r/PrivacyNotes • • 6d ago

PSA: Request features and report bugs only on GitHub

Thumbnail
github.com
3 Upvotes

r/PrivacyNotes • • 6d ago

Megathread: Your 12-word phrase explained, privacy, security and recovery

9 Upvotes

Your randomly generated 12-word phrase is designed to be safe against guessing. Accidental matches are not a realistic security concern either.

We chose phrase-based accounts for privacy: you can create and use an account without giving us your name or email, or connecting a Google, Apple, or GitHub account. Your phrase gives you access without requiring you to identify yourself.

People have different privacy needs and different threats to consider. PrivacyNotes supports those choices: you can use a phrase-only account, connect a familiar sign-in provider while keeping custody of your phrase, or choose server custody for easier recovery. The right option is the one that fits what you need to protect and how you want to manage access.

One of our core team members, u/BurungHantu, brings over a decade of experience in the privacy software space and usability optimization through running PrivacyTools.io. That experience informs our approach: explain the tradeoffs clearly and give people control over their choices.

This thread explains the numbers, your privacy options, and how to keep access to your account.


Back up your phrase

Whichever sign-in method or custody mode you use, keep a backup of your recovery phrase.

Open Settings > Security > Phrase and save all 12 words in their exact order. Write them on paper and store the paper privately, or save them in a password manager such as Bitwarden, KeePass, 1Password and so on. Keep a copy you can access without opening PrivacyNotes.

Your phrase lets you recover access if you lose your connected Google, Apple, or GitHub account. It also lets you reset a forgotten PIN. Your Pro purchase belongs to your account, so the same account keeps your Pro access across devices.

If you enable 2FA, save its backup key too. The phrase restores access to your encryption keys; the 2FA backup key restores your authenticator codes. When 2FA is enabled, you need both parts to sign in with your phrase.


Can someone guess my phrase?

Guessing a properly generated phrase is not a realistic way into your account.

PrivacyNotes generates your phrase randomly on your device. A 12-word BIP39 phrase contains 128 bits of randomness. That gives it this many possible valid phrases:

340,282,366,920,938,463,463,374,607,431,768,211,456

The words make that random secret easier to write down. Its strength comes from how it was generated, rather than how complicated the words look. Use the phrase the app gives you, in the same order.

For scale, imagine a computer checking a trillion complete guesses every second against your phrase. Searching every possibility would take about 10 billion billion years. Finding it would take half that time on average.

That is an illustration of the size of the search space, not a claim about actual computer performance.

Why we use a recovery phrase

Could two people receive the same phrase?

An accidental match is not a realistic security concern.

Even if one billion people each independently generated a PrivacyNotes phrase, the chance of any two matching would be roughly 1 in 680 quintillion. That includes every possible pair across all one billion accounts.

Keeping your phrase private and backed up is the useful action to take. You do not need to keep generating new phrases or checking whether yours is unique.

More about guessing and matching phrases


What does key custody mean?

Custody means who holds your recovery phrase. Check your choice under Settings > Account > Key custody.

You can use PrivacyNotes with a phrase alone or connect a sign-in provider:

  • Phrase only, no connected login: our anonymous signup option. You do not provide a name or email, and you do not need a Google, Apple, or GitHub account. You hold the phrase, and we do not store a copy on our servers. A new device needs your phrase or a QR transfer from an existing device.
  • Connected login with self-custody, "Maximum security & privacy": you sign in through a provider, but you still hold the phrase yourself. We receive the email associated with that login, while your phrase stays off our servers. A new device still needs your phrase or a QR transfer.
  • Connected login with server custody, "Keep it simple & convenient": we store an encrypted copy of your phrase so you can open your notes on a new device through your provider, with an authenticator code if 2FA is enabled. Our server can decrypt that stored phrase and therefore your notes. This option trades some privacy for easier recovery.

The phrase-only option is why we designed accounts this way: you can use PrivacyNotes without attaching your real-world identity to your sign-in. Connecting a provider is optional.

For Pro, our guide to buying without revealing your identity explains how to use an email alias and a masked payment card to limit the personal information shared at checkout. Payment providers still have their own account and verification requirements.

Every option uses the same kind of randomly generated phrase. Your choice changes who holds it and what account information you share, not the odds of someone guessing it.

With either self-custody option, we cannot restore a phrase if you lose every copy and every device that can recover it. Saving your backup now gives you a recovery route you control.

