Do we then need a service provider to hold the e2e decryption keys?
I was thinking your password is your decryption key so that even if the place is hacked the service provider could never decrypt your nsec