PrivacyNotes

Help & FAQ

Answers and step-by-step guides: security, sync, pricing, and switching from other apps.

Ask your AI agent instead

// Getting started

Can I try PrivacyNotes without creating an account?

Yes. The demo at try.privacynotes.app is the full app with sample content: no signup, no email, and nothing you type is saved. It runs entirely in your browser and never sends anything to our servers.

Closing the tab clears everything, which is the point. When you are ready to keep your notes, create a real vault at use.privacynotes.app and start fresh: copy out anything from the demo you want to take with you first.

Which sign-up option should I choose?

Whichever matches your threat level. There are three of them. One: sign in with Google, Apple, or GitHub, with your key stored on our server. Two: the same sign-in, with your key kept on your device only. Three: "Generate a phrase", with no email, no name and no login at all. All three keep your notes encrypted on your device, and what separates them is who holds the key and how much we learn about you.

Signing in with Google, Apple, or GitHub then asks where your key lives, starting on "Keep it simple & convenient". That option stores your phrase on our server, encrypted, so a new device can open your notes after provider sign-in and an authenticator code if 2FA is enabled. Save your phrase in case you lose the provider account, and keep your 2FA backup key if you enable two-factor sign-in. "Maximum security & privacy" keeps the phrase on your device: we could not read a note under any pressure, and a new device needs your 12 words or a QR scan from one already signed in.

The phrase-only route has no email or name tying the account to a person. In exchange the phrase is yours alone, so losing it with no unlocked device left means nobody can recover it for you. Settings > Account > Key custody shows your current mode and lets you change it. A phrase account must first connect a provider under Account > Accounts before choosing server custody; connecting alone does not change custody. Every mode can add a PIN or biometric lock and optional two-factor sign-in. The full comparison is in the threat-level ladder.

Do I need an email address to sign up?

No. A new vault is a freshly generated 12-word recovery phrase, nothing else. No email, no username, no phone number, no verification step. If you sign in with the phrase, we could not email you even if we wanted to, because we never learn who you are.

Prefer a familiar flow? Sign in with Google, Apple, or GitHub works too. That route necessarily tells us the email tied to that login, but your notes stay encrypted on your device either way, and you still get a phrase under the hood.

How do I move my notes in from another app?

Open Settings > Import & Export and pick your source. The list covers the apps people arrive from: Apple Notes, Obsidian, Evernote, Standard Notes, Notesnook, UpNote, Google Keep, Simplenote, Samsung Notes and Apple Journal. Bitwarden and your browser's saved passwords land in the Vault, your browser bookmarks come across as bookmarks, and a generic Markdown importer takes any folder of .md files.

Imports run entirely on your device: your exported files are parsed, encrypted, and stored locally, nothing is uploaded for processing. Each imported note is tagged with its source so you can review the batch afterwards, and Google Keep checklists even convert to native task lists.

Can I edit a folder of Markdown files from my own disk?

Yes. Open the Markdown pillar in the sidebar, pick a folder of .md and .txt files, and edit them in the same editor you use for notes. Subfolders appear on their own, edits save straight back to the file, and nothing is converted, so the same folder keeps working in Obsidian, in a git repo, or in your own scripts. Save to my notes copies any file, or a whole selection, into your encrypted notes in one click and leaves the original where it is. All of it is free on every tier.

Those files stay on your disk exactly as you left them: we never upload them, they never sync to your other devices, and nothing is converted on the way in or out. It works in the desktop app on any computer, and in Chrome, Edge or Opera in the browser, because opening a folder straight from disk is a desktop capability.

Can I open a Markdown folder on my phone?

Not today. The Markdown folder runs in the desktop app on macOS, Windows and Linux, and in Chrome, Edge or Opera on a computer, because a desktop hands the app a real folder it can read and write directly. Android and iOS hand an app no folder at all: every file reaches an app through the system's own document layer, one grant at a time, so reading a whole tree and saving back into it is separate work on each platform and it is not built yet.

On a phone you can bring the same files in as copies: Settings > Import & Export > Import > "Markdown files" takes .md and .txt one at a time or as a .zip, and a zipped folder keeps its subfolders, images and attachments. They arrive as encrypted notes that sync to your other devices, and Export writes clean .md back out. The originals stay on your disk exactly where they are.

Is the editor Markdown-friendly?

Yes. Type Markdown and it formats live: # headings, bold, lists, - [ ] task checkboxes, quotes, and callouts. Notes export as clean Markdown too, so what you write stays portable.

You can also connect notes to each other: type [[ and an autocomplete offers your existing notes. A note-link opens its target with one click, and the outline panel plus find-in-note keep long documents navigable.

Which Markdown syntax does the editor understand?

Standard Markdown formats live as you type: headings, emphasis, strikethrough and highlight, bulleted and numbered lists, task lists (Tab and Shift+Tab nest any list, checklists included), quotes, dividers, inline code and code blocks with syntax highlighting, inline and block math (KaTeX), and note-links between notes with autocomplete.

The formatting toolbar and its Insert menu add the rest: tables, callouts that can fold closed, underline, superscript and subscript, text alignment, text and highlight colors, fonts, links, images, and file attachments. Everything round-trips as Markdown: "Show markdown" below any note reveals the raw source, and exports are clean .md files, so nothing you write is locked into a proprietary format.

// See it in action

Headings

# Planning
## This week
### Monday

Planning

This week

Monday

Inline formatting

**bold**, *italic*, ~~done~~,
==marked== and `inline code`

bold, italic, done, marked and inline code

Task list

- [x] Derive keys on the device
- [ ] Trust a server
Derive keys on the device
Trust a server

Nested lists

1. Write your phrase down
2. Store it offline
   - paper beats cloud
   - two copies, two places
  1. Write your phrase down
  2. Store it offline
    • paper beats cloud
    • two copies, two places

Callouts

> [!info] Zero-knowledge
> The server stores only ciphertext.

> [!warning] No resets
> A lost phrase cannot be recovered.
Zero-knowledge

The server stores only ciphertext.

No resets

A lost phrase cannot be recovered.

Table

| App | Can read your notes |
| --- | --- |
| PrivacyNotes | No |
| Typical cloud notes | Yes |
AppCan read your notes
PrivacyNotesNo
Typical cloud notesYes

Code block

```js
// keys never leave your device
const keys = deriveKeys(phrase);
```
// keys never leave your device
const keys = deriveKeys(phrase);

Superscript, subscript, underline

H<sub>2</sub>O and E = mc<sup>2</sup>,
<u>underline</u> included

H2O and E = mc2, underline included

Math (KaTeX)

$e^{i\pi} + 1 = 0$

eiπ + 1 = 0

Quote and note-link

> Privacy is a feature, not a setting.

Ideas live in [[Second brain]]
Privacy is a feature, not a setting.

Ideas live in Second brain

Divider

Quick capture

---

Polished later

Quick capture


Polished later

How do tasks work?

Any line you write as - [ ] in any note becomes a task, and the Tasks view in the sidebar collects them all in one place. Checking a task off there updates the note it lives in, and opening a task jumps to that note. There is no separate task database to maintain: tasks are just lines in your notes, encrypted like everything else.

The quick-add box at the top of Tasks appends to a note called Quick Tasks (created for you on first use), so capturing a stray to-do takes one keystroke, not a filing decision. The same view offers three layouts (Hybrid, Aggregated, List), a completed-tasks toggle, and task search, and the New button on the All view can start a task note directly.

How does the journal work, and what can I track?

Journals is a dedicated view for dated entries: one tap creates today's entry, and the calendar button next to it backfills a recent day you missed. An entry is a normal note plus optional trackers: mood on a 1-10 scale with 24 emotion tags, sleep, activity, medications, energy, focus, and more. "Configure trackers" inside any entry toggles the built-ins, and Pro adds up to 10 custom trackers (scales, numbers, yes/no).

