Can I try PrivacyNotes without creating an account?
Yes. The demo at try.privacynotes.app is the full app with sample content: no signup, no email, and nothing you type is saved. It runs entirely in your browser and never sends anything to our servers.
Closing the tab clears everything, which is the point. When you are ready to keep your notes, create a real vault at use.privacynotes.app. Demo content does not carry over, so copy out anything you want to keep first.
Which sign-up option should I choose?
Whichever matches your threat level. There are three of them. One: sign in with Google, Apple, or GitHub, with your key stored on our server. Two: the same sign-in, with your key kept on your device only. Three: "Generate a phrase", with no email, no name and no login at all. All three keep your notes end-to-end encrypted, and what separates them is who holds the key and how much we learn about you.
Signing in with one of those three then asks where your key lives. "Keep it simple & convenient" stores it on our server, encrypted, so any new device signs in with that login alone and there is nothing for you to keep safe. That is the right level if what you fear is losing your own credentials. "Maximum security & privacy" keeps the key on your device: we could not read a note under any pressure, and a new device needs your 12 words or a QR scan from one already signed in.
The phrase-only route is the highest level: no email, no name, nothing tying the account to a person. In exchange the key is yours alone, so losing it with no signed-in device left means nobody can help. Nothing is permanent, though. Settings > Security > Your Phrase moves you between modes whenever you like, and every level can add a PIN or biometric lock on top. The full ladder, with what each rung costs, is in the threat-level ladder.
Do I need an email address to sign up?
No. A new vault is a freshly generated 12-word recovery phrase, nothing else. No email, no username, no phone number, no verification step. If you sign in with the phrase, we could not email you even if we wanted to, because we never learn who you are.
Prefer a familiar flow? Sign in with Google, Apple, or GitHub works too. That route necessarily tells us the email tied to that login, but your notes stay end-to-end encrypted either way, and you still get a phrase under the hood.
How do I move my notes in from another app?
Open Settings > Import & Export and pick your source. There are dedicated importers for Apple Notes, Obsidian, Standard Notes, Google Keep, Simplenote, Samsung Notes, and Bitwarden (logins, cards, and secure notes land in the Vault), plus a generic Markdown importer for any folder of .md files.
Imports run entirely on your device: your exported files are parsed, encrypted, and stored locally, nothing is uploaded for processing. Each imported note is tagged with its source so you can review the batch afterwards, and Google Keep checklists even convert to native task lists.
Can I edit a folder of Markdown files from my own disk?
Yes. Open the Markdown pillar in the sidebar, pick a folder of .md and .txt files, and edit them in the same editor you use for notes. Subfolders appear on their own, edits save straight back to the file, and nothing is converted, so the same folder keeps working in Obsidian, in a git repo, or in your own scripts. Save to my notes copies any file, or a whole selection, into your encrypted notes in one click and leaves the original where it is. All of it is free on every tier.
One honest limit: the folder is the one part of the app we do not encrypt. Those files stay on your disk exactly as you left them, we never upload them, and they never sync to your other devices. It needs the desktop app, or Chrome, Edge or Opera on a computer. Safari, Firefox and phones cannot open a folder from disk.
Is the editor Markdown-friendly?
Yes. Type Markdown and it formats live: # headings, bold, lists, - [ ] task checkboxes, quotes, and callouts. Notes export as clean Markdown too, so what you write stays portable.
You can also connect notes to each other: type [[ and an autocomplete offers your existing notes. A note-link opens its target with one click, and the outline panel plus find-in-note keep long documents navigable.
Which Markdown syntax does the editor understand?
Standard Markdown formats live as you type: headings, emphasis, strikethrough and highlight, bulleted and numbered lists, task lists (Tab and Shift+Tab nest any list, checklists included), quotes, dividers, inline code and code blocks with syntax highlighting, inline and block math (KaTeX), and note-links between notes with autocomplete.
The formatting toolbar and its Insert menu add the rest: tables, callouts in nine types that can fold closed, underline, superscript and subscript, text alignment, text and highlight colors, fonts, links, images, and file attachments. Everything round-trips as Markdown: "Show markdown" below any note reveals the raw source, and exports are clean .md files, so nothing you write is locked into a proprietary format.
// See it in action
Headings
# Planning
## This week
### Monday
Planning
This week
Monday
Inline formatting
**bold**, *italic*, ~~done~~,
==marked== and `inline code`
bold, italic, done, marked and inline code
Task list
- [x] Derive keys on the device
- [ ] Trust a server
Derive keys on the device
Trust a server
Nested lists
1. Write your phrase down
2. Store it offline
- paper beats cloud
- two copies, two places
Write your phrase down
Store it offline
paper beats cloud
two copies, two places
Callouts
> [!info] Zero-knowledge
> The server stores only ciphertext.
> [!warning] No resets
> A lost phrase cannot be recovered.
Zero-knowledge
The server stores only ciphertext.
No resets
A lost phrase cannot be recovered.
Table
| App | Can read your notes |
| --- | --- |
| PrivacyNotes | No |
| Typical cloud notes | Yes |
App
Can read your notes
PrivacyNotes
No
Typical cloud notes
Yes
Code block
```js
// encrypted before it leaves
const keys = deriveKeys(phrase);
```
// encrypted before it leavesconst keys = deriveKeys(phrase);
Superscript, subscript, underline
H<sub>2</sub>O and E = mc<sup>2</sup>,
<u>underline</u> included
H2O and E = mc2, underline included
Math (KaTeX)
$e^{i\pi} + 1 = 0$
eiπ + 1 = 0
Quote and note-link
> Privacy is a feature, not a setting.
Ideas live in [[Second brain]]
Privacy is a feature, not a setting.
Ideas live in Second brain
Divider
Quick capture
---
Polished later
Quick capture
Polished later
How do tasks work?
Any line you write as - [ ] in any note becomes a task, and the Tasks view in the sidebar collects them all in one place. Checking a task off there updates the note it lives in, and opening a task jumps to that note. There is no separate task database to maintain: tasks are just lines in your notes, encrypted like everything else.
The quick-add box at the top of Tasks appends to a note called Quick Tasks (created for you on first use), so capturing a stray to-do takes one keystroke, not a filing decision. The same view offers three layouts (Hybrid, Aggregated, List), a completed-tasks toggle, and task search, and the New button on the All view can start a task note directly.
How does the journal work, and what can I track?
Journals is a dedicated view for dated entries: one tap creates today's entry, and the calendar button next to it backfills a recent day you missed. An entry is a normal note plus optional trackers: mood on a 1-10 scale with 24 emotion tags, sleep, activity, medications, energy, focus, and more. "Configure trackers" inside any entry toggles the built-ins, and Pro adds up to 10 custom trackers (scales, numbers, yes/no).
