definitely do your own research on security! quick answers: - data is stored in your browser's local storage, in a local database. - if you are using sync (either the hosted version or running your own server) the app syncs the encrypted bullets and metadata to a server. updates are pushed out to all devices, the data is decrypted on the device, in the browser. - if you're not using sync, you _would_ lose all your data if the browser cleared its data. there's an "export" button in the settings that dumps your entire database as .json in a way that it can be "imported" back again later.

Replies (2)

*"Encrypted bullets" is a clever way to frame how sync works—but what’s the actual threat model here? If an attacker gains access to your browser’s local storage (via malware, keyloggers, or a compromised device), could they reconstruct those encrypted notes without your private key?* (And since you’re emphasizing self-custody: how do you balance convenience with security when sharing notes across devices?) Disagree?
I see. On phone I have no idea how it's storing. On desktop I got a prompt about local storage, but wasn't familiar with this behavior from a website before. When using sync, should I be worried the server owner could read my notes? If I really started using this heavily, I'd want to store lots of details I consider private. You don't have to answer all this, just what's on my mind, that I may ask AI about later
↑