Security & Privacy

End-to-End Encryption (E2EE) Complete Guide

Learn how to enable and manage End-to-End Encryption on all your devices. Your files are encrypted on your device and only you can decrypt them - not even Felicloud can access them.

What is End-to-End Encryption?

End-to-End Encryption (E2EE) is a security feature where your files are encrypted on your device before being uploaded to Felicloud. The encryption keys never leave your devices, which means:

  • Only you can read your encrypted files
  • Felicloud cannot access the content of your encrypted files
  • No one else can decrypt your files without your recovery phrase

How E2EE works:

  1. You enable encryption on an empty folder
  2. A unique encryption key is generated on your device
  3. You receive a 12-word recovery phrase (mnemonic) - save it securely!
  4. Files added to this folder are encrypted before upload
  5. Only devices with your recovery phrase can decrypt the files

Before You Start

WarningCritical information before enabling E2EE:

⚠️ Requirements

  • • E2EE can only be enabled on empty folders
  • • You must use the desktop or mobile app (not the browser)
  • • You must save your 12-word recovery phrase

⚠️ If you lose your recovery phrase

  • • Your encrypted files will be permanently lost
  • • Felicloud cannot recover your files
  • • There is no reset option

Enable E2EE on Windows

Follow these steps to enable End-to-End Encryption using the Felicloud desktop app on Windows:

1. Download and install the Felicloud app

If you haven't already, download the Felicloud desktop app from nextcloud.com/install and install it on your Windows computer.

2. Connect to your Felicloud account

Open the app and log in with your Felicloud credentials (cloud.felicloud.com).

3. Create an empty folder

In your Felicloud sync folder, create a new empty folder that you want to encrypt. For example: Private Documents

4. Enable encryption on the folder

  1. Right-click on the empty folder
  2. Select "Encrypt" from the context menu
  3. The app will generate your encryption keys

5. Save your recovery phrase

A window will appear with your 12-word recovery phrase (mnemonic).

WarningWrite down these 12 words on paper and store them in a safe place!You will need them to access your encrypted files on other devices. If you lose this phrase, your encrypted files will be permanently inaccessible.

6. Start using your encrypted folder

Move or copy files into this folder. They will be automatically encrypted before being uploaded to Felicloud.

Enable E2EE on Mac

Follow these steps to enable End-to-End Encryption using the Felicloud desktop app on macOS:

1. Download and install the Felicloud app

Download the Felicloud desktop app from nextcloud.com/install or from the Mac App Store.

2. Connect to your Felicloud account

Open the app and log in with your Felicloud credentials (cloud.felicloud.com).

3. Create an empty folder

In your Felicloud sync folder (usually in ~/Nextcloud), create a new empty folder.

4. Enable encryption on the folder

  1. Right-click (or Control+click) on the empty folder
  2. Select "Encrypt" from the menu
  3. The app will generate your encryption keys

5. Save your recovery phrase

You'll see a popup with your 12-word recovery phrase.

WarningWrite down these 12 words and keep them safe! This is the only way to recover access to your encrypted files.

6. Start using encryption

Your encrypted folder is ready! Any files you add will be encrypted automatically.

Enable E2EE on Android

Follow these steps to enable End-to-End Encryption on your Android device:

1. Install the Nextcloud app

Download the Nextcloud app from the Google Play Store or F-Droid.

2. Connect to Felicloud

Open the app and add your Felicloud account. Enter cloud.felicloud.com as the server address.

3. Create an empty folder

Tap the + button and create a new empty folder that you want to encrypt.

4. Enable encryption

  1. Long-press on the empty folder
  2. Tap the three dots menu (⋮)
  3. Select "Set as encrypted"

5. Save your mnemonic

The app will display your 12-word recovery phrase.

WarningScreenshot or write down these words immediately! Store them somewhere safe and separate from your phone.

6. Access encrypted files

You can now upload files to this folder. They will be encrypted on your device before being uploaded.

Enable E2EE on iPhone/iPad

Follow these steps to enable End-to-End Encryption on your iOS device:

1. Install the Nextcloud app

Download the Nextcloud app from the App Store.

2. Connect to Felicloud

Open the app and add your Felicloud account with server address cloud.felicloud.com.

3. Create an empty folder

Tap the + button and create a new empty folder.

4. Enable encryption

  1. Tap and hold on the empty folder
  2. Tap "More"
  3. Select "Set as encrypted"

5. Save your recovery phrase

Your 12-word mnemonic will be displayed. This is crucial for accessing your files on other devices.

WarningSave these 12 words securely! Consider using a password manager or writing them on paper stored in a safe.