Statistics (in Settings, or the stats icon in the footer) turns entries into trends under the Wellness tab: mood over time, sleep and activity charts, medication adherence. Exports are generated on your device: "Download JSON" is free, and Pro adds a "Doctor PDF" to bring to appointments, a copy-ready AI prompt for the chatbot of your choice, pattern insights, and a week in review. Tracker data lives inside the encrypted entry, so the server can read none of it.
Can I save my browser bookmarks in PrivacyNotes?
Yes. Bookmarks are a pillar in the sidebar, next to Notes, Tasks and Journals, and they are free on every tier. Paste a link into the quick-add bar to save one. To bring your existing ones across, export a bookmarks .html file from your browser, then drop it into Settings > Import & Export > Import > "Browser bookmarks". Chrome, Firefox, Safari, Edge, Opera, Brave and Vivaldi all hold the same file, and your folders and dates come with it. Safari wraps it in a .zip, which you can drop in unopened.
We never fetch the page behind a link, so a bookmark you add by hand carries its domain as the name until you type one. That is deliberate: reading the page would mean sending your URLs to a server. Site icons are the one exception, and you can switch them off. Export writes the same standard .html file, so your bookmarks leave as easily as they arrived (import guide).
How do folders work, and do I need Pro for them?
Folders nest as deeply as you like and live in the sidebar. Browsing them is free on every tier. Creating one, renaming it, or moving a note into it ("New folder" and "Move to folder") is where Pro starts, so a free account can always read a structure it imported or built while on Pro. An "Unfiled" row lists every note that sits in no folder.
A note lives in one folder at a time, the way a file does. Reach for tags when something belongs in two places at once. The folder is stored inside the encrypted note, so the server sees your structure no better than it sees your text.
How do tags work?
Every open note has a tag row under the title. Type a word and press Enter, a comma, or #, and the tag becomes a chip. The sidebar lists every tag you use, and clicking one filters the list to those notes. You can rename a tag everywhere at once, favorite it so it pins to the top, or delete it, with or without the notes under it.
Tags and folders solve different problems: a note sits in one folder but carries as many tags as you like, which is what you want when something is both "work" and "invoice". Imports tag by source, so everything that arrived from another app lands with its own tag and is easy to find, or to clean up later.
How do I link one note to another?
Type [[ anywhere in a note and start typing a title. Pick a note from the list and it becomes a note-link you can click. If nothing matches, choose "Create" and the new note is made and linked in one step. The toolbar button "Link to another note" does the same thing.
Note-links live inside the note, so they export with it and travel with an import: an Obsidian vault keeps its links, and Evernote note links are converted on the way in. What does not exist yet is a graph view or a backlink panel, so a note does not list what points at it. Search is the way to find the other side of a link today.
Can I change how the app looks?
Yes, in Settings > Appearance. Mode switches between Light, Dark and Auto, which follows your system. Text size has four steps and scales your writing surface only, so the interface around it stays put. View lays items out as a List or a Grid. Editor decides whether notes open Formatted or as plain Markdown.
Color themes are the one part behind Pro: the default theme is free and Pro unlocks the rest, in light and dark alike. Zen mode, which hides everything except your text, is Pro too (Cmd+Shift+F). Mode and text size stay on the device you set them on. Everything else follows your account to your other devices.
What keyboard shortcuts are there?
Press ? anywhere in the app for the built-in cheat sheet, also available under Settings > About & Help. Shortcuts cover navigation, note actions, formatting, and views - and on Windows and Linux, every Cmd reads as Ctrl and Option as Alt.
// The full list
// Navigation
Focus search⌘K
Move down / up in the listJ/K
Clear search / close note / exit selectionEsc
// Notes
New note⌥⇧N
Move note to trash⌘⌫
// Editor
Find in note (press again to close)⌘F
Toggle outline⌘⇧O
Insert link (while editing)⌘⇧K
Undo⌘Z
Redo (while editing)⌘⇧Z
// Formatting
Bold⌘B
Italic⌘I
Underline⌘U
Strikethrough⌘⇧S
Highlight⌘⇧H
Inline code⌘E
Superscript⌘.
Heading 1 to 6⌥⌘1–⌥⌘6
Normal text⌥⌘0
Numbered list⇧⌘7
Bulleted list⇧⌘8
Task list⇧⌘9
Increase indent (list or checklist)Tab
Decrease indent (list or checklist)⇧Tab
Blockquote⌘⇧B
Code block⌥⌘C
// Alignment
Center⌘⇧E
Align right⌘⇧R
Justify⌘⇧J
// View
Open settings⌘,
Toggle sidebar⌘\
Toggle light / dark mode⌘⇧L
Zen / Focus mode (Pro)⌘⇧F
Toggle this help?
On Windows and Linux, ⌘ is Ctrl and ⌥ is Alt.
Most shortcuts are ignored while you're typing in a text field, so regular keys like J and K still type J and K.
Is there a printable cheat sheet of the shortcuts?
Yes. The printable cheat sheet lays every shortcut out on a single A4 page in two columns, ready to pin next to your screen. It is generated from the same list the app itself shows, so it can never lag behind a release.
Open it and press the Print button (or Cmd+P / Ctrl+P). To keep a file instead of paper, choose PDF as the destination in the print dialog. The sheet is also linked above and below the in-app shortcut list under Settings > About & Help > Hotkeys, and in the footer of this site.
Can I use my own AI agent to get help with PrivacyNotes?
Yes, and we built the help center for it. Every answer is published as one plain-text file at llms-full.txt, so an assistant reads the lot in one go. The box at the bottom of any help page copies a ready-made prompt: paste it into ChatGPT, Claude, Gemini, or whichever assistant you already use, and ask in your own language.
We deliberately do not run a chatbot of our own. One would mean your questions landing on our servers, and questions about a notes app tend to carry the contents of the notes. Sending you to a tool you already trust keeps us out of it entirely, and we never learn what you asked. This is separate from the app itself, which has no AI features at all (details).
One rule, and it matters: never paste your recovery phrase, your PIN, or the text of a note into an assistant. No answer requires them, the copied prompt tells the assistant to refuse them, and anything you type into someone else's chat box has left your device.
// Security & privacy
What can PrivacyNotes see about my notes?
Nothing readable. Notes, titles, tags, and attachments are encrypted on your device before they sync. The server stores ciphertext it cannot decrypt, and there is no key on our side to change that.
What we can see is the minimum needed to run the service: how much encrypted storage you use, how many devices you have linked, and sync timestamps. If you sign in with a phrase rather than a Google, Apple, or GitHub account, we do not even know your email address.
Why a recovery phrase instead of a username and password?
It can feel backwards at first, but a single recovery phrase is the stronger construction. With a username and password, the username is not a secret (it shows up in every breach dump), so all the security rests on the password, and human-chosen passwords average maybe 30 to 40 bits of entropy. Your 12-word phrase is a guaranteed 128 bits, generated by your device, never chosen by a human, and never reused from another site.