Statistics (in Settings, or the stats icon in the footer) turns entries into trends under the Wellness tab: mood over time, sleep and activity charts, medication adherence. Exports are generated on your device: "Download JSON" is free, and Pro adds a "Doctor PDF" to bring to appointments, a copy-ready AI prompt for the chatbot of your choice, pattern insights, and a week in review. Tracker data lives inside the encrypted entry, so the server can read none of it.

Can I save my browser bookmarks in PrivacyNotes?

Yes. Bookmarks are a pillar in the sidebar, next to Notes, Tasks and Journals, and they are free on every tier. Paste a link into the quick-add bar to save one. To bring your existing ones across, export a bookmarks .html file from your browser, then drop it into Settings > Import & Export > Import > "Browser bookmarks". Chrome, Firefox, Safari, Edge, Opera, Brave and Vivaldi all hold the same file, and your folders and dates come with it. Safari wraps it in a .zip, which you can drop in unopened.

Your URLs never leave your device: we do not fetch the page behind a link, which is why a bookmark you add by hand carries its domain as the name until you type one. Site icons are the one exception, and you can switch them off. Export writes the same standard .html file, so your bookmarks leave as easily as they arrived (import guide).

Can I keep an address book in PrivacyNotes?

Yes. Contacts is a pillar in the sidebar, next to Notes, Tasks and Journals, and it is free on every tier. A contact holds names, numbers, emails, addresses, websites, dates, a company and a note. Tap a number to dial it, an email address to write one, or any row to copy it. Anything else your phone wrote into the file stays under Also in this file and is written back when you export.

To bring yours across, export a vCard (.vcf) from your phone, your Mac, or Google Contacts, then drop it into Settings > Import & Export > Import > "Contacts (vCard)". Import the same file again later and the people already there are matched rather than duplicated. Export writes a standard vCard back out, so your address book leaves as easily as it arrived (more on importing).

What should I keep in Bookmarks, Contacts and the Vault?

The parts of your life that do not belong in a browser profile or a phone address book. Bookmarks, Contacts and the Vault sit beside the ones your browser and your phone already sync to Google, Apple or Mozilla, and they hold what you would rather keep out of those. All three are free on every tier.

  • Links about health, money, law or a job hunt, on a computer you share with someone
  • Research for one topic, kept together instead of buried among thousands of browser bookmarks
  • The doctor, the lawyer, the landlord and the recruiter, kept out of an address book that syncs to iCloud or Google
  • A contact with the context around them: your notes, the dates, the file they sent you
  • Recovery phrases, license keys, safe codes and passport numbers, which are secrets but not logins
  • The few credentials you never want inside a browser extension

Each one is a row in the sidebar. If a row is missing, open the sidebar options menu above your tags and switch Show in sidebar on for it. You can bring your existing ones in from a file and take them out the same way (bookmarks, contacts, the Vault).

How do folders work, and do I need Pro for them?

Folders nest as deeply as you like and live in the sidebar. Browsing them is free on every tier. Creating one, renaming it, or moving a note into it ("New folder" and "Move to folder") is where Pro starts, so a free account can always read a structure it imported or built while on Pro. An "Unfiled" row lists every note that sits in no folder.

A note lives in one folder at a time, the way a file does. Reach for tags when something belongs in two places at once. The folder is stored inside the encrypted note, so the server sees your structure no better than it sees your text.

How do tags work?

Every open note has a tag row under the title. Type a word and press Enter, a comma, or #, and the tag becomes a chip. The sidebar lists every tag you use, and clicking one filters the list to those notes. You can rename a tag everywhere at once, favorite it so it pins to the top, or delete it, with or without the notes under it.

Tags and folders solve different problems: a note sits in one folder but carries as many tags as you like, which is what you want when something is both "work" and "invoice". Imports tag by source, so everything that arrived from another app lands with its own tag and is easy to find, or to clean up later.

How do I link one note to another?

Type [[ anywhere in a note and start typing a title. Pick a note from the list and it becomes a note-link you can click. If nothing matches, choose "Create" and the new note is made and linked in one step. The toolbar button "Link to another note" does the same thing.

Note-links live inside the note, so they export with it and travel with an import: an Obsidian vault keeps its links, and Evernote note links are converted on the way in. To find what points at a note, search its title: every note linking to it carries those words.

Can I change how the app looks?

Yes, in Settings > Appearance. Mode switches between Light, Dark and Auto, which follows your system. Text size has four steps and scales your writing surface only, so the interface around it stays put. View lays items out as a List or a Grid. Editor decides whether notes open Formatted or as plain Markdown.

Color themes are the one part behind Pro: the default theme is free and Pro unlocks the rest, in light and dark alike. Zen mode, which hides everything except your text, is Pro too (Cmd+Shift+F). Mode and text size stay on the device you set them on. Everything else follows your account to your other devices.

What keyboard shortcuts are there?

Press ? anywhere in the app for the built-in cheat sheet, also available under Settings > About. Shortcuts cover navigation, note actions, formatting, and views - and on Windows and Linux, every Cmd reads as Ctrl and Option as Alt.

// The full list

// Navigation

Focus search⌘K
Move down / up in the listJ/K
Previous note in the list⌘[
Next note in the list⌘]
Clear search / close note / exit selectionEsc

// Notes

New note⌥⇧N
Move note to trash⌘⌫

// Lists

Select several items⌘Click
Select a range (while selecting)⇧Click
Open in a tab (a middle-click works too)⌥Click
Close the tab⌥⇧W

// Editor

Find in note (press again to close)⌘F
Find and replace⌥⌘F
Toggle outline⌘⇧O
Insert link (while editing)⌘⇧K
Undo⌘Z
Redo (while editing)⌘⇧Z

// Formatting

Bold⌘B
Italic⌘I
Underline⌘U
Strikethrough⌘⇧S
Highlight⌘⇧H
Inline code⌘E
Superscript⌘.
Heading 1 to 6⌥⌘1–⌥⌘6
Normal text⌥⌘0
Numbered list⇧⌘7
Bulleted list⇧⌘8
Task list⇧⌘9
Increase indent (list or checklist)Tab
Decrease indent (list or checklist)⇧Tab
Blockquote⌘⇧B
Code block⌥⌘C

// Alignment

Center⌘⇧E
Align right⌘⇧R
Justify⌘⇧J

// View

Open settings⌘,
Toggle sidebar⌘\
Toggle light / dark mode⌘⇧L
Zen / Focus mode (Pro)⌘⇧F
Toggle this help?

On Windows and Linux, ⌘ is Ctrl and ⌥ is Alt.

Most shortcuts are ignored while you're typing in a text field, so regular keys like J and K still type J and K.

Printable cheat sheet
Is there a printable cheat sheet of the shortcuts?

Yes. The printable cheat sheet lays every shortcut out on a single A4 page in two columns, ready to pin next to your screen. It is generated from the same list the app itself shows, so it can never lag behind a release.

Open it and press the Print button (or Cmd+P / Ctrl+P). To keep a file instead of paper, choose PDF as the destination in the print dialog. The sheet is also linked above and below the in-app shortcut list under Settings > About > Hotkeys, and in the footer of this site.

Can I use my own AI agent to get help with PrivacyNotes?

Yes, and we built the help center for it. Every answer is published as one plain-text file at llms-full.txt, so an assistant reads the lot in one go. The box at the bottom of any help page copies a ready-made prompt: paste it into ChatGPT, Claude, Gemini, or whichever assistant you already use, and ask in your own language.

Sending you to a tool you already trust keeps us out of it entirely, and we never learn what you asked. A chatbot of our own would mean your questions landing on our servers, and questions about a notes app tend to carry the contents of the notes. This is separate from the app itself, which has no AI features at all (details).

Never paste your recovery phrase, your PIN, or the text of a note into an assistant. No answer requires them, the copied prompt tells the assistant to refuse them, and anything you type into someone else's chat box has left your device.

// Security & privacy

What can PrivacyNotes see about my notes?

Notes, titles, tags, and attachments are encrypted on your device before they reach the server. Under self-custody, which every phrase sign-up starts with, no decryption key exists on our side. Signing up with Google, Apple, or GitHub asks where your key lives and starts on "Keep it simple & convenient", which stores your phrase on our server, encrypted under a key of ours. In that mode, our server can decrypt the phrase and therefore your notes. Settings > Account > Key custody shows your current mode and lets you switch.

