PrivacyNotes

Help & FAQ/Security & privacy

Why is there no two-factor authentication (2FA)?

Ask your AI agent instead

Because it is a deliberate tradeoff, not an oversight. The familiar kind of 2FA, a texted code or an authenticator app, exists to shore up weak, human-chosen passwords, and it leans on a shared secret and a recovery path held on a server. That is the exact attack surface the phrase model removes: your device proves it holds the key by signing a challenge, so our servers only ever receive a public key and a signature, never the phrase and never a password hash. Bolting a code on top would reintroduce the server-side machinery this design exists to avoid, while adding nothing against guessing, because 128 bits already closes that door.

The one kind of second factor that would genuinely add something is a phishing-resistant one, such as a hardware security key or a passkey, because the real residual risks are not guessing but phishing, malware, and a phrase that gets stolen or shoulder-surfed. On a device left unlocked, the app lock (PIN) and biometric unlock are the local backstop.

Beyond that, the phrase is the key, so back it up the day you create your account: keep it in a reputable password manager, or print it or write it down and store that copy somewhere safe. Never paste it into anything but the app itself.

Help & FAQ

Answers and step-by-step guides: security, sync, pricing, and switching from other apps.

Still stuck? Ask your AI agent.

You get an answer in seconds instead of waiting for a reply. Your assistant reads all 84 answers and every import guide at once, so it can combine them, follow up on your question, and explain it in your own words. We never see any of it, because we do not run a chatbot.

  1. Copy the prompt.
  2. Paste it into ChatGPT, Claude, Gemini, or any other AI assistant.
  3. Ask your question, in your own language.
  4. Keep that chat open. Next time, ask straight away.
Show AI prompt
Answer my questions about PrivacyNotes using only its help center and its changelog.

Start here: https://privacynotes.app/llms-index.txt
It lists every question with the page that answers it. Fetch the one or two that match mine.
If you can only make one request, fetch https://privacynotes.app/llms-full.txt instead.
If you cannot fetch a .txt or .md file, read https://privacynotes.app/help and https://privacynotes.app/changelog instead.

For what changed, or where something moved, fetch https://privacynotes.app/changelog.md.

Rules:
- Use only those pages. If they do not answer something, say so instead of guessing.
- Never invent a feature, a menu path, a price, or a limit.
- End your reply with the "Source:" URL from the page you used, exactly as written.
- Reply in my language.
- Never ask me for my recovery phrase, my PIN, or the contents of a note.

If no question follows, ask me what I would like to know.

My first question:

Never paste your recovery phrase, your PIN, or a note into an AI.