There is also nothing for us to lose. A password login means the server stores at least a password hash, which can be leaked, cracked, or phished. Your phrase never leaves your device: it derives your encryption keys locally, and the server only ever sees encrypted data. There is no hash to steal and no password reset flow for an attacker to abuse.
If typing 12 words feels clunky: you can save the phrase to your password manager with one tap (Settings > Security > Your Phrase), and signing in feels like any other login. Prefer a familiar flow? Sign in with Google, Apple, or GitHub works too, and you still get a phrase under the hood.
Can I choose my own balance between convenience and privacy?
Yes, deliberately. Not everyone is defending against the same threats, so the account model is a ladder rather than a single dogma. Every rung keeps your notes end-to-end encrypted; what changes is who holds the key and what we know about you.
The convenient end: sign in with Google, Apple, or GitHub and pick "Keep it simple & convenient" when asked. We store your recovery phrase for you, encrypted at rest on our server, so any device signs in with that login alone and there is nothing to back up or lose. The honest tradeoff: we know the email behind that login, and a fully compromised server could in principle expose the stored key. If your realistic threat is losing your own credentials rather than a targeted breach, that is a sensible trade.
The middle: sign in with Google, Apple, or GitHub but pick "Maximum security & privacy". Your phrase never touches our servers and the encryption is fully zero-knowledge; new devices need the phrase or a QR scan from a device that is already signed in. We still necessarily know the email behind that login, but we could not read a single note even under compulsion.
The private end: skip the logins entirely and use only the 12-word phrase. No email, no name, no identity, and paired with an anonymous Pro purchase, even paying leaves no name anywhere. In exchange, key custody is entirely yours: lose the phrase with no signed-in device left, and nobody can help.
You are not locked into the rung you picked. Settings > Security > Your Phrase shows both modes side by side with what each one costs, and you can move either way whenever you like. Switching to self-custody deletes our stored copy and asks you to retype three of your twelve words first, since the people most likely to click it are the ones who never wrote them down. Switching back uploads the phrase again and takes an explicit choice. Both directions are signed with your own account key, so a stolen session cannot change your custody mode. And every rung can add the local layers on top: PIN app lock, biometric unlock, and per-note protection.
Is a 12-word recovery phrase secure enough? Why not 24 words like Bitcoin wallets?
Yes, 12 words is enough. A 12-word BIP-39 phrase encodes 128 bits of entropy. Brute-forcing 128 bits is not a "needs a bigger computer" problem, it is a "more energy than humanity produces" problem. There is no realistic attack that breaks 128 bits but fails at 256.
The Bitcoin comparison actually shows why 24 words is mostly marketing: Bitcoin keys live on the secp256k1 curve, which itself only provides about 128 bits of security. A 24-word phrase feeds 256 bits of entropy into a lock that still only takes about 128 bits of work to break. That is also why many major wallets still default to 12 words.
PrivacyNotes targets the same 128-bit security level end to end: your phrase is run through a key derivation function, and the encryption it protects (XChaCha20-Poly1305) is keyed to match. Adding 24 words would double what you write down and type without adding any practical security, so we have no plans to offer it.
The honest weak points of any recovery phrase are phishing and where you store the paper, not its length. Guard the phrase itself and 12 words will outlive all of us.
If someone guesses my 12 words, can they log into my account?
Short answer: yes. Your phrase is the key, so anyone who holds it can sign in, the same way anyone holding your house key can open your door. That is by design: it is the single master key to your notes, and nothing weaker sits in front of it. So the real question is not whether holding the phrase grants access (it does), but whether someone could guess it, and there the answer is no, not with any computer that exists or that we can foresee.
Here is the scale. A 12-word phrase is one of 2^128 possibilities: about 340 undecillion, a 39-digit number (3.4 x 10^38). The odds of guessing yours on the first try are 1 in 340 undecillion, longer odds than winning a 1-in-300-million lottery jackpot four times in a row. Treating it as a search rather than a lucky guess does not help: even at a billion billion attempts every second (10^18, far beyond what any real hardware could reach, nation-states included), working through them all would take around 10 trillion years, close to 800 times the current age of the universe. And that is the fantasy version, because every real attempt has to run a deliberately slow key-derivation step and any online attack must go through our servers, which makes actual guessing slower by many more orders of magnitude. This is not a novel scheme either: the same 128-bit construction has secured Bitcoin wallets for over a decade, and no one has ever guessed one.
It is tempting to picture the phrase like a password, where you add strength by mixing in capitals, numbers, and symbols. A recovery phrase does not work that way, and you should never try to build or edit one by hand. Your device generates 128 bits of cryptographically secure randomness and encodes them as 12 words from a fixed public list of 2048 words: that randomness is the entire strength. The last word even carries a built-in checksum, so a mistyped or made-up phrase is rejected on sight. Word order matters, capitalization does not (we normalize it when you sign in), and adding symbols would only make the phrase invalid. Type the words exactly as issued.
Why is there no two-factor authentication (2FA)?
Because it is a deliberate tradeoff, not an oversight. The familiar kind of 2FA, a texted code or an authenticator app, exists to shore up weak, human-chosen passwords, and it leans on a shared secret and a recovery path held on a server. That is the exact attack surface the phrase model removes: your device proves it holds the key by signing a challenge, so our servers only ever receive a public key and a signature, never the phrase and never a password hash. Bolting a code on top would reintroduce the server-side machinery this design exists to avoid, while adding nothing against guessing, because 128 bits already closes that door.
The one kind of second factor that would genuinely add something is a phishing-resistant one, such as a hardware security key or a passkey, because the real residual risks are not guessing but phishing, malware, and a phrase that gets stolen or shoulder-surfed. On a device left unlocked, the app lock (PIN) and biometric unlock are the local backstop.
Beyond that, the phrase is the key, so back it up the day you create your account: keep it in a reputable password manager, or print it or write it down and store that copy somewhere safe. Never paste it into anything but the app itself.
Do you use the same word list as Bitcoin wallets (BIP-39)?
Yes, the standard BIP-39 English wordlist: 2048 words, the exact same list Bitcoin wallets use. We generate phrases with @scure/bip39, an audited open-source library. No custom wordlist and no homegrown crypto.
The list is designed for writing down by hand: the first four letters of every word are unique, so a smudged or abbreviated word is still unambiguous, and similar-looking words were deliberately excluded.
Because it is the standard list, you can verify your phrase against any public BIP-39 reference, and our encryption layer is published as open core so you can check the implementation yourself.
Does searching my notes send anything to your servers?
No. Search runs against a full-text index built and stored on your device. Queries never leave it, results appear even with no connection at all, and nothing about what you search for is ever transmitted.
This is not a policy choice we could quietly reverse, it is forced by the architecture: the server only holds ciphertext, so there is nothing readable on our side to index or search. A server that cannot read your notes cannot search them either.
Does PrivacyNotes use AI on my notes?
