End-to-end encryption (E2EE) is a method of protecting data in which content is encrypted on the sender's device and can be decrypted only on the devices of the intended recipients. The decryption keys exist only on those devices. Every server in between — the one that relays messages, stores files or syncs devices — handles ciphertext it has no key for, so it cannot read the content.
The "ends" in the name are the people, or more precisely their devices. The provider is in the middle, and that is the whole point: end-to-end encryption is the one kind of encryption that protects your data from the service that carries it, not only from outsiders.
Most E2EE systems combine two ideas. Each device has a key pair: a public key that others use to encrypt data for it, and a private key that never leaves the device. The parties then use those keys to agree on shared keys that encrypt the actual content, often rotated per message or per session so that one leaked key does not expose everything.
Well-known implementations:
The word "encrypted" appears on almost every security page, and most of the time it means something narrower.
| Term | Who holds the key | Can the provider read the content? |
|---|---|---|
| Encryption in transit (TLS) | The provider's servers | Yes, once it arrives |
| Encryption at rest | The provider | Yes, whenever its systems need it |
| End-to-end encryption | Only the participants' devices | No |
Encryption in transit protects data on the way between your device and the server. Encryption at rest protects it on the server's disks from someone who steals the hardware. Both are useful, and both leave the provider able to read everything, because the provider decrypts the data to show it, search it or process it. For meeting notes specifically, we walk through what that means in are AI meeting notes encrypted.
A real end-to-end design has visible consequences. You can test for them without reading any cryptography:
E2EE also depends on law and policy around it. Since February 2025, Apple has not offered Advanced Data Protection to new users in the United Kingdom after a government demand under the Investigatory Powers Act, and Apple's legal challenge was still pending when this entry was written on 28 September 2026.
In Speak-Y, audio is deleted after processing, transcripts stay on your device by default, and sync between your own devices is end-to-end encrypted. Sharing into a team knowledge base uses the same model: channel keys exist only on the team's devices, and removing a member rotates them. The full data handling is described in the privacy policy.
For how this plays out when a team shares meeting notes — who can read what, and what changes when someone leaves — see the team knowledge base guide.
End-to-end encryption (E2EE) is a way of protecting data so that it is encrypted on the sender's device and can only be decrypted on the devices of the intended recipients. The keys never leave those devices, so the service that stores or relays the data sees only ciphertext and cannot read the content, even if it wants to.
No. Encryption at rest protects data on the provider's disks with a key the provider holds, so the provider can decrypt the data whenever its systems need it. End-to-end encryption means the provider never has the key at all. A service can truthfully say "encrypted" about both, which is why the word alone tells you little.
Ask whether support can restore your data if you forget your password. If it can, the provider holds a key and the content is not end-to-end encrypted. Other signs of a real E2EE design: no server-side search over your content, no way to read it in a browser without key material, and a way to compare keys with the other party, like Signal's safety numbers.
It does not hide metadata such as who communicated with whom, when and how much. It does not protect content on a compromised or unlocked device, where the plaintext is available. And it does not stop a legitimate recipient from copying, forwarding or screenshotting what they received.
Because the machine that transcribes or summarizes content has to read it in plaintext. Zoom's end-to-end encrypted meetings, for example, disable Zoom's AI features, cloud recording and live transcription, since the meeting keys are generated by participants' machines rather than Zoom's servers. AI and E2EE can coexist only when the AI runs on a device that already holds the key.