What we can see is the information needed to run the service: how much encrypted storage you use, how many devices you have linked, and sync timestamps. If you use only your phrase and have not connected a Google, Apple, or GitHub account, we do not know your email address.

Why a recovery phrase instead of a username and password?

It can feel backwards at first, but a single recovery phrase is the stronger construction. With a username and password, the username is not a secret (it shows up in every breach dump), so all the security rests on the password, and human-chosen passwords average maybe 30 to 40 bits of entropy. Your 12-word phrase is a guaranteed 128 bits, generated by your device, never chosen by a human, and never reused from another site.

There is also no password for us to lose. A password login means the server stores at least a password hash, which can be leaked, cracked, or phished. Under self-custody, your phrase never leaves your device: it derives your encryption keys locally, and the server only ever sees encrypted data. There is no hash to steal and no password reset flow for an attacker to abuse.

If typing 12 words feels clunky: you can save the phrase to your password manager with one tap (Settings > Security > Phrase), and signing in feels like any other login. Prefer a familiar flow? Sign in with Google, Apple, or GitHub works too: you still get a phrase under the hood, and you choose whether it stays on your device or we store it for you.

Can I choose my own balance between convenience and privacy?

Yes, deliberately. Not everyone is defending against the same threats, so the account model is a ladder rather than a single dogma. Every rung keeps your notes encrypted on your device; what changes is who holds the key and what we know about you.

The convenient end: sign in with Google, Apple, or GitHub and leave "Keep it simple & convenient" selected when asked, which is where that screen starts. We store your recovery phrase for you, encrypted at rest on our server, so a new device can open your notes after provider sign-in and an authenticator code if 2FA is enabled. In exchange we know the email behind that login, and our server can decrypt your phrase. Save your phrase in case you lose the provider account, and keep your 2FA backup key if you enable two-factor sign-in.

The middle: sign in with Google, Apple, or GitHub but pick "Maximum security & privacy". Your phrase never touches our servers and the encryption is fully zero-knowledge; new devices need the phrase or a QR scan from a device that is already signed in. We still necessarily know the email behind that login, but we could not read a single note even under compulsion.

The private end: skip the logins entirely and use only the 12-word phrase. No email, no name, no identity, and paired with an anonymous Pro purchase, even paying leaves no name anywhere. In exchange, key custody is entirely yours: lose the phrase with no signed-in device left, and nobody can help.

Settings > Account > Key custody shows both modes with their tradeoffs and lets you switch. Leaving server custody deletes our stored copy after you confirm three words from your saved phrase. Switching back uploads the phrase again and requires an explicit choice. Both directions are signed with your account key and need a fresh authenticator code when 2FA is enabled. A phrase account can connect a provider under Account > Accounts, then choose server custody separately; connecting the provider does not upload the phrase. Every mode can also use PIN app lock, biometric unlock and per-note protection.

Is a 12-word recovery phrase secure enough? Why not 24 words like Bitcoin wallets?

Yes, 12 words is enough. A 12-word BIP-39 phrase encodes 128 bits of entropy. Brute-forcing 128 bits is not a "needs a bigger computer" problem, it is a "more energy than humanity produces" problem. There is no realistic attack that breaks 128 bits but fails at 256.

The Bitcoin comparison actually shows why 24 words is mostly marketing: Bitcoin keys live on the secp256k1 curve, which itself only provides about 128 bits of security. A 24-word phrase feeds 256 bits of entropy into a lock that still only takes about 128 bits of work to break. That is also why many major wallets still default to 12 words.

PrivacyNotes targets the same 128-bit security level end to end: your phrase is run through a key derivation function, and the encryption it protects (XChaCha20-Poly1305) is keyed to match. Adding 24 words would double what you write down and type without adding any practical security, so we stay at 12.

What matters is where you keep the phrase, not how many words it has. Keep it in a password manager, type it nowhere else, and 12 words will outlive all of us.

Can someone guess my 12 words or end up with the same ones?

No. Nobody can guess your 12 words, and nobody else ends up with the same ones: no computer that exists, or that we can foresee, comes close. Only someone who gets your actual words can sign in, so keep them safe.

Your device picks your phrase at random, and the number of possible phrases has 39 digits. Guessing yours on the first try is less likely than winning a 1-in-300-million lottery jackpot four times in a row. A computer that tried a billion billion phrases every second would still need about 10 trillion years to try them all, far longer than the universe has existed. Even if all 8 billion people on Earth each had a phrase, the chance that any two of them match is smaller than winning that jackpot twice in a row.

The strength comes from that randomness, not from how the words look. Do not make up a phrase or add symbols to it: use the 12 words exactly as the app gives them to you. Capital letters do not matter. The last word works as a check, so the app refuses a mistyped or made-up phrase.

Can someone else get the same recovery phrase as me?

No, not in practice. Your device picks your phrase at random from a huge number of possible phrases. Even if every person on Earth made an account, two matching phrases would be less likely than winning a 1-in-300-million lottery jackpot twice in a row. The same numbers are why nobody can guess your phrase.

Your Account ID comes from the phrase. So if you delete an account and sign in again with the same 12 words, you get a new, empty vault with the same Account ID. Nothing from the deleted vault comes back. After you move to a new phrase, remove the old one from your password manager, so you never sign in to the old account by mistake.

How do I turn on two-factor authentication (2FA)?

Turn on optional two-factor sign-in in Settings > Security > 2FA. Update PrivacyNotes on your other devices first. Scan the QR code with an authenticator app, or enter the setup key manually. Save the 2FA backup key outside PrivacyNotes, confirm the saved copy, then enter a current code to finish.

After setup, a new server session needs your phrase or a connected provider, followed by an authenticator code. Self-custody users still need their phrase to decrypt notes. Manage provider accounts in Settings > Account > Accounts; connecting one does not change key custody.

If you lose the authenticator, add the saved 2FA backup key to another authenticator app. Losing both means we cannot restore server access. Notes already unlocked on a device remain readable and exportable. Two-factor sign-in does not add encryption or protect an already unlocked device.

Do you use the same word list as Bitcoin wallets (BIP-39)?

Yes, the standard BIP-39 English wordlist: 2048 words, the exact same list Bitcoin wallets use. We generate phrases with @scure/bip39, an audited open-source library. No custom wordlist and no homegrown crypto.

The list is designed for writing down by hand: the first four letters of every word are unique, so a smudged or abbreviated word is still unambiguous, and similar-looking words were deliberately excluded.

Because it is the standard list, you can verify your phrase against any public BIP-39 reference, and our encryption code is open source so you can check the implementation yourself.

Does searching my notes send anything to your servers?

No. Search runs against a full-text index built and stored on your device. Queries never leave it, results appear even with no connection at all, and nothing about what you search for is ever transmitted.

This is not a policy choice we could quietly reverse, it is forced by the architecture: the server only holds ciphertext, so there is nothing readable on our side to index or search. A server that cannot read your notes cannot search them either.

Does PrivacyNotes use AI on my notes?

No. There are no AI features in the app, no AI processing running in the background, and no model training on your content. Your notes are always encrypted, on your device and on the way to the server, so there is nothing readable on our servers to feed into anything.

If we ever ship a feature in this direction, it would have to run entirely on your device and be strictly opt-in. Sending plaintext notes to a cloud model would break the zero-knowledge promise, so it is off the table.

What are burn notes?

A burn note is a self-destructing way to share a note with someone who does not use PrivacyNotes. The app encrypts the content with a one-time key and gives you a link. The key travels in the link fragment, which browsers never send to servers, so our server stores ciphertext it cannot read.

The first time the link is opened, the server hands over the ciphertext and deletes it in the same step: one read, then it is gone. Unopened links expire on their own after the time the sender picks, from 1 hour to 7 days. Either way, nothing lingers.

Can I share a note with someone else, or work on one together?