No. There are no AI features in the app, no AI processing running in the background, and no model training on your content. Your notes are encrypted before they leave your device, so there is nothing readable on our servers to feed into anything.
If we ever ship a feature in this direction, it would have to run entirely on your device and be strictly opt-in. Sending plaintext notes to a cloud model would break the zero-knowledge promise, so it is off the table.
What are burn notes?
A burn note is a self-destructing way to share a note with someone who does not use PrivacyNotes. The app encrypts the content with a one-time key and gives you a link. The key travels in the link fragment, which browsers never send to servers, so our server stores ciphertext it cannot read.
The first time the link is opened, the server hands over the ciphertext and deletes it in the same step: one read, then it is gone. Unopened links expire on their own after 24 hours. Either way, nothing lingers.
Can I share a note with someone else, or work on one together?
You can share, but not collaborate. A burn note turns any note into a one-time encrypted link that is destroyed the moment it is read, which covers handing over a password, an address, or a draft. For something the other person keeps, export the note as Markdown, HTML or PDF and send them the file.
What does not exist is a note two people edit, or an account two people use at once. That is deliberate. Live collaboration means the server has to hand keys between people, and keeping the server out of your keys is the whole design. One account is one person with one phrase.
What is the difference between read-only and PIN-protected notes?
"Read-only" (in the note options menu, Pro) locks a note against edits so a finished document cannot be mangled by accident; it hides nothing. "Protect" (same menu, Pro) hides a note's title and contents behind your PIN or biometric unlock, for the things you would rather not have visible on a screen others sometimes see.
Both are convenience gates on your device, not extra encryption. The flags travel inside the note's encrypted data, and the note is deliberately not re-encrypted with your PIN: that way a forgotten PIN can never destroy data. It also means anyone holding your recovery phrase could sign in on a fresh device, set a new PIN, and read everything. The phrase remains the real security boundary - protect it first, and use these gates for on-screen privacy.
Biometric unlock stopped working. What can I do?
You are never locked out. The lock screen always offers a fallback: "Unlock with PIN", or "Sign in with recovery phrase". The biometric is a local gate, not an encryption key, so your notes are untouched either way.
Then fix the gate. Enrollment is per-device, so a new phone, a fresh browser profile, or a reinstall needs re-enrolling: Settings > Security > "Biometric Lock", disable, then "Enable biometric unlock" again. It also requires "Trust this device" (untrusted sessions clear when the tab closes) and hardware with a platform authenticator (Touch ID, Face ID, Windows Hello). If a password manager like Bitwarden or 1Password pops up instead of the system prompt, dismiss it and retry, or turn off its passkey capture for the site - the app requests the built-in authenticator, but some managers intercept anyway.
Is PrivacyNotes open source?
The parts that protect you already are. The encryption code, database schema, and threat model are published as open core, so anyone can audit exactly how your notes are secured rather than taking our word for it.
The apps are next. Once the native apps for every platform have shipped, we will open-source the client code (web, desktop, and mobile). The one part that stays closed is the sync backend, and it never holds anything but encrypted data we cannot read. Keeping it private costs you nothing on privacy, and it stops anyone from cloning the whole service and passing our work off as their own. Open where it protects you, closed where it protects us.
// Account & recovery
I lost my recovery phrase. Can you recover my account?
If you are still signed in on any device: yes, you can recover it yourself. Open Settings > Security > Your Phrase and save it to your password manager right now.
If you have no signed-in device and no phrase: no, and nobody can. Your phrase never reaches our servers, so there is nothing to reset and no support ticket that can help. This is not a policy we could bend - it is what end-to-end encryption means. Any service that can restore your encrypted data after a total loss is holding your keys.
The fix costs ten seconds: store the phrase in a password manager the day you create your account.
I sign in with Google, Apple, or GitHub. What if I lose access to that account?
You still have a 12-word phrase under the hood, and the phrase alone signs you in on any device - no Google, Apple, or GitHub account required. Open Settings > Security > Your Phrase and save it to your password manager.
Do that once and losing that account costs you nothing: just sign in with the phrase instead.
My recovery phrase leaked. What do I do?
Treat the vault as burned. A phrase cannot be changed or rotated, because the phrase is the key everything is encrypted under - so the fix is moving to a fresh vault. First, in the old account, export everything: Settings > Import & Export > Export > "PrivacyNotes backup (.zip)".
Sign out, create a new vault (new 12 words), and bring the export back in via Settings > Import & Export > Restore > "Full backup (.zip)". Then delete the old account from any device still signed into it: Settings > Account > "Delete account & data...". That removes its synced data and shuts out anyone holding the old phrase. If you signed in with Google, Apple, or GitHub, delete the old account first, then sign in with that same login again to start the fresh vault.
Two honest costs: an active storage add-on must be cancelled before deletion, and Pro is bound to the account it was bought on - it does not transfer to the new vault, and beyond the standard 30-day window this is not a refundable event. Prevention is cheap by comparison: keep the phrase in a password manager and nowhere else.
I lost a device. How do I protect my notes?
From any signed-in device, open Settings > Account > "Registered devices" and remove the lost one. The next time that device comes online it is signed out and its local data is wiped, within about a minute of its next use. It stays listed under "Recently removed" for 72 hours so you can confirm it is gone.
The honest limits: a device that never reconnects keeps whatever it already stored until it does, which is why the app lock (PIN or biometric) plus your OS screen lock matter on anything portable. And removal is not a key change - anyone who actually holds your 12 words can sign in again regardless. If you suspect the phrase itself leaked, follow the phrase leak playbook instead.
I forgot my PIN. Is my data gone?
No. The PIN is a convenience lock against shoulder-surfing on your own device, not an encryption key. Your notes are encrypted with keys derived from your recovery phrase, and the phrase always grants full access without any PIN.
This is a deliberate design choice: tying encryption to a 4-digit PIN would mean a forgotten PIN destroys data. It never does here.
How do I delete my account?
In the app: Settings > Account, then "Delete account & data". This permanently removes your synced notes, files, devices, settings, and the account itself from the server. There is no retention window and no backup we could restore afterwards, so export anything you want to keep first (Settings > Import & Export).
Two details: an active storage subscription must be cancelled before deletion (one already scheduled to cancel does not block it), and because a phrase account never included an email or a name, there is no profile or marketing list left to scrub. Wiping the local data on one device is a separate action and does not touch your account.
// Sync & devices
How do I sign in on a second device?
On the device you already use, open Settings > Security > Your Phrase. It shows your 12 words and a sign-in QR code. On the new device, choose "Phrase login", then scan that QR with the camera, upload a photo of it, or type the words in. Your notes arrive within seconds.
A free account covers 2 devices and Pro covers as many as you like, and two browsers on one computer count as a single device. Treat the QR exactly like the phrase it carries: show it to nobody, and never let it land in a photo library that syncs to somebody else's cloud.
What exactly syncs across my devices, and what stays local?
