Last updated:

Encrypted task management for private practice.

Your EHR guards clinical notes. SealTask encrypts task and workspace plaintext on your device, so protected content is unreadable to us while operational metadata remains server-visible. SealTask does not replace the EHR or the controls your practice requires.

TL;DR

Practice-management systems cover charts, claims, and scheduling. The rest of running a practice — waitlist follow-ups, intake chasing, supervision prep, billing chores — tends to land in to-do apps whose servers can read every word. SealTask encrypts task plaintext on your device before it syncs, so a task title that mentions a client stays unreadable to us. Due dates, status, relationships, and other disclosed operational metadata remain server-visible. Start solo on the €0 Free tier and share lists with an assistant only when you need to.

The gap your EHR doesn’t cover.

Clinical documentation belongs in your EHR. But most of the work that keeps a practice running happens outside it, and that is where confidentiality quietly leaks.

Operational tasks name names.

“Follow up with M. about intake paperwork.” “Resend superbill to J.” The moment practice admin moves into a general-purpose to-do app, client references travel with it — into a database someone else can read.

Conventional tools process plaintext.

Mainstream task managers encrypt data at rest, but provider-side systems can still process readable content for features and support — and AI features may send it further. Encryption at rest protects storage media, not necessarily content from provider access.

Your clients chose you for discretion.

Many clinicians now tell clients that their information never touches AI tools or third-party analytics. The reminders and follow-ups around your clinical work deserve the same standard as the charts themselves.

What SealTask encrypts before sync.

Zero-knowledge is a checkable claim, not a slogan. SealTask encrypts task, list, note, comment, checklist, recurring-template, and attachment content with ChaCha20-Poly1305 before it leaves your device; operational metadata remains server-visible. The cryptographic implementation is published on GitHub for audit. Here is the honest split:

Not readable by the service

  • Readable task titles
  • Readable task bodies and notes
  • Readable recurring-task template content
  • Readable comment bodies
  • Readable checklist content
  • Readable project titles and descriptions
  • Attachment plaintext
  • Plaintext account passwords
  • Workspace content decryption keys

Server-visible workspace metadata

  • Account email addresses and workspace or project membership identities, roles, statuses, invitation states, and access timestamps
  • Database identifiers and relationships, including project owner, task and note creators, comment authors, delegation members, attachment uploaders, and per-member task-read cursors
  • Project timezone, section identifiers and policies, section timestamps, and task position or order
  • Task priority, completion and archive state and timing; note privacy and timestamps; per-member task-read timestamps; project timestamps and archive state; note, comment, and attention counts; and workspace write or collaboration entitlement flags
  • Recurrence schedule, timezone, active state, section, iteration, next-run, last-materialized, and task-materialization timestamps
  • Comment authorship relationships, counts, and timestamps; comment bodies remain encrypted
  • Delegation membership identifiers, roles, statuses, and timestamps; delegation notes remain encrypted
  • Attachment, project, and task relationships, including task-to-attachment link timestamps; storage identifiers; ciphertext byte size (which usually approximates original file size); upload capability expiry and protocol; status; and creation, update, or deletion timestamps; attachment content remains encrypted
  • Per-membership salts and membership proofs, plus the server-held project-scoped payload-binding key used to verify or compute matching HMACs; this binding key is not a workspace-content decryption key
  • Real-time event types; event, project, actor, membership, browser-instance, affected entity, section, and order identifiers; changed-field names; occurrence timestamps; and missed-event counts

This disclosure covers encrypted workspace content and its server-visible metadata. The workspace-content metadata inventory is complete for the enumerated current workspace persistence and SQL models, API-response models, and SSE event models. It is not a complete privacy-data inventory and excludes account authentication, billing, security and audit, abuse-prevention, and service telemetry domains; those domains are described non-exhaustively in the privacy policy. Metadata can itself be sensitive. Attachment ciphertext size usually reveals an approximation of the original file size. If a due date, recurrence, relationship, or status would itself reveal clinical context, keep that item inside your EHR.

Built for how a practice actually runs.

Start solo, stay solo if you like.

The Free tier costs €0 and needs no credit card: one workspace, two projects, 100 MB of attachments, and 30-day audit history. Enough to run an intake pipeline and an admin project.

Repeating tasks for recurring compliance.

Progress-note deadlines, claim submissions, license and CE renewals, supervision prep — set them once and let them come back. Recurring task template content is encrypted, while the cron schedule, timezone, active state, and run timestamps remain server-visible metadata.

Share one list, not your whole practice.

Personal (€5.90/mo) adds project sharing with per-project access control: give a virtual assistant or billing service exactly the project they need. Removing a collaborator revokes their server-authorized access to the project. Using access review to remove them from every manageable project applies that same server-side revocation to each project. On the server that commits the change, active real-time streams are signaled after the commit; changes committed on another server and bulk or otherwise unsignaled changes are rechecked within the current authorization lease, at most 30 seconds. Bytes already delivered or buffered by the transport cannot be recalled. The current release does not automatically rotate any affected project key or re-encrypt projects for remaining members, and removal cannot erase content or key material obtained while the collaborator was authorized. If future sensitive work needs a fresh cryptographic boundary, create a new project and share it only with current members.

Search that never leaves your browser.

SealTask provides no server-side full-text search of workspace content. Search runs on your device after unlock and decryption.

Worked example: a new-client intake without a second chart.

The task layer coordinates follow-up. The EHR remains authoritative for identity, consent, clinical information, scheduling, and documentation.

SealTask

Intake I-17: confirm paperwork status.

A neutral reference and operational next action can live in the encrypted task list.