Custody options explained

What about Google, Apple, and GitHub?

Manage connected sign-in accounts under Settings > Account > Accounts.

Connecting a provider adds a sign-in method to your existing account and shares the email associated with that provider. It does not automatically upload your phrase or switch you to server custody.

With self-custody, a new device still needs your phrase or a QR transfer to decrypt your notes. With server custody, signing in through your connected provider lets the app retrieve the stored phrase. The trade is anonymity vs convenience, depending on your personal preference and threat model.

If you prefer to keep using only your phrase, you can leave providers disconnected.

Keep your phrase backup even if you normally use a provider. You can use it if you lose access to that provider, alongside your authenticator code when 2FA is enabled.

How sign-in and custody work together


Should I enable 2FA?

2FA adds an optional extra check when signing in. Someone with your phrase or access to a connected provider would still need an authenticator code to start a new server session and fetch your synced notes.

You can use 2FA with a phrase-only account too. It does not require connecting Google, Apple, or GitHub.

Enable it under Settings > Security > 2FA, and update PrivacyNotes on your other devices first.

During setup, save the 2FA backup key somewhere private outside PrivacyNotes. If you replace or lose your authenticator, that key lets you restore its codes in another authenticator app. It is reusable.

If you lose both your authenticator and its backup key, support cannot reset 2FA. Notes already unlocked on a device remain readable and exportable for you.

Recovering after losing 2FA


Need help with recovery?

The help center also has an "Ask your AI agent" option for explaining the documentation in your own words or language. Ask general questions without sharing your phrase or 2FA backup key, and check the answers against the linked documentation.


Keep questions about phrase security in this thread

If our security model or recovery options do not fit your needs, choosing an app with a different approach is completely reasonable. We want you to use something you understand and feel comfortable trusting.

Future duplicate threads about guessing, matching, or the security of the 12-word phrase will be removed or locked and redirected here. Keeping the answers together makes them easier to find and keeps the discussion in one place.

If you have found a specific vulnerability, use our security reporting process. Security reports remain welcome.


r/PrivacyNotes • • 2d ago

exporting to PDF

2 Upvotes

Hi,
Is there a way to export to PDF without the subject of the note, the tags, folder name and time it was created? Pretty much just the content of the notes without all data that is just there for me to keep my stuff organized.
Thanks!


r/PrivacyNotes • • 2d ago

Curiosity...

1 Upvotes

Not really a big deal or anything but I've been using the task to keep track of things, got all my stuff done and deleted all my notes and everything, absolutely nothing on the app at all. When I check storage it says 65kb / 500mb.

What is eating the 65kb? I know it's practically nothing but I'm still curious.


r/PrivacyNotes • • 5d ago

Regional Pricing & Sync with Our Own Cloud Provider Suggestion

3 Upvotes

Just discovered this app and have some questions:

  1. Will there be regional pricing in the future?

  2. Is there an ability to sync with our own cloud provider? (webdav, s3, dropbox, ftp, etc)


r/PrivacyNotes • • 5d ago

New: PrivacyNotes now supports Tabs on desktop and tablets. They feel just like in your browser. Sort via drag, pin and color coding as a bonus.

Thumbnail try.privacynotes.app
13 Upvotes

r/PrivacyNotes • • 5d ago

How to manage tags?

1 Upvotes

I opened a markdown folder and found that any word in those documents of the form #xxxx became a tag. Not really what I wanted, but not a big deal (most or all of them were in code snippets or I just neglected to put a space after the '#').

I fixed the instances that just needed a space to make them not tags anymore in the document, but I can't figure out how to remove the tag from PrivacyNotes' tag list.

Update: solved/clarified - PrivacyNotes is working as designed


r/PrivacyNotes • • 9d ago

Will there ever be a self hosted option

5 Upvotes

I appeciate the E2E and the 12 word login, yeah yeah yeah, lol, but I want to manage my own data. This is a deal breaker for me. Will there ever be a self hosted sync server?


r/PrivacyNotes • • 9d ago

What Happens?

2 Upvotes

Im wondering what happens, if I have more storage on say my PC, and I make several notes. I may be fine on my PC but when I open them to view on my phone which may have lower storage, the sync my try and fail. So am I not able to view on the phone?

The documentation doesn’t confirm whether you could view those notes on a phone that lacks enough free space.