Everything you would expect, all encrypted on your device before it syncs: notes, tasks, journal entries, your vault, and the encrypted files in it. Your settings follow you too - favorite tags, sort and view preferences, color theme, your PIN (as a salted hash, never the PIN itself), app lock, tracker and medication setup, and trash auto-delete. Set something up once and every device picks it up.
A few things stay deliberately device-local: light or dark mode (each device follows its own system preference), biometric unlock (tied to the hardware of each device), and your unlock state (closing the app always re-locks). The server only ever stores encrypted blobs and can read none of it.
Does PrivacyNotes work offline?
Yes. The app is local-first: your notes live in a database on your device, so reading, writing, and search all work with no connection. Changes sync automatically when you are back online.
Can I stop a device from syncing without signing out?
Yes. Open Settings > ID & Sync and press "Pause sync". That device stops sending anything to the server: notes, settings and files alike. You keep writing exactly as before, everything queues locally, and the moment you resume it all goes up.
The pause belongs to that device alone. It does not travel to your other devices and it never clears itself, because a switch that says "this device talks to nobody" must not be turned back on by anything except you. One thing keeps running on purpose: the small heartbeat that lets a removed device learn it was removed, which is how a lost device still wipes itself.
Can I stop the app from uploading files over mobile data?
On Android, yes. Open Settings > ID & Sync and turn on "Files on wifi only". Your notes keep syncing on any connection, because text is tiny. Only images and attachments wait, and they go up the moment wifi comes back rather than sitting out the next retry.
The switch is Android only, and it is hidden elsewhere on purpose: Android is the one platform whose app view reports wifi against cellular reliably, and a switch that guesses is worse than no switch. On a metered connection anywhere else, "Pause sync" is the blunt version that works everywhere.
What happens if I edit the same note on two devices at once?
Nothing is overwritten silently. If both devices changed the same note while apart (say, one was offline), the app detects the collision when they sync again and shows a conflict dialog: keep the version on this device, keep the other one, or keep both as separate notes.
In everyday use you will rarely see it. Edits sync within seconds while you are online, and the dialog only appears when two versions of the same note genuinely diverged.
How do I remove a device I no longer use?
Settings > Account lists every registered device. Remove the one you are retiring: the slot frees up immediately (useful on the free 2-device plan), and the removed device is signed out the next time it tries to sync. It stays visible under "Recently removed" for 72 hours so you can confirm it is gone.
One honest caveat: removal is not a security boundary on its own, because anyone holding your recovery phrase can sign in again. If a device was lost or stolen, the phrase is the thing to protect, and the app lock (PIN or biometrics) is what keeps a found device from being an open door.
What does "Device limit reached" mean?
Free accounts sync on up to 2 devices, and this dialog appears when a third tries to register. Remove a device you no longer use directly in the dialog, or on an existing device under Settings > Account (how removal works). The slot frees immediately, and the removed device stays visible under "Recently removed" for 72 hours. Pro lifts the cap entirely.
One quirk worth knowing: so that several browsers on one computer do not eat several slots, devices are grouped using privacy-preserving hashes of coarse machine signals, computed on your device with a per-account secret. A major browser update, or hardened browsers like Brave or Tor that randomize those signals, can land the same machine in a new slot for a while. You are never locked out - remove the stale entry and carry on.
What happens when I go over my storage limit?
Nothing is ever deleted. When new changes stop fitting, sync says so: "Storage full. Some notes couldn't sync." Existing data keeps syncing, new growth does not. If you stay over the cap, a 90-day countdown starts, shown as an amber banner. Reading, editing things smaller, deleting, and exporting all keep working the entire time.
After 90 days over cap, sync pauses: the banner turns red ("Sync paused. You've been over your storage limit for 90+ days."). The app still works fully on every device; changes just stay local until you are back under. Recovery is instant and self-serve: free up space - emptying the trash counts - or add storage under Settings > Storage, and sync resumes on its own. This is the deliberate opposite of services that auto-delete over-quota data.
// Your data
Where is my data stored?
On your device first, and that is the copy you work with: the app is local-first, so your notes open and edit offline. The synced copy lives on servers in Zurich, Switzerland. What sits there is your public key, encrypted blobs of your notes, files and settings, plus the timestamps and sizes a sync needs. No titles, no text, no tags.
The country matters less than the encryption does. Everything is encrypted on your device before it leaves, so that copy would be unreadable wherever it sat: Switzerland is a bonus, not the promise. What syncs lists it item by item.
One honest limit: the copy on your device is not encrypted. Notes sit in ordinary browser storage so the app can open and search them instantly, and encryption happens at the sync boundary. Disk encryption and a screen lock are what protect that copy; the app lock keeps someone out of the app, not out of the files.
Can I export my notes, or am I locked in?
You can export everything at any time, generated entirely on your device: Markdown files in a zip with attachments included, a full JSON backup, or self-contained HTML - per note or for the whole account.
Import works too: bring notes in from Obsidian, Apple Notes, Google Keep, Standard Notes, Simplenote, and Samsung Notes. Lock-in is not part of the business model.
Can I print a note or save it as a PDF?
Yes. Right-click a note, or open its share menu, and choose "Print / Save as PDF". Your system print dialog opens, so you can send it to a printer or save a PDF from there. The page renders clean on white with your formatting intact, whatever theme you use in the app.
It is generated on your device like every other export, so nothing is uploaded to produce it. For several notes at once, select them and export as HTML: you get one printable page per note. The "Doctor PDF" under Statistics is a separate, purpose-built wellness report and needs Pro.
What is the best way to back up my notes?
For a full safety net: "PrivacyNotes backup (.zip)" under Settings > Import & Export > Export. It contains everything - notes, journals, vault, tasks, images, audio, files - and restores completely via the Restore tab, into any vault. It is readable on your disk, so store it somewhere you trust: an encrypted disk, not a shared drive.
"Encrypted backup (.pnbackup)" is the opposite trade: safe to park anywhere because it is unreadable without your phrase, but it covers text and metadata only (no images or files) and restores only into the same account that created it - which makes it useless if you ever move to a new phrase. "Text backup (.json)" and the HTML archive are portability formats rather than restore formats, and the "Vault export (.json)" is Bitwarden-compatible plaintext for password managers.
Why keep local backups at all, when everything syncs? Because sync is not a backup: it faithfully propagates deletions, including, in the worst case, a compromised server dropping data that your devices then mirror. A periodic full backup on your own disk is the one copy no server event can touch. Export before big imports, before leaving, and on a rhythm you will actually keep.
How do I restore a backup?
Open Settings > Import & Export > Restore and pick the format you have. "Full backup (.zip)" takes the complete export: notes, journals, vault items, tasks, images, audio, and files. "Encrypted backup (.pnbackup)" takes the text-only encrypted export. Your file is read and decrypted on your device, and restoring is free on every tier.
