Concepts · Encryption

Your data, locked to you.

Open Lab's end-to-end encryption keeps your participants' responses readable only by you — and the people you choose. Not even Open Lab can see inside. Here's how it works, in plain terms.

Readable byOnly you & the people
you choose
Open Lab seesScrambled characters —
never the contents
Your keyMade in your browser —
never sent to us
Your one backupA recovery code —
save it somewhere safe

What "end-to-end encryption" means here

We hold the box. Only you hold the key.

When encryption is on, your study responses are scrambled the moment they're collected and can only be unscrambled with your key. Open Lab stores the data for you — but to us, and to anyone without your key, it looks like meaningless characters.

Open Lab holds

The locked box

We store your data and keep it safe, backed up, and available — but it stays locked. We can't open it.

You hold

The only key

Your key lives with you. It's the one thing that turns those scrambled characters back into readable responses.

Your vault and your key

Turning on encryption sets up your vault.

Think of your vault as a personal keyring. It holds your keys, you unlock it when you sign in, and it does the unscrambling for you behind the scenes.

Your vault

Your personal keyring

You unlock your vault when you sign in. How you unlock it depends on how you sign in to Open Lab:

  • Sign in with a password? You unlock your vault with your account password.The usual setup
  • Sign in with Google or ORCID? Since you don't have an Open Lab password, you set a separate encryption passphrase instead.For accounts without a password
Most important · save this

Your recovery code

When you set up encryption, we show you a one-time recovery code. It's your backup key — the way back in if you ever forget your password. We show it once, and we never keep a copy.

Save it somewhere safe

A password manager is ideal. Treat it like a spare key to your home.

It gets you back in

Forgot your password? Your recovery code restores access to your encrypted data.

If you lose both your password and your recovery code, the data cannot be recovered — by anyone, including Open Lab. There's no back door. That's the trade-off for true privacy.

How a response gets protected

From a participant's answer to your locked dataset.

Four steps, all automatic. You and your participants don't do anything differently — it happens behind the scenes.

Step 1

Participant submits

A participant sends in their responses, exactly as they always would.

Step 2

Locked right away

The responses are locked with a one-time key as they're collected.

Step 3

Sealed to your key

That one-time key is sealed so only your study's key can open it.

Step 4

Stored scrambled

Everything is stored scrambled. Open your data and your unlocked vault un-scrambles it — no extra steps.

Invisible by design

You don't manage keys or paste codes to read your data. Once your vault is unlocked for the session, everything you're allowed to see just reads normally.

Every study has its own lock

One key per study — not one key for everything.

Each encrypted study gets its own key. So you can share one study with a collaborator without giving them access to any of your other studies.

Three studies, three separate locks. Hand someone the key to one and the others stay shut. Sharing one study never means sharing all of them.

Sharing with your team

Many people. Their own keys. No shared password.

You can let project collaborators read an encrypted study's data — with no key files to email. Each person unlocks it with their own vault.

You
Owner · own key
Collaborator
Granted automatically
One encrypted studySame lock for all
Teammate
Shared in one click
New teammate
Hasn't set up encryption yet
Collaborators with encryption set up are granted access automaticallyEach unlocks with their own vault — never your passwordSee who can decrypt in Settings → EncryptionRevoke access at any time
Honest note

Revoking access stops future access. If someone was already viewing the data, their browser may keep it until they reload — like any data they've already seen.

What Open Lab can and can't see

Clear about where the line sits.

Encryption hides the contents of your responses. To run the service, we still see some basic information about your study — and we'd rather say so plainly.

We can't seeEncrypted & private

  • The contents of your encrypted responses — to us they're meaningless scrambled characters.

This is the whole point of turning encryption on.

We can seeNeeded to run the service

  • How many responses came in, and when.
  • Which participants took part.
  • Your study's settings.

This is true whether or not encryption is on.

Turning it on

Three steps, set up once.

You set up your vault one time for your account, then switch encryption on for any study you like.

1

Set up your vault

Create your vault and save your recovery code somewhere safe.

Settings → Security
2

Choose account encryption

Open a study's encryption settings and pick Account encryption.

Study → Settings → Encryption
3

You're done

From then on, new responses for that study are encrypted — automatically.

Nothing else to do
Good to know

Data collected before you turned encryption on keeps the protection it had when it was saved.

Advanced · optional

Bring your own key

Prefer to hold your own key file? There's an advanced option to encrypt a study with a key you download and manage yourself. It works without a vault — but there's no recovery code, so if you lose that key file, the data can't be recovered. Most researchers should use the standard option above.

Short FAQ

Quick answers.

?Can Open Lab recover my data if I lose everything?
No. We never hold your key — that's what keeps it private. Your recovery code is the backup; keep it safe.
?Do my participants need to do anything?
No. Encryption happens automatically — there's nothing for your participants to set up or notice.
?Will encryption slow things down or change how I collect data?
No — it's invisible to you and your participants in normal use. You collect and read data exactly as you do today.
?What happens to encrypted data if I delete a collaborator or my account?
Removing a collaborator removes their access. Deleting your account deletes your studies and their keys.
?Can I switch a study to encrypted after I've started?
Yes — new data is encrypted from then on. Data collected earlier keeps the protection it had when it was saved.

Related concepts

Open Lab Onlineresearch.open-lab.onlineConcepts · How encryption works