March 2021 status: Public roadmap and Spreadsheet updates

This month we released two versions of CryptPad, 4.2 and 4.3. Both improved CryptPad’s stability and performance:

  • Version 4.2 saw Offline mode extended to Teams, shared folders within teams, and files. Summary on Mastodon
  • Version 4.3 focused on improving “intensive” use cases, defined as 1200+ concurrent viewers on the same document, or 10+ editors all writing at once. Summary on Mastodon

In this status we’ll focus on long requested updates to Spreadsheets and on other activities of note for the month.

Spreadsheet updates

We made a couple of important updates to the Spreadsheets application this month. First we enabled OnlyOffice’s Strict collaboration mode, in addition to the Fast mode that was already integrated. In Fast mode, which remains the default, new edits are synchronized automatically between users as they are made. In Strict mode, users “lock” cells as they edit them and they have to manually save their changes in order for them to be sent to other users. The benefit of Strict mode is that it allows users to Undo their unsaved changes. The lack of undo in sheets has been a recurring point in user feedback. This goes some way towards addressing these requests, at least within the constraints of OnlyOffice collaboration. There are more details on how to switch between modes in our Spreadsheet documentation.

The other notable change is the update to OnlyOffice 6.2 in our 4.3 release. Aside from small user-interface polish, this update introduces pivot tables and improved graphs.

Open Tech Will Save Us

David presented CryptPad on the monthly Open Tech Will Save Us Matrix/Element meetup. Episode 11 was an art & design special with a great lineup:

Public Roadmap

We have been working to make more use of CryptPad itself to communicate about the project. The first major step in this direction is the introduction of our Public Roadmap Kanban where we detail all of the research projects we are currently working on. We summarise each project, funding amount, and associated features. Using the tags feature to filter one project gives an overview of its completion status. We find this very useful and hope you will find it informative.

The Public Roadmap Kanban

The next steps planned in this direction include a review of the onboarding document (the first document that is placed in new user’s CryptDrives), as well as a rewrite of the Privacy Policy for This last one is nearly complete and will be published as a rich text document.

Cleaned up translations

We have started an effort to reduce the amount of work needed to translate CryptPad. As the development team we maintain English and French, and an active German speaking community maintains the German translation in near real-time for which we are very grateful. We want to encourage people to translate CryptPad in other languages, and to complete the many languages where the translation has been started but not completed.

Past efforts towards this have included moving the Frequently Asked Questions out of the platform to a dedicated page in the documentation. This month we have taken further steps with automated scripts to detect un-used translations. These were left over from previous versions of CryptPad and were sometimes hard to detect in the code. There is now less work for translators, and better assurance that no time will be wasted translating text that isn’t actually used in the product.

We are keeping this in mind for future versions and will do our best to facilitate the work of community translators as much as we can. If you are interested in translating CryptPad, please head over to our Weblate instance.

This wraps up our monthly status update. There is more to look forward to in April as we move to complete our Communities project, and exciting things on the horizon for CryptPad’s interoperability with office formats.

Feb. 2021 status: Dark mode and organisation plans

This is a new format of post we are starting on the blog: publishing the monthly updates that were until now only circulated in the internal XWiki newsletter. This will be an opportunity to regularly catch up on new features, research projects, funding/budget updates, and any other relevant news.

FOSDEM presentations

Aaron and David presented different aspects of CryptPad at FOSDEM 2021. Please see the updated blog post for videos of both presentations.

Dark mode

This month we followed up on the rebranding started with version 4.0 by thoroughly refactoring how styles, especially colors, are applied across CryptPad. This allows for better maintainance and easier customisation. The first custom theme is the long requested dark mode.

CryptPad will now follow the browser or operating system preference by default, and switch to a dark theme accordingly. The theme can also be set manually in Settings > Appearance.

The CryptDrive in dark mode

Following the introduction of the dark theme in our 4.2 release, we noticed a few problems and got to work on correcting them. The most noticeable issue was the use of a dark background for rich text documents. Wanting to offer a “true” dark mode, we had intially switched the editor itself to a dark background, and made the default text color contrast with that automatically. It soon became apparent that this was a problematic choice in rich text documents where users are able to set colors for text. It may lead to text being un-readable depending on the theme used. One particularly painful example was a document about making web content accessible written in black text on a dark background. We reverted our decision and opted for a light background in the editor even when the rest of the interface is dark. There is a reason mainstream editors such as Microsoft Word do it this way. You can expect more polish on the dark theme in the upcoming 4.3 release.

Web accessibility guide shown with black text on a dark background

The web content accessibility guide that prompted us to revert our decision on the dark theme rich text editor. The guide is by AccessiBloc.

