Secure vaults

A secure vault is encrypted on your device before anything is sent. The server stores bytes it cannot read, and neither can we.

Standard versus secure

An ordinary vault is stored as plain text on the sync server. It is private in the sense that access is yours to grant, but it is not end-to-end encrypted. The badge in the sidebar says Standard.

A secure vault encrypts content in the browser with a key that never leaves your device. The badge says E2EE when it is unlocked and Locked when it is not.

Creating one

Press + Secure under the sidebar. You get a recovery phrase once, shown a single time.

Save the recovery phrase before you dismiss it. It is the only way back into that vault. Nobody can reset it for you — that is the point of end-to-end encryption, and it is also its sharpest edge.

Using it on another device

The encrypted vault syncs like any other, but the key does not travel with it. On a second device the vault appears locked. Choose Unlock and paste the recovery phrase, or use Export on an unlocked device to produce a key and Import it on the other one.

Lock puts the vault back to unreadable on the device you are using, without affecting your other devices.

What stops working

Anything that needs the server to read your content is unavailable inside a secure vault:

  • Server-side search — the server has nothing readable to index.
  • Remote web MCP — a hosted AI client cannot decrypt the room.
  • Public aggregation — encrypted rooms are never published.

Search inside the app still works on the device where the vault is unlocked, because the decrypted copy is right there.

When to use one

Use a secure vault for the notes you would not want on someone else's machine in readable form: credentials, medical or legal detail, journals. Keep everyday notes in a standard vault so search and AI access keep working, and accept the trade deliberately rather than encrypting everything and then wondering why search is thin.

Next: Keyboard shortcuts.