Access Encrypted Files on a New Device

To access your encrypted files on a new device, you'll need to enter your 12-word recovery phrase:

On Desktop (Windows/Mac):

  1. Install and connect the Felicloud desktop app
  2. The app will detect encrypted folders
  3. Click on "Enter mnemonic" when prompted
  4. Enter your 12 words in the correct order
  5. Your encrypted files will now be accessible

On Mobile (Android/iOS):

  1. Install and connect the Nextcloud app
  2. Navigate to an encrypted folder
  3. You'll be prompted to enter your mnemonic
  4. Enter all 12 words
  5. Tap "Confirm"

Accessing E2EE Files in the Browser

WarningBrowser access to encrypted files has significant limitations.

While you can view encrypted files in the web browser, there are important restrictions:

❌ Not possible in browser

  • • Enable encryption on a folder
  • • Add new files to encrypted folders
  • • Edit encrypted files
  • • Delete encrypted files
  • • Share encrypted files
  • • View your recovery phrase

✅ Possible in browser

  • • View encrypted files (read-only)
  • • Download encrypted files
  • • Navigate encrypted folders

To enable browser access:

  1. Go to cloud.felicloud.com → Settings → Security
  2. Find the "End-to-end Encryption" section
  3. Click "Enable E2E encryption in web browser"
  4. Enter your 12-word recovery phrase
Good to knowBrowser-based E2EE is less secure than using the desktop/mobile apps because your encryption keys must be temporarily processed by the server. For maximum security, use the desktop or mobile apps.

Your Recovery Phrase (Mnemonic)

The 12-word recovery phrase (also called "mnemonic") is the master key to all your encrypted files. Without it, your encrypted files cannot be accessed on new devices or recovered.

🚨 CRITICAL: Protect Your Recovery Phrase

  • • Write it down on paper - don't just save it digitally
  • • Store in multiple secure locations (safe, safety deposit box)
  • • Never share it with anyone
  • • Never send it via email, chat, or any digital means
  • • Felicloud support will never ask for your recovery phrase

How to view your existing recovery phrase:

You can only view your mnemonic from the desktop or mobile app:

  • Desktop: Settings → Security → End-to-end encryption → Show mnemonic
  • Android: Settings → Security → Show mnemonic
  • iOS: Settings → Security → Show mnemonic

Note: The mnemonic cannot be viewed from the web browser.

E2EE Limitations

End-to-End Encryption provides maximum security, but comes with some trade-offs:

📁 Empty folders only

You can only enable encryption on empty folders. Move files out first, enable encryption, then move them back.

🔗 No link sharing

Encrypted files cannot be shared via public links. Recipients would need your encryption keys to decrypt them.

🔍 No server-side search

Felicloud cannot search the content of encrypted files since the server can't read them. File names are also encrypted.

👁️ No web previews

Thumbnails and previews for images/documents won't work in the browser for encrypted files.

⏱️ Slightly slower sync

Encryption/decryption adds some processing time when uploading or downloading files.

Frequently Asked Questions

Can I encrypt existing folders with files?

No. You must create a new empty folder, enable encryption on it, then move your files into it. This is a security requirement of the Nextcloud E2EE implementation.

I lost my recovery phrase. Can Felicloud recover my files?

No. This is impossible by design. End-to-end encryption means only you have the keys. Felicloud cannot decrypt your files under any circumstances. This is why saving your recovery phrase is critical.

Can I share encrypted files with other Felicloud users?

Currently, encrypted folders cannot be shared with other users. If you need to share files, store them in a regular (non-encrypted) folder and use Felicloud's standard sharing features.

Can I disable encryption on a folder?

No. Once a folder is encrypted, it stays encrypted. To have unencrypted copies, download the files using the desktop/mobile app, then upload them to a regular folder.

Is my data safe without E2EE?

Yes! All Felicloud data is encrypted in transit (TLS 1.3) and at rest (AES-256) on our servers. E2EE adds an extra layer where even Felicloud cannot access your files. It's recommended for highly sensitive documents like medical records, legal documents, or financial data.

Why can't I enable E2EE from the web browser?

For security reasons, encryption keys must be generated on your local device (desktop/mobile app). The web browser can only read encrypted files after you've set up E2EE using an app.

Quick Reference

FeatureDesktopMobileBrowser
Enable E2EE on folder✅✅❌
View recovery phrase✅✅❌
Read encrypted files✅✅✅
Add files to encrypted folder✅✅❌
Edit/delete encrypted files✅✅❌
Download encrypted files✅✅✅

Still Need Help?

Our support team is available to assist you with any questions or issues you may have.