Organization plans

On, another long-awaited feature were the Organization plans. We have been communicating this pricing on request for the last few months but the plans are now live in the interface. These bigger plans have the additional option to download a personalised signed Data Processing Agreement (DPA) for organsations that need to demonstrate they operate according to the GDPR.

These plans come with 1 business day support and increased storage shared between a number of user accounts, priced as follows:

  • 25 Users with 100GB of storage for 500€ a year (ex. VAT)
  • 100 Users with 150GB of storage for 1000€ a year (ex. VAT)

An additional On Premises option is available for organizations that require their own CryptPad instance, with installation and maintainance support by the development team.

We were happy to welcome the first couple of subscribers on these plans and hope that they will contribute to making CryptPad financially sustainable in the longer term.

The new organization plans on in dark mode.

We had an unexpected spike in traffic early in the month after the following tweet linked to a toolkit made on

This brought a lot of traffic to the service, as illustrated by the spike below. While this was a surprise, our infrastructure was prepared for it and held up very well.

graph showing a big spike in visits to

Delivered: NGI Trust project: Secure Mobile Collaboration

We have wrapped up this exploratory project about using CryptPad on mobile devices. There will be dedicated posts about this project in the near future. This project allowed us to scope out, in depth, the options available to make CryptPad work as an “app”. As a summary of our findings, here is what we plan to include in the new Frequently Asked Questions section of our documentation that will be part of the next release:

FAQ: Are you planning a mobile app?

We are not planning a dedicated mobile application for the following reasons:

  • It would dramatically increase the amount of code that has to be developed and maintained, effectively creating other “versions” of CryptPad for iOS and Android.
  • CryptPad is open source and can be hosted by anyone who wants to offer the service. Therefore, users of a mobile application would have to specify which CryptPad instance they want to connect to, which would be confusing. To complicate things further, each instance may be running a different version of the software, depending on whether or not the latest updates were applied by the administrators.

To address these problems, the development team is working on making CryptPad a “Progressive Web App”. This means that it can be used on mobile through the web browser, behaving like an application while being the same software that runs on desktop browsers. This has the benefit of turning every CryptPad instance into a web app provider, rather than putting the burden of choosing the right instance on the user.

This approach has already started to inform new developments for CryptPad, for example the use of IndexedDB for caching documents which is already deployed. Further improvements will follow, including a full “offline” mode.

This wraps up our first monthly status post. In March we will be shifting back to our NLNet Communities project and attempt to finish the outstanding deliverables around documentation for developers and instance administrators.

CryptPad at FOSDEM 2021

(this post was edited on 24th Feb. 2021 to include links to videos and corrections)

The CryptPad team is taking part in the 2021 online edition of FOSDEM. We will use this opportunity to reflect on the past year from a couple of different perspectives.

Aaron MacSween’s presentation is about the technical challenges faced by the team this year. The massive influx of users working from home pushed us to scale CryptPad to accomodate an additional 60K weekly active users. This was made easier by the platform’s unique architecture, where most of the “expensive” work involving cryptography happens on the client rather than the server. Additional challenges involved a 27 hour outage due to a cooling malfunction at our hosting provider. While the outage itself was out of our control, it brought into sharp relief that our procedures to mitigate uncertainty had not scaled with our user-base. Aaron will speak about what we plan to do to avoid such situations in future.

In the design devroom, I will reflect on my first year as the designer on the CryptPad team. My work has been spread across many different areas, from UI design to answering support tickets, writing the product and documentation, as well as visual identity. All of these elements boil down to one thing: communication. I will show some examples of work produced this year as attempts to improve how CryptPad communicates, from onboarding to daily-use. I will conclude with one of the challenges for the year ahead: accessibility. Communication is all well and good, but of no use if it cannot be heard on a screen reader.

Talks are pre-recorded and will be aired on Saturday 6th February. For more information, abstracts, and broadcast time with Q&A session, see the indications below.

This blog post will be updated with video embeds once these are available.

Living on the edge with CryptPad

  • Speaker: Aaron MacSween

Due to unforeseen circumstances, Aaron was unable to include his presentation in the FOSDEM track. However he still recorded it so we are making it available here and on our PeerTube channel.

Watch on the CryptPad Peertube channel

Communicating CryptPad

Watch on the CryptPad Peertube channel

No plan survives first contact with the enemy

In 2019 we finished a four-year research project that had covered the majority of CryptPad’s development costs. We had some worries about how we would continue to fund our team, but we were fortunate enough to meet and form a good relationship with members of Europe’s Next Generation Internet Initiative.