Send a burn note: it turns any note into a one-time encrypted link that is destroyed the moment it is read, which covers handing over a password, an address, or a draft. For something the other person keeps, export the note as Markdown, HTML or PDF and send them the file.

A note two people edit live is a different product: it would mean the server handing keys between people, and keeping the server out of your keys is the whole design here. One account is one person with one phrase, which is what makes "we cannot read your notes" a fact rather than a policy.

What is the difference between read-only and PIN-protected notes?

"Read-only" (in the note options menu, Pro) locks a note against edits so a finished document cannot be mangled by accident; it hides nothing. "Protect" (same menu, Pro) hides a note's contents behind your PIN or biometric unlock, for the things you would rather not have visible on a screen others sometimes see. Its title stays visible in the list, so keep the secret out of the title.

Both are on-screen gates rather than a second layer of encryption. The flags travel inside the note's own encrypted data, and the note is deliberately not re-encrypted with your PIN, so a forgotten PIN can never destroy data. The phrase stays the real boundary: protect it first, and use these gates for the screen that other people sometimes see.

Biometric unlock stopped working. What can I do?

You are never locked out. The lock screen always offers a fallback: "Unlock with PIN", or "Sign in with recovery phrase". The biometric is a local gate, not an encryption key, so your notes are untouched either way.

Then fix the gate. Enrollment is per-device, so a new phone, a fresh browser profile, or a reinstall needs re-enrolling: Settings > Security > "Lock", disable, then "Enable biometric unlock" again. It also requires "Trust this device" (untrusted sessions clear when the tab closes) and hardware with a platform authenticator (Touch ID, Face ID, Windows Hello). If a password manager like Bitwarden or 1Password pops up instead of the system prompt, dismiss it and retry, or turn off its passkey capture for the site - the app requests the built-in authenticator, but some managers intercept anyway.

Is PrivacyNotes open source?

Yes. The web, desktop, and mobile apps are published on GitHub, together with the encryption code that scrambles your notes and the threat model spelling out what each piece protects. It is the same code our releases are built from.

That is what turns a promise into something you can check. Read the encryption in one sitting, open your browser's network tab and watch your own notes leave as unreadable text, or build the app yourself and compare it against what we ship. You do not have to take our word for any of it.

I found a security vulnerability. How do I report it?

Email privacynotes@lifetimelabs.dev. The same address is published in our PGP-signed security.txt, so you can confirm it is genuine before you write, and our public key is there if you would rather encrypt the report.

We reply, and where a fix needs coordinating we agree the disclosure timing with you before anything goes public. Reports reach the people who wrote the code directly, and a reporter who wants credit gets it. Test against the demo at try.privacynotes.app or a throwaway account, never against somebody else's notes.

// Account & recovery

I lost my recovery phrase. Can you recover my account?

If you are still signed in on any device: yes, you can recover it yourself. Open Settings > Security > Phrase and save it to your password manager right now.

If you have no signed-in device and no phrase, it depends on who holds the key. If you let us store it when you signed up with Google, Apple, or GitHub, sign in with that login and you are back in. Under self-custody, nobody can: your phrase never reaches our servers, so there is nothing to reset and no support ticket that can help. Any service that can restore your encrypted data after a total loss is holding your keys.

The fix costs ten seconds: store the phrase in a password manager the day you create your account. If it is already gone and you pay for a storage add-on, Paddle bills you directly and can cancel it without your phrase: see changing or cancelling an add-on.

I lost my 2FA codes. How do I get back in?

Add your 2FA backup key to any authenticator app, then enter the code it shows when PrivacyNotes asks for one. The backup key is the one you saved when you turned on 2FA, and it works every time you need it.

If you lost both your phone and the backup key, we do not reset 2FA, and our support cannot help with it. The notes already on your devices stay readable.

To keep them, go to Settings > Import & Export > Export on a device that still has them. Then create a new vault and import the export there.

I sign in with Google, Apple, or GitHub. What if I lose access to that account?

You still have a 12-word phrase under the hood, and the phrase alone signs you in on any device - no Google, Apple, or GitHub account required. Open Settings > Security > Phrase and save it to your password manager.

Do that once and losing that account costs you nothing: just sign in with the phrase instead.

My recovery phrase leaked. What do I do?

Treat the vault as burned. A phrase cannot be changed or rotated, because the phrase is the key everything is encrypted under - so the fix is moving to a fresh vault. First, in the old account, export everything: Settings > Import & Export > Export > "PrivacyNotes backup (.zip)".

Sign out, create a new vault (new 12 words), and bring the export back in via Settings > Import & Export > Restore > "Full backup (.zip)". Then delete the old account from any device still signed into it: Settings > Account > "Delete account & data...". That removes its synced data and shuts out anyone holding the old phrase. If you signed in with Google, Apple, or GitHub, delete the old account first, then sign in with that same login again to start the fresh vault.

Two things to handle first: cancel any active storage add-on, which deletion requires, and note that Pro stays with the account it was bought on rather than moving to the new vault. Then keep the new phrase in a password manager and nowhere else, which is the whole of the prevention.

I lost a device. How do I protect my notes?

From any signed-in device, open Settings > Account > "Registered devices" and remove the lost one. The next time that device comes online it is signed out and its local data is wiped, within about a minute of its next use. It stays listed under "Recently removed" for 72 hours so you can confirm it is gone.

Set the app lock (PIN or biometric) on anything portable, and keep your OS screen lock on. A device wipes when it next reconnects, so those local gates are what stand between a lost phone and your notes until then. The phrase is the real key: anyone holding your 12 words can sign in again, so if you suspect the phrase itself leaked, follow the phrase leak playbook instead.

I forgot my PIN. How do I get back in?

Nothing is lost, and you can clear the PIN yourself with your recovery phrase. The PIN is a screen gate rather than an encryption key: your notes are encrypted with keys derived from the phrase, so the phrase is what opens them. Tying encryption to four digits would mean a forgotten PIN destroyed data, and it never does here.

Wherever the app asks for the PIN, choose Forgot your PIN? and type your 12 words. It is on the lock screen, on a protected note, and in Settings > Security > PIN. The PIN clears on every device, and you can set a new one straight away. Biometric unlock is not affected.

How do I delete my account?

In the app: Settings > Account, then "Delete account & data". This permanently removes your synced notes, files, devices, settings, and the account itself from the server. There is no retention window and no backup we could restore afterwards, so export anything you want to keep first (Settings > Import & Export).

Two details: an active storage subscription must be cancelled before deletion (one already scheduled to cancel does not block it), and because a phrase account never included an email or a name, there is no profile or marketing list left to scrub. Wiping the local data on one device is a separate action and does not touch your account.

// Sync & devices

How do I sign in on a second device?

On the device you already use, open Settings > Security > Phrase. It shows your 12 words and a sign-in QR code. On the new device, choose "Phrase login", then scan that QR with the camera, upload a photo of it, or type the words in. Your notes arrive within seconds.

A free account covers 2 devices and Pro covers as many as you like, and two browsers on one computer count as a single device. Treat the QR exactly like the phrase it carries: show it to nobody, and never let it land in a photo library that syncs to somebody else's cloud.

What exactly syncs across my devices, and what stays local?

Everything you would expect, and all of it encrypted on your device: notes, tasks, journal entries, your vault, and the files in it. Your settings follow you too - favorite tags, sort and view preferences, color theme, your PIN (as a salted hash, never the PIN itself), app lock, tracker and medication setup, and trash auto-delete. Set something up once and every device picks it up.

A few things stay deliberately device-local: light or dark mode (each device follows its own system preference), biometric unlock (tied to the hardware of each device), and your unlock state (closing the app always re-locks). The server only ever stores encrypted blobs and can read none of it.

Does PrivacyNotes work offline?

Yes. The app is local-first: your notes live in a database on your device, so reading, writing, and search all work with no connection. Changes sync automatically when you are back online, and a picture or file you add offline waits on this device and uploads then too.

Can I stop a device from syncing without signing out?