SealTask

I-17: remind owner to record the outcome.

The reminder lives in SealTask; the intake outcome is entered in the EHR.

Specialist system

Client identity, consent, health details, and clinical notes.

These belong in the approved EHR or practice-management system.

Specialist system

Claims, superbills, payment data, and formal scheduling record.

Keep these in billing, payment, and scheduling systems with the required controls and agreements.

A private reminder is still not the clinical record. Minimize the task, use a neutral reference, and keep the source in the EHR.

What belongs here, and what stays in the EHR?

This is a product boundary, not clinical or legal advice. Practice policy and applicable agreements may require an even narrower use.

Work item SealTask System of record Why
Operational owner and next action Yes — use a neutral reference when possible EHR or practice-management system SealTask coordinates the follow-up; the practice system preserves the client record.
Clinical notes, diagnosis, treatment, and consent No — do not duplicate EHR Clinical records need the EHR’s access, audit, retention, and correction controls.
Claims, superbills, and payment information Reminder only Billing and payment systems Financial and health records need their specialist workflows and agreements.
Assistant or billing-service handoff Yes — a dedicated shared list Authorized practice systems Per-list access narrows coordination, while source-record authorization stays separate.
Sensitive appointment or treatment timing Only if metadata exposure is acceptable EHR or approved calendar Due dates and timestamps remain visible operational metadata.

An honest note on HIPAA.

SealTask’s zero-knowledge design aligns with the goals of HIPAA’s technical safeguards: task, list, note, comment, checklist, recurring-template, and attachment content is encrypted before it leaves your device, and we hold no keys to decrypt protected content. A database breach could expose ciphertext plus account, routing, audit, and workspace metadata.

Encryption alone does not make a tool HIPAA compliant. SealTask must expressly agree in writing before any PHI use. Where HIPAA applies, the parties must execute a HIPAA-compliant BAA before use.

In practice, many clinicians keep clinical documentation in their EHR and use a separate tool for the operational layer around it. That division can keep the PHI question smaller. Do not place PHI in SealTask unless the required written consent is in place and, where HIPAA applies, the parties have executed a HIPAA-compliant BAA.

Contact SealTask before any PHI use

Frequently asked questions.

Is SealTask HIPAA compliant?

SealTask does not treat encryption as automatic HIPAA compliance. Its zero-knowledge design supports technical-safeguard goals, but HHS guidance says even a no-view cloud service acting as a business associate needs a contract. SealTask must expressly agree in writing before any PHI use. Where HIPAA applies, the parties must execute a HIPAA-compliant BAA before use. Do not store PHI unless both conditions are satisfied.

Can SealTask staff read a task title that mentions a client?

SealTask cannot decrypt readable task, project, note, comment, checklist, recurring-template, or attachment content, and it does not receive plaintext passwords or workspace content keys. The service can still see operational metadata such as account and membership identities, relationships, task state and timing, recurrence schedules, attachment sizes and statuses, and real-time event identifiers. Metadata can itself be sensitive; the security architecture lists the complete current workspace inventory.

What happens if I forget my password?

SealTask cannot reset it for you — the server holds no keys needed to decrypt protected workspace plaintext, and disclosed operational metadata remains server-visible. Your safety net is a one-time backup key you download and store safely: it lets you reset your password and keep access without giving SealTask a content-decryption key. With neither the password nor the backup key, protected workspace content is unrecoverable.

Can I share a list with an assistant or billing service?

Yes. The Personal plan (€5.90/month) adds project sharing with per-project access control, so a collaborator sees only the projects you share. Removing a collaborator revokes their server-authorized access to the project. Using access review to remove them from every manageable project applies that same server-side revocation to each project. On the server that commits the change, active real-time streams are signaled after the commit; changes committed on another server and bulk or otherwise unsignaled changes are rechecked within the current authorization lease, at most 30 seconds. Bytes already delivered or buffered by the transport cannot be recalled. The current release does not automatically rotate any affected project key or re-encrypt projects for remaining members, and removal cannot erase content or key material obtained while the collaborator was authorized. If future sensitive work needs a fresh cryptographic boundary, create a new project and share it only with current members.

Does SealTask replace my EHR or practice-management system?

No, and it does not try to. Clinical notes, charts, claims, and scheduling belong in a system designed for them. SealTask covers the operational layer around your clinical work: follow-ups, recurring admin, projects, and the running lists a practice generates.

Does SealTask use AI on my data?

No. SealTask has no AI features that process workspace content, and the server does not hold the keys required to decrypt protected content.

Is there really a free plan?

Yes. The Free tier costs €0 with no credit card: one workspace, two projects, solo use, 100 MB of attachments, and 30-day audit history. Personal (€5.90/month) adds unlimited projects and project sharing.

References & further reading.

  1. 01
    SealTask Security — Full zero-knowledge architecture walkthrough
  2. 02
    SealTask Pricing — Free, Personal, and Team plans
  3. 03
    SealTask Terms of Service — Written consent is required before PHI use; a HIPAA-compliant BAA is additionally required where HIPAA applies
  4. 04
    HHS HIPAA Cloud Computing Guidance — Why no-view cloud services still require BAAs
  5. 05
    Best Encrypted Task Management Software — How SealTask compares with Notion, Trello, ClickUp, and Standard Notes

More guides for confidentiality-bound work.

Compare workflows and system-of-record boundaries for executive assistants, law firms, stealth startups, HR and recruiting, and consultants.

Browse audience guides

Keep the practice organized — and confidential.

Start on the Free tier: one workspace, two lists, €0, no credit card. Task and workspace plaintext is encrypted before sync; disclosed operational metadata remains visible to the service.