We received 50000 Euros from NLnet as a part of their NGI0 Privacy Enhancing Technologies grant program. Though we’d planned to finish this project (CryptPad Teams) before the end of 2019, research projects at this scale require a faster pace than we were used to. We’d had an intern join our team over the summer, our plan didn’t really account for vacation days, another salaried worker joined our team in November, and in general there were just many distractions that made everything take a bit longer than expected

We mostly made up a lot of the difference with an increasing number of donations and subscriptions via our premium accounts portal, and we had written a number of new grant proposals for the coming year. Our second NLnet proposal (CryptPad for Communities) had already been accepted, but we were waiting to sign the final contract before making any announcements. So, with 2020 on the horizon I wrote an article which alluded to our plans while we waited to hear back about which of our remaining proposals would be accepted.

2020’s projects

In early 2020 we were still finishing up the final components of CryptPad Teams. In addition to the remaining technical features we were also required to complete two audits of the platform: one to assess CryptPad’s accessibility and another quick scan of its security features. We didn’t really know how long these would take, and we hadn’t budgeted additional time for them, so these delayed our other projects and added a little bit to our 2019 deficit.

We already knew to expect another 50000 Euros from NLnet for our Communities project, but since the status of our other proposals was still uncertain we decided to attend the Open-Source Speed Dating session at FOSDEM. Two of our team members pitched a project to speed up CryptPad’s page loading times, making for a total of three pending proposals.

As it turned out, we heard about all three projects in the space of a few days and all three were accepted. We weren’t expecting all of these proposals to be successful, so we had to adjust a lot of our plans to ensure we could manage all of their respective deadlines, but on paper it all seemed manageable.

CryptPad for communities

We’d already begun working on Communities‘ features quite early in the year. The project included a number of high-level themes, but the overall goal was to make it easier for groups of various sizes to adopt or transition to CryptPad instead of proprietary alternatives.

Firstly, we’d heard from small businesses and social initiatives that they wanted to use CryptPad but needed some new features before they could make the switch. We made major changes to our Kanban, rich text, and spreadsheet editors.

CryptPad’s admin panel, which used to be very limited, now features a variety of controls for adding or modifying quotas for particular users, along with a variety of other configuration options to make it easier to run your own CryptPad instance. We still need to add the ability to restrict registration and unregistered usage, but we expect to deliver this in early 2021.

Finally, we launched our documentation platform, which is available in English, French, and (courtesy of some dedicated contributors) German. There is currently only a user guide, but we’ll soon offer a thorough installation guide for admins and some technical documentation for contributors.

Secure Mobile Collaboration

The goal of this project was to experiment with different technologies and ultimately prototype some dedicated mobile and desktop apps for CryptPad. Our intent was to make CryptPad usable on mobile devices while also improving security by distributing static builds of our source code with cryptographic signatures so their authenticity could be verified.

We pitched this project to NGI TRUST at the end of November 2019 and framed it as an experiment since we weren’t sure we’d be able to maintain dedicated apps in addition to the web platform we already offer. Nevertheless, we know that mobile support is important to our users and we wanted to dedicate time to investigate our options.

We expect to finish this project soon but our approach has diverged from its early goals in some very notable ways. For now I’ll just say that a lot of time and effort has gone towards addressing the intended problems and that you can expect a dedicated blog post or two about this in the near future.


Not long after proposing Communities to NLnet we pitched this third PET project. It can take several months for these proposals to pass through their various stages of review, and each project only funds our team for part of the year, so it’s important that we line up our next project before the current ones finish. At the same time, we can’t (legally) get paid by multiple funding bodies for the same work, so we need to ensure that projects don’t overlap.

We applied for this and the NGI TRUST grant concurrently, but we didn’t expect to win both. NLnet’s deadlines are considerably less strict, however, so we’ve prioritized SMC and saved Dialogue for the coming year. All NGI0 PET projects have to be completed by late 2021, so we expect this to be our last.

CryptPad is currently specialized mostly for real-time document editing, and our cryptographic permissions system reflects that. The main idea behind this project is to develop a new set of applications with different permission schemes that support more granular permissions for document components instead of all-or-nothing permissions for whole documents.

We already offer a poll application, but it uses the same editor/viewer roles as our document editors, which really doesn’t match users’ expectations. This current implementation will be phased out in favour of the new scheme to support distinct roles for authors (who can ask questions and determine who can answer them), responders (who can submit answers), and viewers (who can see responses). We’re also going to add support for more complex surveys with multiple questions, implement a reminder system to notify authors and viewers when their polls have closed, and add some more instance admin functionality so that we and other people hosting CryptPad can communicate with their users via the existing notification system.


The requirements of Mozilla’s Open-Source Support program were considerably less formal than those of NLnet and NGI TRUST. We received 10000 USD, which converted to about 9000 Euros at the time we received it, and we promised to use it to improve page loading times. There wasn’t any contract or formal definition of how we’d planned to do this, and no deadline given.

This funding model was extremely helpful for us this year and did a fantastic job of living up to its name and goal of supporting open-source. Our European funding partners provide all or most of their financial support as their deliverables or the entire project are completed. By contrast, MOSS solved some immediate cash-flow issues during this difficult year and afforded us the flexibility to fulfill our promises in between our other deadlines.