Yes. Open Settings > ID & Sync and press "Pause sync". That device stops sending anything to the server: notes, settings and files alike. You keep writing exactly as before, everything queues locally, and the moment you resume it all goes up.

The pause belongs to that device alone. It does not travel to your other devices and it never clears itself, because a switch that says "this device talks to nobody" must not be turned back on by anything except you. One thing keeps running on purpose: the small heartbeat that lets a removed device learn it was removed, which is how a lost device still wipes itself.

Can I stop the app from uploading files over mobile data?

On Android, yes. Open Settings > ID & Sync and turn on "Files on wifi only". Your notes keep syncing on any connection, because text is tiny. Only images and attachments wait, and they go up the moment wifi comes back rather than sitting out the next retry.

Android is where the switch lives, because Android is the one platform whose app view reports wifi against cellular reliably, and a switch that guesses is worse than no switch. On a metered connection anywhere else, "Pause sync" does the same job with a bigger hammer and works everywhere.

What happens if I edit the same note on two devices at once?

Your devices merge the note detail by detail when they sync again, so a change made on only one of them is kept. If both edited the text while apart (say, one was offline), the device that syncs second shows a conflict dialog: keep the version on this device, keep the other one, or keep both as separate notes. Both versions are kept until you choose.

When both devices changed the same detail while apart, such as a pin, a folder or the title, the detail from the device that edited the note last is kept, without a dialog. A note deleted permanently on one device is deleted everywhere, including an edit another device made to it while apart.

How do I remove a device I no longer use?

Settings > Account lists every registered device. Remove the one you are retiring: the slot frees up immediately (useful on the free 2-device plan), and the removed device is signed out the next time it tries to sync. It stays visible under "Recently removed" for 72 hours so you can confirm it is gone.

Removal frees the slot and signs that device out; the phrase is what controls access. Anyone holding your 12 words can sign in again, so if a device was lost or stolen, protect the phrase first and keep the app lock (PIN or biometrics) on. That is what keeps a found device from being an open door.

What does "Device limit reached" mean?

Free accounts sync on up to 2 devices, and this dialog appears when a third tries to register. Remove a device you no longer use directly in the dialog, or on an existing device under Settings > Account (how removal works). The slot frees immediately, and the removed device stays visible under "Recently removed" for 72 hours. Pro lifts the cap entirely.

Several browsers on one computer count as a single device: they are grouped using privacy-preserving hashes of coarse machine signals, computed on your device with a per-account secret. A major browser update, or a hardened browser like Brave or Tor that randomizes those signals, can land the same machine in a new slot. Remove the stale entry and carry on. You are never locked out.

What happens when I go over my storage limit?

Nothing is ever deleted. When new changes stop fitting, sync says so: "Storage full. Some notes couldn't sync." Existing data keeps syncing, new growth does not. If you stay over the cap, a 90-day countdown starts, shown as an amber banner. Reading, editing things smaller, deleting, and exporting all keep working the entire time.

After 90 days over cap, sync pauses: the banner turns red ("Sync paused. You've been over your storage limit for 90+ days."). The app still works fully on every device; changes just stay local until you are back under. Recovery is instant and self-serve: free up space - emptying the trash counts - or add storage under Settings > Storage, and sync resumes on its own. This is the deliberate opposite of services that auto-delete over-quota data.

// Your data

Where is my data stored?

On your device first, and that is the copy you work with: the app is local-first, so your notes open and edit offline. The synced copy lives on servers in Zurich, Switzerland. What sits there is your public key, encrypted blobs of your notes, files and settings, plus the timestamps and sizes a sync needs. No titles, no text, no tags.

The country matters less than the encryption does. Everything is always encrypted, on your device and on the way to the server, so that copy would be unreadable wherever it sat: Switzerland is a bonus, not the promise. What syncs lists it item by item.

The copy on your device is encrypted too. Notes are sealed on disk under a key derived from your recovery phrase when you unlock, so a copy of the app's storage on your device, or a stolen backup of it, carries ciphertext rather than your notes.

Where on my disk does the app store my notes?

In one folder per install, inside your account's app-data area. Where that folder is depends on the platform:

  • macOS: ~/Library/WebKit/app.privacynotes/WebsiteData/
  • Windows: %LOCALAPPDATA%\app.privacynotes
  • Linux: ~/.local/share/app.privacynotes, or app.privacynotes.appimage for the AppImage, which bundles its own web engine and so keeps its own profile
  • Android, iOS: the app's private storage, which no other app can open
  • Browser: your browser profile, under use.privacynotes.app

What sits there is ciphertext. Each note is one sealed blob holding the title, body and tags, opened by a key derived from your recovery phrase when you unlock, so a copied folder carries nothing readable. Only what the local index needs stays in the clear: ids, timestamps, the kind of item, and flags such as pinned or deleted.

To move your notes to another device, or to keep a copy of your own, use Settings > Import & Export > Export and pick "Encrypted full backup (.pnbackupz)". It holds everything, it is encrypted with your phrase key, and it restores with your phrase on any device. More on backups.

Can I export my notes, or am I locked in?

You can export everything at any time, generated entirely on your device: Markdown files in a zip with attachments included, plain JSON, or self-contained HTML - per note or for the whole account. The zip is the "PrivacyNotes backup (.zip)", and it restores, as the encrypted backups do; JSON and HTML are for reading and for your next app. Vault items get their own route, "Vault export (.json)", which writes Bitwarden's format and carries your usernames, passwords, URLs, card details and 2FA keys into Bitwarden, 1Password or KeePass.

It all sits under Settings > Import & Export > Export. Import runs the same way, from Obsidian, Evernote, Apple Notes, Standard Notes, Bitwarden and more: the full list is in moving in from another app. Lock-in is not part of the business model.

Can I print a note or save it as a PDF?

Yes. Right-click a note, or open its share menu, and choose "Print / Save as PDF". Your system print dialog opens, so you can send it to a printer or save a PDF from there. The page renders clean on white with your formatting intact, whatever theme you use in the app.

It is generated on your device like every other export, so nothing is uploaded to produce it. For several notes at once, select them and export as HTML: you get one printable page per note. The "Doctor PDF" under Statistics is a separate, purpose-built wellness report and needs Pro.

What is the best way to back up my notes?

Export "Encrypted full backup (.pnbackupz)" under Settings > Import & Export > Export. It encrypts everything - notes, journals, vault items, tasks, images, audio, and files - with your phrase key, so it is safe to park on a cloud drive or a USB stick, and it restores with your phrase on any device.

It opens with the phrase that made it, so keep a "PrivacyNotes backup (.zip)" alongside it if you ever move to a new phrase: same contents, restores into any vault, and readable on disk, so store it somewhere you trust. "Encrypted backup (.pnbackup)" covers text and metadata rather than images and files, and "Text backup (.json)" and the HTML archive are portability formats rather than restore formats.

Why keep local backups when everything syncs? Sync is not a backup: it faithfully propagates deletions, including a compromised server dropping data that your devices then mirror. A copy on your own disk is the one no server event can touch. Export before big imports, before leaving, and on a rhythm you will keep.

How do I restore a backup?

Open Settings > Import & Export > Restore and pick the format you have. "Full backup (.zip)" takes the complete export: notes, journals, vault items, tasks, images, audio, and files. "Encrypted backup (.pnbackup, .pnbackupz)" takes either encrypted export. Your file is read and decrypted on your device, and restoring is free on every tier.

A restore matches notes by id. A note you already have is updated only when the backup's copy is newer, a note in your trash comes back out, a note you lack is added once, and restoring the same file again changes nothing unless you edited a restored note in between, which brings the older copy back beside your edit. A file with no ids of ours, from another app or from a backup made by an older version of this one, adds its notes as new ones every time. Both encrypted formats open only in the account that created them, because they are encrypted with that account's phrase key, while a .zip restores into any vault (which backup to make).

What happens if I clear my browser data or cookies?

The web app keeps your notes in your browser's own storage, so clearing site data for PrivacyNotes wipes the local copy and signs you out. Everything that already synced is safe: sign in with your 12-word phrase and it comes back. Anything that had not synced yet is gone, because we never had a copy of it.

