps the lock. You keep the key. It knows you have data. It has no way to turn that data into readable text.
⚖️ Why it is worth the trouble
This is not a slogan. It changes what is possible.
- A court order. If an agency demands your data, we can hand over encrypted nonsense and nothing else. Nobody can be compelled to decrypt what they cannot read.
- A breach. If our servers are broken into, the attacker carries away noise.
- Us. You do not have to believe that everyone who works here is honest. You only have to believe the mathematics.
🛡️ What that means in TaskNote
Your privacy here does not rest on our good intentions. It rests on your key.
When you sign up, the keys are generated in your browser. What we store is encrypted blocks of notes, tasks and labels. We do not hold your password, and we do not hold your key.
❓ Questions people ask
If I forget my password, why can you not reset it?
Because we never knew it. There is no administrator's back door in a system built this way. Lose the password and the recovery key together, and the notes are gone.
Does it cover metadata too?
Mostly, not entirely. Note contents and titles are unreadable to us. The server still has to know the plain operational facts to work at all, along the lines of this account holds fifty encrypted files and last synced this morning. We keep that to the minimum the service needs.
Can notes still be shared?
Yes, with more work behind the scenes. Your device encrypts the note's key for the person receiving it, using their public key. The server passes the parcel along without ever being able to open it.