Everything arrives as new items and nothing you already have is overwritten, so restoring the same file twice leaves you with two copies of every note. There is no automatic dedupe yet. A .pnbackup restores only into the account that created it, because it is locked to that phrase key, while a .zip restores into any vault. That is why the .zip is the one to keep (which backup to make).
What happens if I clear my browser data or cookies?
The web app keeps your notes in your browser's own storage, so clearing site data for PrivacyNotes wipes the local copy and signs you out. Everything that already synced is safe: sign in with your 12-word phrase and it comes back. Anything that had not synced yet is gone, because we never had a copy of it.
So do two things. Check that the footer says "Synced" before you clear anything, and keep your phrase in a password manager, because a cleared browser cannot ask you nicely for it. The desktop and mobile apps are not affected at all: they keep their own storage, which a browser cleanup never touches.
What counts against my storage, and how do I free space?
Everything you sync, at its encrypted size: note text, images, audio recordings, and file attachments. The bar under Settings > Storage shows the total; each note's own footprint is listed in its note options as "Storage used". Trashed notes still count until the trash is emptied.
To free space fast, open Files, sort by Size, and delete the biggest items - attachments dwarf text in almost every account. Then empty the trash: the Trash view shows how much space "Empty" will free. Text alone almost never fills a quota; even the free 50 MB holds tens of thousands of plain notes.
I deleted files but my storage did not go down. Why?
Your space is already free. The moment the delete syncs, those bytes stop counting against your quota, on the server as much as on this device. If the bar still shows the old figure, press the refresh icon beside it: that recounts from the server and leaves out everything queued for deletion. A device that was offline keeps its own last count until it catches up.
The "few days" the app mentions is about the encrypted file itself, not about your quota, and that wait is deliberate. Deleting a file from storage is permanent, with no trash to fish it back out of. A device that has not finished syncing holds an incomplete picture of your notes, so it could delete an image that another note still shows. A file therefore waits at least 24 hours, and only a device that has completed a clean sync removes it. The patience costs you nothing, because the space was credited the day you deleted.
What files can I attach, and how big can they be?
Any file type: images, PDFs, audio, archives, whatever you drop in. Every file is encrypted on your device before upload, exactly like note text, and the Files view collects all attachments in one place.
The per-file limit is 5 MB on the free plan and 50 MB on Pro. Files count against your total sync storage (50 MB free, 500 MB on Pro, expandable to 5.5 GB with storage add-ons), and the storage bar in Settings > Storage always shows where you stand.
Why did my file upload fail?
Two limits apply, and the error tells you which one you hit. Per file: 5 MB on Free, 50 MB on Pro, 100 MB with any storage add-on. In total: everything you sync must fit your account's storage (50 MB Free, 500 MB Pro, more with add-ons), so a full quota fails uploads even when the file itself is small. Any file type is accepted - there is no format restriction.
Check the storage bar in the Files view or under Settings > Storage, then pick the cheapest fix: free up space, upgrade, or shrink the file (phone photos are often multi-MB originals; a compressed JPEG is a fraction of the size). Uploads also need a connection: files do not queue while offline.
Why did notes disappear from my trash?
Trash is not an archive: by default, anything in it is permanently deleted after 30 days. The switch sits in the Trash view itself, labeled "Auto-delete after 30 days" - turn it off there if you want trash kept forever, and the setting syncs to all your devices. The cleanup runs on your device when the app opens, because the server cannot see which encrypted notes are trashed.
Permanently deleted means gone: no server copy and no recovery path. If you use trash as a someday-maybe pile, disable auto-delete or restore notes before day 30. Until then, trashed notes still count toward your storage - "Empty" in the same view frees that space immediately.
Can I get an older version of a note back?
Yes, with Pro. Open the note's "..." menu and choose "Note history" to browse and restore up to 20 previous versions. Restoring loses nothing: the current text is saved as a version first, so you can step back and forth. Versions are encrypted like the note itself, so we cannot read them either.
Two limits worth knowing. A snapshot is taken at most once a minute, so two edits seconds apart share one version. And this is the one Pro feature that needs the server, so it does not run in the demo and it stops recording if a Pro plan lapses. Every tier has the trash, which holds a deleted note for 30 days.
What is the Vault?
The Vault is a dedicated section for structured secrets: logins with usernames and passwords, credit and debit cards, and SSH keys. Entries get proper fields instead of free text, logins display a site icon, and everything is end-to-end encrypted like the rest of your data.
It gives the handful of credentials that otherwise end up scattered across notes a tidy, protected home. Pair it with the app lock and PIN protection for a second gate on your most sensitive entries. A Bitwarden import lands here automatically.
Can the Vault store my 2FA authenticator keys (TOTP / MFA codes)?
Yes. A Vault login has a "2FA code" field that accepts either a base32 secret or a whole otpauth:// link, and a Bitwarden import carries existing keys across. The key is encrypted, saved and synced on every tier, free included. Pro turns it into the live rotating code with its countdown, so you do not need a second app open beside this one.
One thing worth knowing, because the choice is yours. A password and its one-time code in the same vault means one unlocked device holds both factors. That is the same trade every password manager with built-in codes makes, and for most accounts the convenience wins, especially with the app lock or a PIN in front of it. If you would rather keep the two factors apart for your email or your bank, put those codes somewhere else and let the vault carry the rest.
How long can a single note be, and what do the size warnings mean?
Type as much as you like - for normal notes, size never comes up. As a single note grows very large, a small hint appears beneath it and escalates in three steps: around 50,000 words it notes the note is getting long and may lag on slower devices; around 75,000 words it turns amber, meaning editing may start to stutter; and around 100,000 words it suggests splitting the note because you are nearing the sync limit. These are guides, not hard stops, and nothing prevents you from continuing.
That sync limit is the only real ceiling. A single note can hold up to about 1 MB of text once encrypted - very roughly 120,000 words of typical English, and fewer with a non-Latin script or heavy formatting. A note past that keeps working and stays safe on the device you wrote it on, but that one note will not sync to your other devices (you will see a "failed to sync" notice). The rest of your notes are unaffected: one oversized note never blocks anything else.
The fix is easy: split a very long note into a few smaller ones. The content is identical, it syncs without trouble, and the editor stays fast. A live word count under each note lets you watch the size as you go. And if you were about to stress-test where the wall is, now you do not have to.
How do I leave PrivacyNotes completely?
Export first, delete second - both self-serve. Settings > Import & Export > Export covers every exit route: "PrivacyNotes backup (.zip)" for a complete copy, portable Markdown and HTML for your next notes app, and "Vault export (.json)" in Bitwarden-compatible format for your next password manager. Exports are generated on your device.
Then Settings > Account > "Delete account & data...": type DELETE, and your synced notes, files, devices, settings, and the account itself are permanently removed with no retention window (details). An active storage add-on must be cancelled first under Settings > Storage. A phrase-only account leaves nothing behind to scrub, because we never knew who you were. No dark patterns and no win-back emails - your data is yours, including on the way out.
How does PrivacyNotes handle GDPR and my data rights?
Mostly by holding as little as possible. Sign up with a phrase and there is no name, email, or identity on file to request: your data is ciphertext under a random public key, hosted in Zurich, Switzerland. Sign in with Google, Apple, or GitHub and exactly one identifier exists - the email behind that login, linked to that key. Billing details for Pro live with Paddle, the merchant of record, not with us.
Every right is self-serve and immediate, no request form needed: access and portability are Settings > Import & Export (full export in open formats), erasure is Settings > Account > "Delete account & data..." with no retention window, and rectification is editing your notes. The formal version, including how to reach us for anything the app cannot do itself, lives in the privacy policy.
What happens to my notes if PrivacyNotes shuts down?
You lose nothing. The complete dataset is already on your device because the app is local-first, and export to Markdown, JSON, or HTML works entirely offline.
The encryption layer is also published as open core, so the format stays independently readable even in a world where our servers vanish overnight.
// Pricing & Pro
What is free and what is Pro?
Free is the full product, not a teaser: end-to-end encrypted notes, tasks, journal, and vault, offline use, import and export - on up to 2 devices with 50 MB of sync storage.
Pro is a one-time purchase that adds unlimited devices, 500 MB of sync storage (expandable), note version history, larger file attachments, note locking and PIN protection, advanced wellness tracking, zen mode, and all color themes.
How can a one-time payment fund a sync service forever?
Because the service is deliberately cheap to run. The app is local-first and notes are small encrypted blobs, so the server does little more than store them and relay them between your devices. No analytics pipeline, no AI features burning compute, no support department.
The one cost that does grow over time is storage, and that is priced accordingly: storage beyond the included 500 MB is a small yearly add-on. One-time costs are priced once, recurring costs recur. The model only has to pay for itself, and it does.
I bought Pro on one platform. Do I have it everywhere?
Yes. Pro is attached to your account, not to a device, platform, or store. Buy it once, sign in with the same phrase (or the same Google, Apple, or GitHub login) anywhere, and Pro is active there too.
That includes platforms that do not exist yet: when a new app ships, your existing Pro comes along at no extra cost.
Can my family share one account or one Pro purchase?
An account is one 12-word phrase, and whoever holds that phrase holds everything in it: every note, every vault entry, on every device. So a shared account is not a feature, it is a decision to have no privacy from each other. Pro is bought per account, and there is no family plan today.
For two people who want their own notes, two accounts is the answer, and each one gets 2 devices and 50 MB without paying anything. To hand over one specific thing, send a burn note rather than your phrase. If a shared household account really is what you want, it works fine: keep the phrase in a shared password-manager entry, and remember that a person you remove later already had access to everything.
Can I use PrivacyNotes at work, and is there a team plan?
You can use it at work, and plenty of people do. What does not exist is a team plan: no shared workspace, no admin console, no central billing, and no way for a company to read or recover an employee's notes. Each person buys their own Pro and holds their own phrase.
That last part is the one to weigh before you standardize on it. Zero-knowledge encryption means an employer cannot restore what a leaver walked away with, and that is the same property that makes the app right for a journalist and wrong for a compliance department. If your organization needs key escrow or audit logs, we are honestly not the tool for it.
I paid for Pro but it is not active. What now?
Give it a minute, then reload the app. After checkout the app polls for about 20 seconds and unlocks by itself, and a reload re-checks Pro status on launch. If the payment landed but activation lags, a banner says "Payment received but Pro activation is taking longer than usual" - that state resolves itself in nearly all cases. In store builds, a purchase that fails to validate retries when you restart the app, and a purchase that never activates is refunded by the store automatically within 3 days.
Still locked? It is almost always an account mismatch: Pro attaches to the account that was signed in at purchase, so a different phrase - or a Google, Apple, or GitHub login instead of your phrase vault - is a different account. Compare the Account ID under Settings > ID & Sync on the device that bought it. If it is genuinely stuck, report it and include that Account ID: it identifies the purchase and reveals nothing about your notes.
How do storage add-ons work?
Pro includes 500 MB of encrypted sync storage. If you need more, add-on packages stack on top: 1 GB for $4.80 per year, 2 GB for $8.40, or 5 GB for $18, up to 5.5 GB in total. Add-ons are the only recurring purchase in the product, because storage is the only thing that costs us money every month you use it.
Everything is managed under Settings > Storage: switch to a bigger package (you pay only the prorated difference) or cancel anytime and keep the space until the period you paid for ends. Pro itself is yours forever either way.
How do I change or cancel my storage add-on?
Settings > Storage is the control panel. Upgrading to a bigger package applies immediately, and the confirmation shows the exact prorated amount charged today before you commit; the renewal date does not move. "Cancel storage" keeps your extra space until the end of the period you already paid for. Downgrading is not available yet - the interim path is cancel, then buy the smaller package when the period ends.
If your data still fits the remaining cap after expiry, that is the end of it; if not, nothing is deleted and the 90-day over-quota lifecycle begins. A failed renewal shows a banner with an "Update card" link to fix payment in Paddle. If you subscribed inside a store build, the store bills you, so cancellation happens in the store's own subscription settings instead.
Do purchases carry over between the web, Google Play, and the App Store?
Yes. Pro and storage attach to your account, not to a platform or store. Buy on the web and every app you sign into is Pro, including store builds; buy inside a store build and the web and desktop apps unlock the same way. There is no "restore purchases" button because signing in is the restore - the entitlement follows the account.
The one difference is who bills you. Web purchases run through Paddle and are managed in the app under Settings > Storage. Purchases made inside a store build (Google Play or the App Store, once those apps ship) are billed by that store: recurring storage is cancelled in the store's subscription settings, and refunds follow the store's process. Either way it is the same account and the same Pro everywhere - including platforms that do not exist yet.
What is the refund policy?
30 days, no questions asked. If Pro is not for you, request a full refund within 30 days of purchase and it goes back to the original payment method. Customers in the EU additionally keep their statutory 14-day right of withdrawal.
Payments are processed by Paddle, our merchant of record, so refunds are handled by Paddle directly: reply to your purchase receipt email or visit paddle.net. The full policy lives in the terms of service.
What do you learn about me when I pay?
Less than you might expect. Checkout runs through Paddle, the merchant of record: your name, card number, and billing address go to Paddle for payment and tax purposes and never touch our servers.
What reaches us is a confirmation that the public key of your account is now Pro, plus the order amount. The billing relationship, including the receipt email you enter at checkout, stays with Paddle. So a phrase-only account remains pseudonymous to us even as a paying customer: we know that you paid, not who you are.
Can I buy Pro without revealing who I am?
Yes, with two standard tools. For the receipt, use an email alias: Apple Hide My Email, DuckDuckGo Email Protection, SimpleLogin, Firefox Relay, or addy.io all forward to your real inbox without exposing it. For the payment, use a masked card: privacy.com in the US generates virtual cards that work with any name you type, and many banks and services elsewhere (Revolut, for example) offer disposable virtual cards that do the same job.
At checkout, Paddle asks for an email, a payment method, and a country (plus a postal code in some regions) to calculate tax. The alias receives the receipt, the masked card carries whatever name you gave it, and the tax location narrows you to a region, nothing more. Keep the alias alive though: the receipt email is your proof of purchase and your channel for a refund.
Combined with a phrase account, no single party ends up holding the full picture: your bank sees a card top-up, Paddle sees an alias and a masked card, and we see only that a public key became Pro.
// Apps & platforms
Which platforms does PrivacyNotes run on?
Web, macOS, Windows, Linux, and Android today, with iOS coming soon. Every app is built from the same core with the same end-to-end encryption and syncs through the same account. The downloads section always has the latest builds.
The native apps need macOS 13 or newer, Windows 10 or newer, Android 7.0 or newer, or a Linux release with webkit2gtk 4.1 (Ubuntu 22.04+, Debian 12+, or equivalent). iOS will need iOS 15 or newer. Below those versions the app will not install or start, so use the web app instead.
The web app is a first-class citizen, not a fallback: it keeps a full local copy of your data and works offline, so any modern browser is always a way in.
How do I check that the app I downloaded is genuine?
Every build we ship is signed, and your operating system checks that signature before it runs anything. macOS builds are signed and notarized by Apple. Windows installers carry an Authenticode signature you can read under Properties > Digital Signatures. The Android APK is signed with our own key, which is why Android refuses any update that is not ours. The desktop apps also reject an update that is not signed with our key.
Download only from PrivacyNotes.app or from our releases on GitHub, which lists every version. We do not publish per-file checksums, and one would prove less than it looks: a checksum sits on the same site as the file, so anyone able to swap the file can swap the number beside it. A signature is checked against a key that is not on our website at all.
I asked for a feature or reported a bug. How long until it ships?
Often days. Small requests and bug reports usually land in the next release, and releases go out most weeks rather than a few times a year. The changelog is the record: every entry is dated, written in plain language, and says what changed. Read a month of it and you will know exactly what to expect from us before you commit anything to the app.
Part of how we keep that pace is AI assistance on the interface work, and we would rather say so plainly than have you wonder. It means a request from one person is worth building, where a small team would normally have to say no to everything except the top of the list. It does not mean nobody is looking: every change is reviewed by a person, checked by the automated test suite, and shipped under our name. The encryption layer and the sync protocol are the exception and always will be. They move slowly, they are reviewed line by line, they are tested against published reference vectors, and they are public so you can read them instead of trusting us.
The app itself has no AI features and never sends your notes anywhere (details). That is a separate promise, and it does not change.
Will the Android app update itself?
Only if you installed it with Obtainium, which reads our releases and offers each new version as it ships. If you took the APK straight from our website, your phone will not update it on its own, because Android does not auto-update an app that did not come from a store. Google Play is not live yet, so there is no store route today.
The website APK tells you instead. The app checks for a newer version and shows an "Update available" notice with a "Download" button. Tap Download, then open the downloaded file to install it over the old version, with your notes and settings untouched. The check only asks whether a newer version exists, it never touches your notes, which stay encrypted the whole time.
How do I install the Android app with Obtainium?
Obtainium is a free, open-source Android app that installs other apps straight from their release pages, and it is now the way we recommend installing PrivacyNotes on Android, because it is the only route that keeps itself current. Already have it? Tap the badge and it adds PrivacyNotes for you.
New to it? Install Obtainium first, then add an app and paste this in:
Obtainium reads our releases, picks the APK, and installs every new version as it ships. No Google account is involved at any point.
Obtainium is not our app, and Android still asks you to confirm each install, so an update arrives as a notification and one tap, not silently. The APK is the same build our download page serves, signed with the same key, so Obtainium adopts an app you already sideloaded: nothing to uninstall, nothing to sign in to again. Without it, the app can only tell you in-app that a version is ready.
Obtainium, the direct APK, or Google Play: which Android download?
Take Obtainium if you want the app to stay current on its own, and the direct APK if you would rather not run a second app for it. They hand you the same file signed with the same key, so you can move either way at any time: Obtainium adopts an APK you already sideloaded, and the website APK installs over an Obtainium one. Google Play is not live yet.
When Play does arrive, moving between it and our own builds will be the awkward one. Play signs with its own key, Android refuses an update whose signature changed, and the install fails with an "App not installed" style error. That switch means uninstalling first, which clears the app's local data, so confirm the app shows "Synced" and have your 12 words or a sign-in QR from another device ready before you start, not after.
Which languages does the app speak?
English, German, French, Italian, Spanish, Dutch, Polish, Czech, Catalan, Turkish, Swedish, Japanese, Korean, Traditional Chinese, Arabic, and Portuguese in both European and Brazilian variants. The app follows your system language by default, or you can pin one explicitly under Settings > Language on each device.
Translations are free for everyone, not a Pro perk. More languages are planned; if yours is missing, tell us on GitHub or Reddit.
Are the translations machine made?
Yes, and we would rather say so than pretend otherwise. We write the English ourselves. Every other language is machine translated against a style guide for that language, then checked automatically so no text is missing or silently left in English. What no check catches is a sentence that is technically correct and still sounds wrong to a native speaker.
So if you find one, report the translation: your language, the screen it is on, and what it should say instead. Corrections ship in the next release.
Still stuck? Ask your AI agent.
You get an answer in seconds instead of waiting for a reply. Your assistant reads all 84 answers and every import guide at once, so it can combine them, follow up on your question, and explain it in your own words. We never see any of it, because we do not run a chatbot.
Copy the prompt.
Paste it into ChatGPT, Claude, Gemini, or any other AI assistant.
Ask your question, in your own language.
Keep that chat open. Next time, ask straight away.
Show AI prompt
Answer my questions about PrivacyNotes using only its help center and its changelog.
Start here: https://privacynotes.app/llms-index.txt
It lists every question with the page that answers it. Fetch the one or two that match mine.
If you can only make one request, fetch https://privacynotes.app/llms-full.txt instead.
If you cannot fetch a .txt or .md file, read https://privacynotes.app/help and https://privacynotes.app/changelog instead.
For what changed, or where something moved, fetch https://privacynotes.app/changelog.md.
Rules:
- Use only those pages. If they do not answer something, say so instead of guessing.
- Never invent a feature, a menu path, a price, or a limit.
- End your reply with the "Source:" URL from the page you used, exactly as written.
- Reply in my language.
- Never ask me for my recovery phrase, my PIN, or the contents of a note.
If no question follows, ask me what I would like to know.
My first question:
Never paste your recovery phrase, your PIN, or a note into an AI.