So do two things. Check that the footer says "Synced" before you clear anything, and keep your phrase in a password manager, because a cleared browser cannot ask you nicely for it. The desktop and mobile apps are not affected at all: they keep their own storage, which a browser cleanup never touches.

Are my notes included in my Android phone backup?

No. The Android app keeps its data out of the phone's cloud backup, so none of it reaches Google Drive. The reason is the key, not the notes: where you chose Trust this device, your 12 words are held on that device to keep you signed in, and a cloud backup is no place for the key that decrypts your notes.

A new phone therefore starts empty: install the app, sign in with your 12 words, and everything that synced arrives. Restore waits for that first sync, so a backup you bring is matched to what the account holds rather than added twice. What never synced lives only on the old phone, so check the footer reads "Synced" first, or carry a "PrivacyNotes backup (.zip)" from Settings > Import & Export > Export (which backup to make).

A direct phone-to-phone transfer at setup is different: some phones move app data across, and Android gives an app no dependable way to refuse. That copy never leaves your two devices, so wipe the old phone afterwards.

What counts against my storage, and how do I free space?

Everything you sync, at its encrypted size: note text, images, audio recordings, and file attachments. The bar under Settings > Storage shows the total; each note's own footprint is listed in its note options as "Storage used". Trashed notes still count until the trash is emptied.

To free space fast, open Files, sort by Size, and delete the biggest items - attachments dwarf text in almost every account. Then empty the trash: the Trash view shows how much space "Empty" will free. Text alone almost never fills a quota; even the free 50 MB holds tens of thousands of plain notes.

I deleted files but my storage did not go down. Why?

Your space is already free. The moment the delete syncs, those bytes stop counting against your quota, on the server as much as on this device. If the bar still shows the old figure, press the refresh icon beside it: that recounts from the server and leaves out everything queued for deletion. A device that was offline keeps its own last count until it catches up.

The "few days" the app mentions is about the encrypted file itself, not about your quota, and that wait is deliberate. Deleting a file from storage is permanent, with no trash to fish it back out of. A device that has not finished syncing holds an incomplete picture of your notes, so it could delete an image that another note still shows. A file therefore waits at least 24 hours, and only a device that has completed a clean sync removes it. The patience costs you nothing, because the space was credited the day you deleted.

Does PrivacyNotes change or compress my images?

Yes. Both settings are on by default because we love our users: we want you to save storage space and keep your privacy. Space saver shrinks a large image to fit 2048 pixels and saves it as JPEG at 85% quality, which keeps all the detail a screen can show. Remove location data strips the EXIF metadata a camera writes into a photo, including the GPS location, before the image is saved. Both apply to every image in the app: pasted into a note, added as a file, or imported.

Turn either off under Settings > Images, where contact photos have a third switch that keeps them at 512 pixels. The settings apply to new images only; files that are not images are stored exactly as they are. HEIC and TIFF images are converted to JPEG, because only Safari can show them. A backup you restore is written back byte for byte.

What files can I attach, and how big can they be?

Any file type: images, PDFs, audio, archives, whatever you drop in. Every file is always encrypted, on your device and on the way to the server, exactly like note text, and the Files view collects all attachments in one place.

The per-file limit is 5 MB on the free plan and 50 MB on Pro. Files count against your total sync storage (50 MB free, 500 MB on Pro, expandable to 5.5 GB with storage add-ons), and the storage bar in Settings > Storage always shows where you stand.

Why did my file upload fail?

The error names which ceiling you hit. Per file: 5 MB on Free, 50 MB on Pro, 100 MB with any storage add-on. In total: everything you sync must fit your account's storage (50 MB Free, 500 MB Pro, more with add-ons), so a full quota fails an upload even when the file itself is small. Any file type is accepted.

Check the storage bar in the Files view or under Settings > Storage, then pick the cheapest fix: free up space, upgrade, or shrink the file (phone photos are often multi-MB originals; a compressed JPEG is a fraction of the size). An upload that fails for want of a connection is kept, not lost: the file stays on this device and goes up by itself once you are back online, and Settings > ID & Sync counts it as waiting until then.

Why did notes disappear from my trash?

Trash is not an archive: by default, anything in it is permanently deleted after 30 days. The switch sits in the Trash view itself, labeled "Auto-delete after 30 days" - turn it off there if you want trash kept forever, and the setting syncs to all your devices. The cleanup runs on your device when the app opens, because the server cannot see which encrypted notes are trashed.

Permanently deleted means gone: no device and nobody on our side can bring it back, only a backup you made earlier. If you use trash as a someday-maybe pile, disable auto-delete or restore notes before day 30. Until then, trashed notes still count toward your storage - "Empty" in the same view frees that space immediately.

Can I get an older version of a note back?

Yes, with Pro. Open the note's "..." menu and choose "Note history" to browse and restore up to 20 previous versions. Restoring loses nothing: the current text is saved as a version first, so you can step back and forth. Versions are encrypted like the note itself, so we cannot read them either.

A snapshot is taken at most once a minute, so two edits seconds apart share one version. Note history is the one Pro feature that runs through the server, which is why the demo keeps its own local copy instead. Every tier has the trash as well, which holds a deleted note for 30 days.

What is the Vault?

The Vault is a dedicated section for structured secrets: logins with usernames and passwords, credit and debit cards, and SSH keys. Entries get proper fields instead of free text, logins display a site icon, and everything is encrypted on your device like the rest of your data.

It gives the handful of credentials that otherwise end up scattered across notes a tidy, protected home. Pair it with the app lock and PIN protection for a second gate on your most sensitive entries. A Bitwarden import lands here automatically.

Can the Vault store my 2FA authenticator keys (TOTP / MFA codes)?

Yes. A Vault login has a "2FA code" field that accepts either a base32 secret or a whole otpauth:// link, and a Bitwarden import carries existing keys across. The key is encrypted, saved and synced on every tier, free included. Pro turns it into the live rotating code with its countdown, so you do not need a second app open beside this one.

A password and its one-time code in the same vault means one unlocked device holds both factors, which is the trade every password manager with built-in codes makes. For most accounts the convenience wins, especially with the app lock or a PIN in front of it. If you would rather keep the two factors apart for your email or your bank, put those codes somewhere else and let the vault carry the rest.

How long can a single note be, and what do the size warnings mean?

Type as much as you like - for normal notes, size never comes up. As a single note grows very large, a small hint appears beneath it and escalates in three steps: around 50,000 words it notes the note is getting long and may lag on slower devices; around 75,000 words it turns amber, meaning editing may start to stutter; and around 100,000 words it suggests splitting the note because you are nearing the sync limit. These are guides, not hard stops, and nothing prevents you from continuing.

That sync limit is the only real ceiling. A single note can hold up to about 1 MB of text once encrypted - very roughly 120,000 words of typical English, and fewer with a non-Latin script or heavy formatting. A note past that keeps working and stays safe on the device you wrote it on, but that one note will not sync to your other devices (you will see a "failed to sync" notice). The rest of your notes are unaffected: one oversized note never blocks anything else.

The fix is easy: split a very long note into a few smaller ones. The content is identical, it syncs without trouble, and the editor stays fast. A live word count under each note lets you watch the size as you go.

How do I leave PrivacyNotes completely?

Export first, delete second - both self-serve. Settings > Import & Export > Export covers every exit route: "PrivacyNotes backup (.zip)" for a complete copy, portable Markdown and HTML for your next notes app, and "Vault export (.json)" in Bitwarden-compatible format for your next password manager. Exports are generated on your device.

Then Settings > Account > "Delete account & data...": type DELETE, and your synced notes, files, devices, settings, and the account itself are permanently removed with no retention window (details). An active storage add-on must be cancelled first under Settings > Storage. A phrase-only account leaves nothing behind to scrub, because we never knew who you were. No dark patterns and no win-back emails - your data is yours, including on the way out.

How does PrivacyNotes handle GDPR and my data rights?

