Working with your own coding agent means pasting commands, diffs and output you would not paste into a group chat. A sealed scratchpad encrypts all of it on your devices. Threa's servers hold the ciphertext and have no way to open it.
Encryption covers scratchpads and the threads under them. The key is yours. Everything written in one is encrypted in your browser, or on the machine your agent runs on, before it is sent.
Your messages, the agent's replies, and every trace step it writes while it works. The command it ran and what came back are in the stream where you can read them, and nowhere else.
The title is encrypted too, and your browser decrypts it for the sidebar. A list of your scratchpads gives away nothing about what is in them. Threa names the others for you by reading them. This one you name yourself.
When the agent stops to ask whether to run the migration, the question, the choices and the note you type back are sealed. The server learns which option you picked, because it has to check the answer is one of the ones on offer.
Under Settings, in the AI tab. You pick a passphrase, and it wraps a key that never leaves your device unwrapped. Unlock on each device you use, or keep that device unlocked with a PIN or your fingerprint.
Invite the bot from the scratchpad's header and Threa wraps the scratchpad's key to the key on that machine. Take it back out and the wraps it could open are deleted and the key rolls forward: it keeps what it already read and gets nothing sent after.
threa e2e unlock once puts your key in the OS keychain.
After that the ordinary commands work on a sealed scratchpad the way
they work anywhere else: threa streams read prints it,
threa messages send posts to it. The terminal does the
encrypting, so an agent with a shell needs nothing else.
Anything Threa does by reading your messages stops at the seal. Nothing in a sealed scratchpad is searchable and nothing in one becomes a memo, so the knowledge base Threa builds from your conversations skips it. Scheduled messages and stream briefs are off there for the same reason.
Lose the passphrase and that content is gone for good. There is no reset, because a reset would mean someone else had a copy of the key. That is the whole point, and it is worth knowing before you turn it on.
Everything outside sealed scratchpads works the usual way. Channels, DMs and threads are encrypted in transit and at rest like any other service, and Threa can read them, which is how search and memory work at all. Encryption is for the scratchpads where you and your agent do the work.
The crypto is RFC 9180 HPKE with AES-256-GCM, and the code that does it is in the public repo. Read it before you trust it.