So far we’ve followed up on these goals by profiling page loading times on different devices to determine where to best spend our efforts. We’ve made a number of small optimizations on the client along with some big server improvements that were frequently the cause of bottlenecks when establishing a new connection to the server. There’s still much more to do in this regard, and we plan to post ongoing updates as we find more room for improvement.

A year of surprises

With the exception of our MOSS grant, everything I’ve mentioned so far was planned and proposed late in 2019. We’d set our objectives for 2020 early on and had carefully considered how we could coordinate our multiple projects and how their features could complement each other. As you might imagine, very little went according to plan.

i vaguely recall a few headlines about a respiratory illness being discovered in China late last year, but I didn’t give it much thought and obviously didn’t foresee the impact it would have on our plans for the year, let alone everything else it affected. As the epidemic became more widespread, was upgraded to pandemic status, and triggered lockdowns across the world increasingly more people moved to working online. Previously, I was happy with our success when we saw ten to fifteen thousand users in a week, but those numbers quickly doubled, tripled, and quadrupled in a matter of months as offices and classrooms started relying heavily on our platform.

Unique IPs per visiting per day

We made some significant changes to our server code to keep up with demand and eliminated some of our client’s code that was particularly expensive for the server. The precise technical details of exactly what we did to adapt to the dramatic increase in usage deserve their own article, but in general we suddenly had to pay a lot more attention to our infrastructure than was previously the case. We started regularly allocating more disk space to the server and, as 2020 ends, we now store more than six times more user data than we did this time last year.

One major lesson we’ve learned, however, is that it’s been far easier to scale our infrastructure than manual support for the platform. Our surge of new users came along with a matching increase in support tickets, emails, GitHub iissues, and questions on social media. We prioritized the documentation that we were writing as a part of our Communities project, however, we still had to take time to answer the questions of people who hadn’t found those docs or whose questions were not clearly answered therein.

We’re still working to streamline this process, but our ability to respond to individual questions is a frequent bottleneck for our team. This typically makes it more difficult to stay on top of our usual development cycle, and leaves less time than we’d like for promoting the project via public events or blog articles. Having too many users is a fantastic problem to have, though, so this is less a complaint and more an acknowledgement of a challenge that we need to address. We can’t afford to be just a team of software developers that also happen to maintain and support a platform when both activities are equally important to our continued success.


After the year we’ve had it’s tempting to view the future as increasingly uncertain, but the reality is that nothing was ever certain to begin with. We’re still making plans for 2021, but our plans now include more caveats and fallbacks to (hopefully) lessen the impact of whatever else we don’t see coming.

With all the unexpected stress of this year it’s difficult to remember the good things, but we’ve had an incredible increase in support from our users. Contributors have helped to add some significant features to the platform this year and have translated CryptPad into a number of languages. In the past two months subscriptions and donations have covered one of our three team members’ salaries. Our yearly revenue has once again more than doubled compared to the previous twelve months, and if these trend continues we’ll be able to fund our current team’s salaries without having to depend on grants.

There’s a lot more to be said about our goals for the future, but we still have a number of projects to complete, so for now I’ll prefer not to think too far ahead. Instead, I’ll leave you with a bit of a teaser for our upcoming 4.0.0 release…

CryptPad 4.0.0, coming in January 2021!

Thanks so much to everyone who’s supported us in any way throughout this difficult year.

We wish you all the best in 2021!

Recent interviews and presentations

CryptPad and the team have received some attention recently through various channels: a Reddit AMA thread, podcast, presentation, and blog interview. Whether you prefer to read, watch or listen there is a way for you to get an up-to-date presentation of CryptPad.

Aaron MacSween was invited for an Ask Me Anything (AMA) thread on r/privacy on Reddit. The thread started on November 27th 2020 and lasted for a couple of days. 98 questions were raised about everything from CryptPad’s business model, to future development plans, the broader state of open-source software, and the EU’s recent debates against encryption.

Aaron was also a guest on the We Don’t Stream podcast in an episode titled Imagine Google Docs but without the spyware. This was a general presentation of CryptPad, the origin story and the motivations behind it. Each guest is asked to nominate an NGO to encourage donations. Aaron chose the Electronic Frontier Foundation so please consider supporting them.

Ludovic Dubost was interviewed on Website Planet, answering questions about XWiki and CryptPad. The interview covers the founding of XWiki, the effects of the COVID crisis on the company and CryptPad, as well as the future of the open-source industry.

Ludovic also presented CryptPad at esLibre 2020, a Spanish open-source conference organised this year by King Juan Carlos University. Like many others this year this was a “virtual” event, the video is available on our PeerTube channel. Ludovic covered the background of the project and gave a demo-tour of CryptPad.