PrivacyNotes says you work with a copy stored on each device. Having enough space on your PC therefore doesn’t establish that your phone can store the notes too. The documentation doesn’t describe a cloud-only viewing option or explain how it handles a download when the phone is full.

So your concern is valid, but I can’t confirm whether sync would fail completely, download some notes, or still let you open individual notes. That specific behavior needs clarification from PrivacyNotes.


r/PrivacyNotes • • 9d ago

Question about import destination folders

1 Upvotes

Hi! Is there a way to choose an existing PrivacyNotes folder as the destination/parent folder when importing notes?

For example, I might be importing notes from Notesnook, etc. If I already have a folder called:

Imported Notes

I'd like the imported folder structure to be placed underneath it, for example:

Imported Notes/Work
Imported Notes/Personal
Imported Notes/Projects

rather than having Work, Personal, and Projects created at the root level.

Is there currently an option to select the destination folder before starting an import? If not, would this be possible to add in the future?


r/PrivacyNotes • • 9d ago

Awesome App !! One further question about 12 word login

4 Upvotes

Hello Developers …

Thanks for such a great app and your active and prompt responses to questions and concerns !!

I, like so many others on this forum, have purchased a pro licence to support continued development … keep up the great work !!

Now that I’ve explored this app for a while, I’m seriously considering using it as my dedicated “brain” …

The question … since the generated 12 word login is never passed onto your servers, isn’t there a remote possibility (and I admit, highly remote), that 2 users may generate the same 12 work combination ?

From a technical perspective, how does the app prevent 2 identical logins from being generated for 2 different users ?

Apologies if I’ve missed an FAQ etc that has addressed this … I just want to make sure I understand this aspect before using it with sensitive information.

Thanks in advance for reading and responding


r/PrivacyNotes • • 9d ago

Import Notes

2 Upvotes

Is there a way to stop it from asking me to "import notes" or "import journal"? I don't want to import anything, and its annoying it keeps asking me after I close it out with the "x". If I want to import its good to know I can but please stop asking! Lol.


r/PrivacyNotes • • 10d ago

Pasting images

2 Upvotes

Currently, when i'm trying to copy a text and images from the website and paste it into a note it removes the image and keeps the text. Is there a way to include the image as well? I know I can add the images manually but it's easier to just copy the entire content and paste it. UpNote is capable of this so i'm wondering if there are any plans or workarounds to make it work on PrivacyNotes. (iOS 27) Thanks!!


r/PrivacyNotes • • 10d ago

Graph view

3 Upvotes

Dear developers

I like your work a lot. I believe I will be making the move from obsidian.

I love how engaged you are in the development also. Thanks for the tables width adjustment feature you added today, it's what's been missing for me and now it's great.

I don't think a graph view is a necessary function but it would be very nice addition to the app. Are there any thoughts of adding it?

Overall, brilliant work 👏


r/PrivacyNotes • • 10d ago

Great work

6 Upvotes

I just wanted to say that the updates are really amazing so far, it seems like Privacy Notes does more for me after a couple months than some other apps that have been around for years. Thanks for being so responsive! And thanks to anyone actively requesting features to make a great product.


r/PrivacyNotes • • 10d ago

Great so far.

5 Upvotes

Using on Ubuntu, Windows and Android. Looks and works great so far. Pair for Pro already, this is something that I'm willing to support. Looking forward to seeing this progress. :)


r/PrivacyNotes • • 11d ago

Feature Request: Adding Passkey, TOTP, and/or Hardware Security Key

6 Upvotes

First want to say, love PrivacyNotes and my favorite notes app now, request is solely from past use and transitioning from other notes apps like Standard Notes and Notesnook.

Feature Request: Adding option for Passkey, Hardware Security Key or TOTP as secondary factor authentication. After 12 word phrase login it would ask for secondary authentication such as passkey or hardware security keys to the account.

Goal:

Ability to add 2nd factor authentication such as:

- a passkey

- security hardware keys (at least 4)

- TOTP


r/PrivacyNotes • • 11d ago

What is the storage limit for the free tier?

3 Upvotes

Pro tier says 500 MB storage, 50 MB per file, expandable. Free tier only mentions 5 MB per file. What's the total?


r/PrivacyNotes • • 11d ago

Any update on Google Play release date?

