With the FIDO token I can use GoCrypt multiple times (office, notebook, private), depending on where the FIDO token is registered. The private key and my email address are securely stored in the FIDO token. Without a FIDO token, the private key is stored on the PC where the registration took place. Multiple use is not possible. Another advantage is password handling for logging in to GoCrypt. With the FIDO token you have a PIN / PUK reset option. With the GoCrypt application without FIDO token, there is no reset option for the private key. If you lose your PIN, you will have to re-register GoCrypt. This will give you a new private key on your PC. The unretrieved files, if any, will no longer be available for download. However, the data from the history list is retained.
Data classifications are applied when data should only be shared within a specific group, department, organization. This data may not be shared outside of this group of people (management, development, finance, etc.).
For the tokenless version:
The private key is stored on your computer, but it is encrypted with a password. Without the password, the private key is useless.
For the token version:
The private key is in the token and never leaves it. Even if someone gains physical access to your token, it cannot be used unless they know the token password.
No, that's impossible. The file you send/download never leaves/reaches your computer decrypted. Encryption occurs before sending and decryption after downloading. So there is no point in analyzing the data traffic, the files just come through the network encrypted.