Sync Deck 0.2.0 — end-to-end encrypted vaults
- New vaults use E2EE by default with AES-256-GCM and independently derived content, metadata, and path-index keys.
- Encrypts file contents, filenames, folder paths, protected metadata, and collaboration identifiers before upload.
- Adds single-use encrypted
SD1invites and user-heldSDK1recovery keys. - Adds multi-device unlock, recovery-key export, and owner-controlled key rotation.
- Adds verified, crash-resumable migration for Legacy vaults.
- Prevents older clients from opening encrypted manifests unsafely.
- Updates the Terms, privacy disclosure, and detailed E2EE threat model.
Important: keep the recovery key safe. Sync Deck cannot recover a vault if every authorized device and recovery copy loses the key. Account, membership, size, timing, and network metadata remain visible to the service.
Install or update main.js, manifest.json, and styles.css together.