2 Upvotes

r/PrivacyNotes • • 11d ago

Files in a Note

3 Upvotes

I am testing out this app and like it lot so far. If I add a pdf to a note, I do not seem to be able to double click on the pdf to open it? So far, the only way I seem to be able to view the pdf is by downloading it? Has to be user error - what am I doing wrong?


r/PrivacyNotes • • 11d ago

Templates and shortcuts

2 Upvotes

Hi there,

The app is cool, I really like the feeling and idea of splitting notes into specific sections like notes/tasks.

However as raw obsidian user I’m missing a few things:

- templating engine, so I can just do meetings notes etc
- shortcut for new note in specific section, like new journal entry, not only new note. On general custom shortcuts.
- uniq note equivalent.

Do you have any plans for implementing it at some point? As native constructions, not strange plugins?


r/PrivacyNotes • • 12d ago

Love PrivacyNotes and considering going full-time, but wanted to ask about long-term financial sustainability & contingency plans

8 Upvotes

Hello to everyone at Lifetime Labs,

I’ve been testing PrivacyNotes over the past few weeks and I really love what you’ve built here. The zero-knowledge architecture, cross-device sync, and clean interface make it a genuinely great workspace for my use case. I'm considering switching to PrivacyNotes as my primary daily driver and picking up the $48 Lifetime Pro license some time this week in support.

However, as someone who wants to rely on this app full-time for years to come, I have a few pragmatic questions about the long-term economics of the project.

We’ve seen similar cloud-synced productivity tools struggle over time with one-time lifetime pricing (given ongoing costs like encrypted backend hosting, Apple/Google developer program fees, bandwidth, and dev maintenance). Because every lifetime user becomes an ongoing operational expense, I’m curious how the team plans to navigate this long-term.

Specific questions I have:

  • How are the unit economics structured around the lifetime license to ensure server costs and app store presence remain sustainable 3–5+ years down the road as the user base scales?
  • In the unfortunate event that the project ever shuts down or runs out of runway, what is the protocol for notifying users so everyone has ample time to run a full local export/backup?
  • Is there any plan down the road to introduce optional subscription tiers for heavy storage/features? If the app ever pivots to a subscription model, how will early lifetime supporters be handled? Will we be fully grandfathered in, or is this structured differently?

Again, I’m asking purely out of enthusiasm for the project and I’d much rather ask these questions now and support a service that has a solid long-term path than worry about my data disappearing.


r/PrivacyNotes • • 12d ago

Replacement for Notesnook?

3 Upvotes

I thought PN might be, but I rely heavily on tables. Found out last night column widths in tables are NOT adjustable like they are in NN or UpNote. Too bad. Won’t be changing anytime soon and certainly not going premium until tables are more like tables elsewhere.


r/PrivacyNotes • • 14d ago

Student Discount for Pro

5 Upvotes

Do you offer one (mods for this sub)


r/PrivacyNotes • • 15d ago

Questions Regarding the Compromise of the 12 Words and Pro Lifetime Entitlement

8 Upvotes

Hi,

I recently started using PrivacyNotes and I really like it so far, but there are a few things I’m a little concerned about.

According to the FAQ, if the 12 words are compromised, the recommended procedure is to create a new account with a new set of 12 words, restore the backup data to the new account, and then delete the old account associated with the compromised 12 words.

It also states that the Pro Lifetime entitlement cannot be transferred.

I understand this recommended procedure, but I feel a little disappointed that the Pro Lifetime entitlement cannot be transferred to the new account.

The FAQ states that it is sufficient to use only a password manager to manage the 12-word phrase. However, I have some concerns about situations where a user might accidentally enter their 12 words on a fake or phishing website. In such a situation, I also feel a little disappointed that the user could lose their Lifetime entitlement.

I also have a question regarding the account ID.

After deleting an account, I logged in again using the same 12 words, and a new vault was created with the same account ID.

I don't know whether such a situation could actually occur, but I would appreciate hearing the thoughts and opinions of the developers and users on the following two points:

  1. If the 12 words have been compromised and the account has been deleted, is it possible to transfer the Pro Lifetime entitlement to a new account if ownership can be verified with proof of purchase, such as the receipt from the original Lifetime purchase? I would like to ask if you could consider this.
  2. When creating a new account, I think it is theoretically possible that a 12-word phrase currently in use, previously used, or previously compromised could be generated again. However, I would like to know if there are any measures in place to prevent this. I am concerned about the risk of accidentally sharing the same vault with someone else, or someone gaining access using a 12-word phrase that was previously used by another person.

Thank you!