Team encryption keys
Why team encryption exists
In Maskifi, profile data is end-to-end encrypted. When you work in a team, profiles need to be accessible to all authorised members — not just the person who created them. Maskifi handles this automatically using a shared team key.
Team encryption is mandatory. The app cannot open or sync team profiles without it.
What this means in practice
- When you create a profile in a team, it is encrypted so that every authorised team member can open it.
- When a teammate opens a profile you created, their Maskifi client decrypts it locally — the server only ever stores ciphertext.
- Encryption is automatic. You do not need to manage keys manually.
When a new member joins
When you invite someone to a team and they accept, Maskifi sets up their access to team profiles automatically. No action is required from you or the new member beyond completing the normal invite flow. The new member must have completed encryption setup (i.e. have their recovery phrase entered and keys loaded) before they can access team profiles.
When a member is removed
When a member is removed from a team, their access to future team profile data is revoked. Existing profiles remain accessible to remaining members.
Loss of access
If a member loses their recovery phrase and their OS keychain entry is gone, they lose access to their encryption keys and cannot open team profiles. They would need to be re-invited to the team to regain access. See Encryption & recovery phrase for details.