Since this value is used both for identification and authentication, it shouldn't be in the URL where it might be logged or otherwise discovered.
This implements client-side encryption, so that users' task information is not availble to the server (or to anyone who does not have the `encryption_secret`).