Mostly by holding as little as possible. Sign up with a phrase and there is no name, email, or identity on file to request: your data is ciphertext under a random public key, hosted in Zurich, Switzerland. Sign in with Google, Apple, or GitHub and exactly one identifier exists - the email behind that login, linked to that key. Billing details for Pro live with Paddle, the merchant of record, not with us.

Every right is self-serve and immediate, no request form needed: access and portability are Settings > Import & Export (full export in open formats), erasure is Settings > Account > "Delete account & data..." with no retention window, and rectification is editing your notes. The formal version, including how to reach us for anything the app cannot do itself, lives in the privacy policy.

Do you record which website I came from?

Yes, and it is about advertising. We buy placements on other sites and pay creators, so we need to know which ones actually bring people. Wasted advertising money is a cost the product carries either way, so we measure it in the smallest form that answers the question.

The marketing website counts the clicks on our links as totals, by link and country, without any identifier: no cookie, no visitor record, no third-party script. If you create an account, it stores two short words from a published list: which link you arrived from, if there was one, and how you installed the app, such as “android-play”.

Both words are written once when the account is created, never updated, and deleted with your account. Nothing else about your arrival is kept. If you close the tab before signing up, or your browser strips the link, no word is stored. The apps carry no analytics of what you write, no pixels and no third-party trackers: open your network tab and check.

What happens to my notes if PrivacyNotes shuts down?

You keep them. Your notes, tasks, journal entries and vault items live on your device because the app is local-first, and exporting them to Markdown, JSON, or HTML works offline. A picture or file stays on a device once you add or open it there, and one this device never opened is fetched when you open it, so keep a full backup: it fetches every picture and file this device lacks, and says so if one cannot be fetched.

The encryption code is open source too, so the format stays independently readable even in a world where our servers vanish overnight.

// Pricing & Pro

What is free and what is Pro?

Free is the full product, not a teaser: notes, tasks, journal, and vault, all encrypted on your device, offline use, import and export - on up to 2 devices with 50 MB of sync storage.

Pro is a one-time purchase that adds unlimited devices, 500 MB of sync storage (expandable), note version history, larger file attachments, note locking and PIN protection, advanced wellness tracking, zen mode, and all color themes.

How can a one-time payment fund a sync service forever?

Because the service is deliberately cheap to run. The app is local-first and notes are small encrypted blobs, so the server does little more than store them and relay them between your devices. No analytics of what you write, no pixels or third-party trackers, no AI features burning compute, no support department.

The one cost that does grow over time is storage, and that is priced accordingly: storage beyond the included 500 MB is a small yearly add-on. One-time costs are priced once, recurring costs recur. The model only has to pay for itself, and it does.

I bought Pro on one platform. Do I have it everywhere?

Yes. Pro is attached to your account, not to a device, platform, or store. Buy it once, sign in with the same phrase (or the same Google, Apple, or GitHub login) anywhere, and Pro is active there too.

That includes platforms that do not exist yet: when a new app ships, your existing Pro comes along at no extra cost.

Can my family share one account or one Pro purchase?

Two accounts is the answer, and starting a second one costs nothing: each gets 2 devices and 50 MB free. An account is one 12-word phrase, and whoever holds that phrase holds everything in it: every note, every vault entry, on every device. Separate accounts is what gives each person their own private notes. Pro is bought per account.

To hand over one specific thing, send a burn note rather than your phrase. A shared household account works fine if that is genuinely what you want: keep the phrase in a shared password-manager entry, and treat anyone who has ever held it as having seen everything in it.

My recovery phrase leaked. Do I lose Pro?

Pro stays with the account you bought it on, and your recovery phrase is the only key to that account. If the phrase leaks and you move to a new vault, Pro does not move with you, and nobody can move it by hand, us included. The app says this at sign-up and again before you sign out: the 12 words are the only way in.

If you bought Pro in the last 30 days, you can get a full refund and buy again on the new vault. Each refund costs us payment fees, so please keep it for a real leak. The steps to move your notes and close the old vault are in what to do when your phrase leaks. Keep the new phrase in a password manager, and type it nowhere else.

Can I use PrivacyNotes at work, and is there a team plan?

You can use it at work, and plenty of people do. It is a single-person tool by design: your own account, your own phrase, your own Pro purchase, with each person on a team holding their own key. There is no shared workspace, admin console or central billing.

Weigh that before you standardize on it. Zero-knowledge encryption means the notes belong to the person who wrote them, which is exactly what a journalist, a lawyer or a consultant wants, and it is why an organization that needs key escrow or audit logs runs those on a system built for them. For an individual professional it is the strongest position available: nobody can be compelled to hand over what nobody can read.

I paid for Pro but it is not active. What now?

Give it a minute, then reload the app. After checkout the app polls for about 20 seconds and unlocks by itself, and a reload re-checks Pro status on launch. If the payment landed but activation lags, a banner says "Payment received but Pro activation is taking longer than usual" - that state resolves itself in nearly all cases. In store builds, a purchase that fails to validate retries when you restart the app, and a purchase that never activates is refunded by the store automatically within 3 days.

Still locked? It is almost always an account mismatch: Pro attaches to the account that was signed in at purchase, so a different phrase - or a Google, Apple, or GitHub login instead of your phrase vault - is a different account. Compare the Account ID under Settings > ID & Sync on the device that bought it. If it is genuinely stuck, report it and include that Account ID: it identifies the purchase and reveals nothing about your notes.

How do storage add-ons work?

Pro includes 500 MB of encrypted sync storage. If you need more, add-on packages stack on top: 1 GB for $4.80 per year, 2 GB for $8.40, or 5 GB for $18, up to 5.5 GB in total. Add-ons are the only recurring purchase in the product, because storage is the only thing that costs us money every month you use it.

Everything is managed under Settings > Storage: switch to a bigger package (you pay only the prorated difference) or cancel anytime and keep the space until the period you paid for ends. Pro itself is yours forever either way.

How do I change or cancel my storage add-on?

Settings > Storage is the control panel. Upgrading to a bigger package applies immediately. On the web, the confirmation shows the exact prorated amount charged today before you commit, and the renewal date does not move; in the Play Store and the App Store the store's own sheet shows the charge, and Apple refunds the unused part of your current year and starts a new one. "Cancel storage" keeps your extra space until the end of the period you already paid for. To move to a smaller package, cancel the current one and buy the smaller one when the period ends.

If your data still fits the remaining cap after expiry, that is the end of it; if not, nothing is deleted and the 90-day over-quota lifecycle begins. A failed renewal shows a banner with an "Update card" link to fix payment in Paddle.

Cancelling from outside the app works too, which is the answer when you cannot sign in. Paddle is our merchant of record and bills you directly: use the "Manage Subscription" link in your receipt email, or the support chat at paddle.net. A store build is the same idea, so cancel there in the store's own subscription settings.

Do purchases carry over between the web, Google Play, and the App Store?

Yes. Pro and storage attach to your account, not to a platform or store. Buy on the web and every app you sign into is Pro, including store builds; buy inside a store build and the web and desktop apps unlock the same way. Signing in is the restore, because the entitlement follows the account. A store build carries a Restore purchases button under Settings > Account as well, which asks Apple or Google what you own and unlocks it again after a reinstall.

The one difference is who bills you. Web purchases run through Paddle and are managed in the app under Settings > Storage. Purchases made inside a store build (the App Store today, Google Play once that app ships) are billed by that store: recurring storage is cancelled in the store's subscription settings, and refunds follow the store's process. Either way it is the same account and the same Pro everywhere - including platforms that do not exist yet.

What is the refund policy?

30 days, no questions asked. If Pro is not for you, request a full refund within 30 days of purchase and it goes back to the original payment method. Customers in the EU additionally keep their statutory 14-day right of withdrawal.

Payments are processed by Paddle, our merchant of record, so refunds are handled by Paddle directly: reply to your purchase receipt email or visit paddle.net. The full policy lives in the terms of service.

What do you learn about me when I pay?

