What Is Etebase and What Can You Build With It?
Etebase is an open-source SDK and backend for building end-to-end encrypted applications. It handles the encryption and its related challenges so you can sync user data without building cryptography yourself. It fits projects that need private, cross-device sync — task managers, note apps, and similar tools — where the server should never be able to read user data. If you just need a plaintext cloud database, Etebase is more machinery than you need.
What Etebase actually provides
Etebase describes itself as "Firebase but encrypted in a way that only end-users can access their data." Concretely, it's two things:
- Client libraries for desktop, mobile, and web, so you can build apps without worrying about the infrastructure or the encryption.
- A server that stores only encrypted data.
The server never holds the keys, so it cannot read what it stores. Everything — clients and server — is open source, which means you can verify the behavior rather than trust a claim.
Core capabilities
| Capability | What it gives you |
|---|---|
| Encrypted storage and sync | Securely encrypt and upload data with a few lines of code |
| Collection management | Create, encrypt, and upload collections of related data |
| Revision history | A full revision history of your data |
| Sharing and access control | Easy sharing among users, plus what you need for collaborative editing |
| Integrity protections | Strong integrity protections on stored data |
| Integrated billing | Available in beta |
A minimal example
The documented flow is short: log in, get a collection manager, create an encrypted collection, upload it.
// Setup encryption and login to server
const etebase = await Etebase.Account.login("username", "password");
const collectionManager = etebase.getCollectionManager();
// Create, encrypt and upload a new collection
const collection = await collectionManager.create(
"collection.type",
{ name: "My data" },
"My private data!"
);
await collectionManager.upload(collection);
The encryption happens client-side before the upload, which is why the server only ever sees ciphertext.
Why teams choose it
- Users care about privacy. Etebase's pitch is that privacy and security are increasingly a purchase criterion, and this gives you both without designing a crypto scheme.
- Breach protection. Encrypted data stays safe in a breach and, per Etebase, isn't even considered a data breach under GDPR and HIPAA.
- Easier compliance. End-to-end encryption makes complying with GDPR, HIPAA, CCPA, and FERPA substantially easier.
- Cryptography is hard. It's easy to get wrong, hard to get right, and even harder to know whether you got it right — so delegating it is a reasonable trade.
What it's built on
Etebase uses libsodium, a widely used and audited cryptography library, and is based on the code that powers EteSync. That lineage matters: it's battle-tested code rather than a fresh implementation. Tasks.org is listed as a user, which is a useful signal that the model works for a real, privacy-sensitive app.
When Etebase is the right fit
Choose it when:
- Your app syncs user data across devices and users expect that data to be private.
- You want to avoid implementing and maintaining your own encryption.
- You need sharing, access control, or revision history as part of the sync layer.
- Compliance with privacy regulation is a requirement, not an afterthought.
Look elsewhere when your data is genuinely non-sensitive, or when you need server-side querying and processing of plaintext — Etebase's design deliberately prevents the server from reading your data, which rules those use cases out.
Getting started
The site offers documentation, a sign-up path, and a login for existing users, plus a public roadmap and source code. Pricing details are published on a dedicated pricing page — check that page directly for current terms rather than assuming a free tier.