How We Encrypt Your Data
Saved in this browser.
People Work encrypts your workspace data before storing it on your disk or in the cloud. Your approved clients hold the private keys needed to decrypt it. Our servers don't have those keys, so we can't read what's inside your workspace.
A client is an installation of People Work that accesses your workspace. For example, the macOS app or the Terminal/MCP client your agent uses. Each client has its own key pair, even when several run on the same computer.
Your Encryption Ring
Like Signal, we use end-to-end encryption so our servers cannot read your private content.
Each client's key pair has a public key and a private key. We store the public keys for your approved clients, along with the public counterpart of your recovery key, on our servers. Together, those public keys form your encryption ring. People Work uses age to encrypt your workspace for the members of your ring.
This achieves a simple model: anyone with the shared ring can encrypt, and each approved client can decrypt using its own private key. Your recovery key gives you another way to decrypt the workspace. If anyone came to us asking for your data, we could not provide the decrypted contents of your workspace.
Our servers hold the public ring and your encrypted workspace, but no private keys. Your clients keep their private keys locally, and you keep your secret recovery key.
This is also how it works whether you're on the free or paid plan. Privacy is fundamental to how People Work works.
Client Approval
Let's say you install People Work on a new computer, or set up the Terminal/MCP client to connect your agent. That client has its own key pair and needs your approval to join the ring, even on a device you already use.
Verifying your email during sign-in identifies your account; it does not give the new client access to your workspace. You approve the new client from an existing approved client. Its public key joins the ring, and your workspace is re-encrypted for the new ring.
Once that finishes, the new client can decrypt your workspace with its own private key.
See Approve a New Client for the steps.
Client Revocation
If at any time you lose a device or suspect that a client has been compromised, you can revoke that client's access from your account settings. People Work removes its public key from the ring and re-encrypts your workspace for the remaining members.
The revoked client may still hold its private key, but that key cannot decrypt the workspace encrypted for the new ring.
Once the re-encrypted workspace reaches our servers, we no longer serve workspace versions encrypted for the old ring.
Revocation cannot take back older information the client could already decrypt. If a lost computer has both the People Work app and Terminal/MCP client, revoke each client.
See Revoke a Lost or Untrusted Client for the steps.
Account Recovery
If you lose all your devices, you can't approve a new client from one you already trust. This is where your recovery key comes in. Its public counterpart is already in your ring, so you can use your secret recovery key to decrypt your workspace without an approved client.
Recovery requires both email verification and your recovery key. Your new ring contains the public keys for your new client and a replacement recovery key; the previous clients are revoked.
Save the replacement recovery key somewhere safe. If you lose both your recovery key and access to every approved client, we cannot decrypt your workspace for you.
See Recover Your Workspace for the steps.
Recovery Key Rotation
The recovery key we present to you during onboarding is your way to recover your account. If you suspect someone else has obtained it, you can replace it. People Work replaces its public counterpart in your ring and re-encrypts your workspace for the updated ring. The old key no longer works for recovery.
Your approved clients keep access to your workspace. If you also need to remove a client's access, revoke that client separately.
Save the new recovery key somewhere safe. See Replace Your Recovery Key for the steps.