Sync
In Cloud mode, each device pushes its sealed changes and pulls those of the others. The server only orders revisions and distributes blobs it cannot read.
When it syncs
- Push: 2 seconds after each local change (batched).
- Pull: at unlock, when returning to the foreground, and every 5 minutes.
- Offline: a normal state. The indicator shows "Pending" and everything resumes on reconnection. No error dialog.
Revisions
Each upload receives a global revision number for your account. The device remembers the last known revision and only requests what is newer. If a device pushes with a stale revision, the server refuses the write and first returns the newer items.
Conflicts
If the same item was changed on two devices before they talked to each other, the last write wins. The other version is not lost: it is kept as a local copy named "(conflict)", only if its content really differs. You merge by hand, then delete the copy.
Trash
A deleted item leaves a tombstone for 30 days: the other devices learn about the deletion. You can restore it from the trash during that period. Permanent deletion requires retyping the item's name.
Devices
Settings, Account, Devices lists every connected device with its platform and last activity. Revoke cuts its tokens immediately: it will have to log in again with the master password and the 2FA code. A replayed refresh token revokes the device automatically.
What is transmitted
Base64 blobs containing, for each item, its key sealed by the vault key and its content sealed by its own key. The item identifier is bound in the authenticated data: a blob cannot be moved from one item to another. The name, category and content are all inside the blob.
A question not answered here? support@rempar.org