Skip to content

FAQ — Silos, Privacy & Encryption

Quick answers to the questions people ask most about how Letro keeps their messages private. Each answer links to the full page if you want the detail.

Is Letro really end-to-end encrypted?

Yes. Messages, calls, and files in Letro are end-to-end encrypted by default. That means they're scrambled on your device and can only be unscrambled on the devices of the people in the conversation. Nothing readable travels or sits on the server in between.

Related:

Can Letro (or my company) read my messages?

No. Because encryption happens on your device, Letro cannot read your messages, and neither can whoever runs the server. Only you and the people in the silo hold the keys to unlock the content. The server stores encrypted data it can't open.

Related:

What is a recovery key and why do I need one?

Your recovery key is a long string of letters and numbers that can unlock your encrypted message history on a brand-new device. It's your safety net: if you ever lose access to all your signed-in devices, the recovery key is the one thing that can restore your past messages. Save it somewhere only you can reach.

Related:

Why do I have to verify my devices and other people?

Verification confirms that a device or person really is who they claim to be, so no one can quietly slip in and impersonate them. It's how Letro proves your keys match end to end. Once verified, you'll see a badge and stop getting warnings about that device or contact.

Related:

What happens if I lose my device?

As long as you still have another signed-in device, or your recovery key, you're fine — sign in again and confirm it, and your encrypted history comes back. Set up secure backup and save your recovery key now so this is painless later.

Related:

What if I lose all my devices?

Your recovery key restores everything. Sign in on a new device and enter the key to unlock your message history. But be honest with yourself about this trade-off: if you've lost every device and don't have your recovery key, there is no way to recover your past encrypted messages — not even Letro can bring them back. That's the cost of true end-to-end encryption, and it's exactly why the recovery key matters.

Related:

What does "unable to decrypt" mean?

It means your device doesn't have the key needed to unlock a particular message — usually because the message was sent before your device joined, or your keys are still syncing. It doesn't mean the message is lost or that anyone tampered with it. Verifying your devices and making sure secure backup is on usually clears it up.

Related:

What does "key storage out of sync" mean?

It's Letro telling you that this device's encryption keys aren't lined up with your secure backup yet. It's a fixable state, not a breach. Re-verifying the device or re-entering your recovery key gets your key storage back in sync.

Related:

Who can join a silo and read its history?

That's up to the silo's settings. Silos can be invite-only or open to your organization, and a separate setting controls how much past history new members can see — everything, or only messages sent after they joined. Encryption still applies either way: only members hold the keys.

Related:

What's a Dedicated Server and where is my data stored?

A Dedicated Server is a private server that hosts your organization's Letro account, so your encrypted data lives in an environment your company controls rather than a shared one. Because encryption happens on your device, even a Dedicated Server only ever holds data it can't read — it just gives you control over where that encrypted data sits.

Related: