Treat the vault as burned. A phrase cannot be changed or rotated, because the phrase is the key everything is encrypted under - so the fix is moving to a fresh vault. First, in the old account, export everything: Settings > Import & Export > Export > "PrivacyNotes backup (.zip)".
Sign out, create a new vault (new 12 words), and bring the export back in via Settings > Import & Export > Restore > "Full backup (.zip)". Then delete the old account from any device still signed into it: Settings > Account > "Delete account & data...". That removes its synced data and shuts out anyone holding the old phrase. If you signed in with Google, Apple, or GitHub, delete the old account first, then sign in with that same login again to start the fresh vault.
Two things to handle first: cancel any active storage add-on, which deletion requires, and note that Pro stays with the account it was bought on rather than moving to the new vault. Then keep the new phrase in a password manager and nowhere else, which is the whole of the prevention.
Help & FAQ
Answers and step-by-step guides: security, sync, pricing, and switching from other apps.
You get an answer in seconds instead of waiting for a reply. Your assistant reads all 92 answers and every import guide at once, so it can combine them, follow up on your question, and explain it in your own words. We never see any of it, because we do not run a chatbot.
Answer my questions about PrivacyNotes using only its help center, its changelog and its security documentation. Start here: https://privacynotes.app/llms-index.txt It lists every question with the page that answers it. Fetch the one or two that match mine. If you can only make one request, fetch https://privacynotes.app/llms-full.txt instead. If you cannot fetch a .txt or .md file, read https://privacynotes.app/help, https://privacynotes.app/changelog and https://github.com/LifetimeLabsDev/PrivacyNotes.app instead. For what changed, or where something moved, fetch https://privacynotes.app/changelog.md. For how the encryption works, what the server can read, or how to check any of it yourself, fetch https://privacynotes.app/docs/index.md and follow it to one of the documents it lists. That index is a router: cite the document, never the index. Rules: - Use only those pages. If they do not answer something, say so instead of guessing. - Never invent a feature, a menu path, a price, or a limit. - End your reply with the "Source:" URL from the page you used, exactly as written. - Answer in the same language as my question. - Never ask me for my recovery phrase, my PIN, or the contents of a note. If no question follows, ask me what I would like to know. My first question:
Never paste your recovery phrase, your PIN, or a note into an AI.