Less than you might expect. Checkout runs through Paddle, the merchant of record: your name, card number, and billing address go to Paddle for payment and tax purposes and never touch our servers.

Paddle holds your billing details; what reaches our database is your public key, the amount and the order id, and for a storage add-on its size and renewal dates. Our Paddle account can see both sides, and we do not look you up. To keep your name off the purchase, pay with an email alias and a masked card.

Can I buy Pro without revealing who I am?

Yes, with two standard tools. For the receipt, use an email alias: Apple Hide My Email, DuckDuckGo Email Protection, SimpleLogin, Firefox Relay, or addy.io all forward to your real inbox without exposing it. For the payment, use a masked card: privacy.com in the US generates virtual cards that work with any name you type, and many banks and services elsewhere (Revolut, for example) offer disposable virtual cards that do the same job.

At checkout, Paddle asks for an email, a payment method, and a country (plus a postal code in some regions) to calculate tax. The alias receives the receipt, the masked card carries whatever name you gave it, and the tax location narrows you to a region, nothing more. Keep the alias alive though: the receipt email is your proof of purchase and your channel for a refund.

Combined with a phrase account, no single party ends up holding the full picture: your bank sees a card top-up, Paddle sees an alias and a masked card, and we see a public key that became Pro, next to that alias in our Paddle account.

// Apps & platforms

Which platforms does PrivacyNotes run on?

Web, macOS, Windows, Linux, iOS, and Android. Every app is built from the same core, encrypts your notes on your device the same way, and syncs through the same account. The downloads section always has the latest builds.

The native apps need macOS 13 or newer, Windows 10 or newer, iOS 17.4 or newer, Android 7.0 or newer, or a Linux release with webkit2gtk 4.1 (Ubuntu 22.04+, Debian 12+, or equivalent). Below those versions the app will not install or start, so use the web app instead.

The web app is a first-class citizen, not a fallback: it keeps your notes on your device and works offline, so any modern browser is always a way in.

How do I check that the app I downloaded is genuine?

Every build we ship is signed, and your operating system checks that signature before it runs anything. macOS builds are signed and notarized by Apple. Windows installers carry an Authenticode signature you can read under Properties > Digital Signatures. The Android APK is signed with our own key, which is why Android refuses any update that is not ours. The iPhone and iPad app is signed by Apple and only installs through the App Store. The desktop apps also reject an update that is not signed with our key.

Download only from PrivacyNotes.app or from our releases on GitHub, which lists every version. The signature is the check that counts, and your system runs it for you: it is verified against a key that lives nowhere on our website, so a swapped file fails that check whatever the page beside it says.

I asked for a feature or reported a bug. How long until it ships?

Often days. Small requests and bug reports usually land in the next release, and releases go out most weeks rather than a few times a year. The changelog is the record: every entry is dated, written in plain language, and says what changed. Read a month of it and you will know exactly what to expect from us before you commit anything to the app.

That pace comes from how the work is split. The encryption core, the sync protocol and the sign-in flow were written by people, next to day jobs, long before the app had a name, and the crypto core is still maintained that way; nothing automated goes near it. Once that foundation was solid, in spring 2026, we started using AI coding tools under a fixed protocol: first for translations, then help articles, then interface features and non-critical bug fixes, where they are good at pinning down rare edge cases that would otherwise take weeks, and at writing the test scripts that hold several developers to one standard. That is why a request from one person is worth building instead of waiting behind the top of the list.

Anything touching encryption, sync or sign-in stays with skilled developers who write every line, and that code is public so you can read it instead of trusting us. More on the team and how we work on our about page.

The app itself has no AI features and never sends your notes anywhere (details). That promise is separate, and it does not change.

Will the Android app update itself?

Install it with Obtainium and yes: it reads our releases and offers each new version as it ships, which is why we recommend that route on Android. An APK taken straight from our website updates on your say-so instead, because Android auto-updates only apps that came from a store.

The website APK tells you instead. The app checks for a newer version and shows an "Update available" notice with a "Download" button. Tap Download, then open the downloaded file to install it over the old version, with your notes and settings untouched. The check only asks whether a newer version exists, it never touches your notes, which stay encrypted the whole time.

How do I install the Android app with Obtainium?

Obtainium is a free, open-source Android app that installs other apps straight from their release pages, and it is now the way we recommend installing PrivacyNotes on Android, because it is the only route that keeps itself current. Already have it? Tap the badge and it adds PrivacyNotes for you.

Get it on Obtainium

New to it? Install Obtainium first, then add an app and paste this in:

https://github.com/LifetimeLabsDev/PrivacyNotes.app

Obtainium reads our releases, picks the APK, and installs every new version as it ships. No Google account is involved at any point.

Obtainium is not our app, and Android still asks you to confirm each install, so an update arrives as a notification and one tap, not silently. The APK is the same build our download page serves, signed with the same key, so Obtainium adopts an app you already sideloaded: nothing to uninstall, nothing to sign in to again. Without it, the app can only tell you in-app that a version is ready.

Obtainium, the direct APK, or Google Play: which Android download?

Take Obtainium if you want the app to stay current on its own, and the direct APK if you would rather not run a second app for it. Google Play is not live yet, so today the choice is between those two. They hand you the same file signed with the same key, so you can move either way at any time: Obtainium adopts an APK you already sideloaded, and the website APK installs over an Obtainium one.

Either route is easy to change your mind about later. Before any switch that means uninstalling first, confirm the app reads "Synced" and have your 12 words or a sign-in QR from another device ready, because uninstalling clears the local copy.

Which languages does the app speak?

English, German, French, Italian, Spanish, Dutch, Polish, Czech, Catalan, Turkish, Swedish, Ukrainian, Russian, Japanese, Korean, Traditional Chinese, Thai, Arabic, and Portuguese in both European and Brazilian variants. The app follows your system language by default, or you can pin one explicitly under Settings > Language on each device.

Translations are free for everyone, not a Pro perk. More languages are planned; if yours is missing, tell us on GitHub or Reddit.

How are the app's translations made?

We write the English first. An AI agent then translates each language against a shared glossary, in the register fixed for that language, and a second agent reviews every batch for accuracy, terminology and register before it ships. Native speakers review a sample, starting with the newest languages and the security, sign-in and billing text, and two automated checks fail the build while any translation is missing or out of date. Translations are free on every tier, never a Pro perk.

You can improve any of them. If a sentence reads oddly in your language, report the translation: your language, the screen it is on, and what it should say instead. Corrections ship in the next release.

Still stuck? Ask your AI agent.

You get an answer in seconds instead of waiting for a reply. Your assistant reads all 95 answers and every import guide at once, so it can combine them, follow up on your question, and explain it in your own words. We never see any of it, because we do not run a chatbot.

  1. Copy the prompt.
  2. Paste it into ChatGPT, Claude, Gemini, or any other AI assistant.
  3. Ask your question, in your own language.
  4. Keep that chat open. Next time, ask straight away.
Show AI prompt
Answer my questions about PrivacyNotes using only its help center, its changelog and its security documentation.

Start here: https://privacynotes.app/llms-index.txt
It lists every question with the page that answers it. Fetch the one or two that match mine.
If you can only make one request, fetch https://privacynotes.app/llms-full.txt instead.
If you cannot fetch a .txt or .md file, read https://privacynotes.app/help, https://privacynotes.app/changelog and https://github.com/LifetimeLabsDev/PrivacyNotes.app instead.

For what changed, or where something moved, fetch https://privacynotes.app/changelog.md.

For how the encryption works, what the server can read, or how to check any of it yourself, fetch https://privacynotes.app/docs/index.md and follow it to one of the documents it lists. That index is a router: cite the document, never the index.

Rules:
- Use only those pages. If they do not answer something, say so instead of guessing.
- Never invent a feature, a menu path, a price, or a limit.
- End your reply with the "Source:" URL from the page you used, exactly as written.
- Answer in the same language as my question.
- Never ask me for my recovery phrase, my PIN, or the contents of a note.

If no question follows, ask me what I would like to know.

My first question:

Never paste your recovery phrase, your PIN, or a note into an AI.