Every time someone asks whether Protecht is end-to-end encrypted, the honest answer needs two sentences, not one. It depends on how the share happens. We’d rather explain both paths than round up to a word that doesn’t quite fit either of them.
Receipts, not promises means telling you exactly what happens to your data, not the version that sounds best. So here’s what actually happens when you share a result, both ways it can go.
When you’re both in the app, nothing touches our servers
If the person you’re sharing with has Protecht open on their phone, the results travel straight from your device to theirs over a direct connection, encrypted the whole way. Our servers are never part of that path. This is the one case where “end-to-end” is the accurate word, and we use it here on purpose.
When they don’t have the app yet
If you’re sharing with someone who doesn’t have Protecht, we fall back to a link. Your results are encrypted on your phone before anything leaves it, and the key that unlocks them is locked with our public key and sent separately. When the link is opened, the encrypted result passes through our server for a moment as part of loading the page, then the server sends back the key and deletes its copy. None of it is ever written to our database. The whole thing is built to work once: the link’s key is single-use and expires within an hour whether or not anyone opens it.
Why we’re not calling this one “end-to-end”
For a few seconds while that link is open, our server technically holds enough to read the result, the encrypted data and the key that unlocks it, even though it never stores either one and never looks. That distinction is small in practice and real on paper, and “end-to-end encrypted” glosses over it. We’d rather say the precise thing than the reassuring thing. No upload path, no PHI in our database, and a key that expires in an hour either way.
See exactly what’s stored
The full breakdown of both sharing paths, in plain language.
We checked the parts you can’t see, too
The claims above are only as good as the infrastructure behind them, so we went back and checked it directly: the request logs and backups that sit underneath the app don’t retain share links either. It’s not a glamorous thing to verify, but it’s the same principle as everything else here. Say what’s actually true, then go check that it still is.
Ready to bring your own?
Download Protecht and share verified status in seconds, not screenshots.
Carry your receipts, not just your word.
Pull your provider-verified results and share a negative status the safe way. Free to download.