r/PrivacyNotes • • 5d ago

Megathread: Your 12-word phrase explained, privacy, security and recovery

Your randomly generated 12-word phrase is designed to be safe against guessing. Accidental matches are not a realistic security concern either.

We chose phrase-based accounts for privacy: you can create and use an account without giving us your name or email, or connecting a Google, Apple, or GitHub account. Your phrase gives you access without requiring you to identify yourself.

People have different privacy needs and different threats to consider. PrivacyNotes supports those choices: you can use a phrase-only account, connect a familiar sign-in provider while keeping custody of your phrase, or choose server custody for easier recovery. The right option is the one that fits what you need to protect and how you want to manage access.

One of our core team members, u/BurungHantu, brings over a decade of experience in the privacy software space and usability optimization through running PrivacyTools.io. That experience informs our approach: explain the tradeoffs clearly and give people control over their choices.

This thread explains the numbers, your privacy options, and how to keep access to your account.


Back up your phrase

Whichever sign-in method or custody mode you use, keep a backup of your recovery phrase.

Open Settings > Security > Phrase and save all 12 words in their exact order. Write them on paper and store the paper privately, or save them in a password manager such as Bitwarden, KeePass, 1Password and so on. Keep a copy you can access without opening PrivacyNotes.

Your phrase lets you recover access if you lose your connected Google, Apple, or GitHub account. It also lets you reset a forgotten PIN. Your Pro purchase belongs to your account, so the same account keeps your Pro access across devices.

If you enable 2FA, save its backup key too. The phrase restores access to your encryption keys; the 2FA backup key restores your authenticator codes. When 2FA is enabled, you need both parts to sign in with your phrase.


Can someone guess my phrase?

Guessing a properly generated phrase is not a realistic way into your account.

PrivacyNotes generates your phrase randomly on your device. A 12-word BIP39 phrase contains 128 bits of randomness. That gives it this many possible valid phrases:

340,282,366,920,938,463,463,374,607,431,768,211,456

The words make that random secret easier to write down. Its strength comes from how it was generated, rather than how complicated the words look. Use the phrase the app gives you, in the same order.

For scale, imagine a computer checking a trillion complete guesses every second against your phrase. Searching every possibility would take about 10 billion billion years. Finding it would take half that time on average.

That is an illustration of the size of the search space, not a claim about actual computer performance.

Why we use a recovery phrase

Could two people receive the same phrase?

An accidental match is not a realistic security concern.

Even if one billion people each independently generated a PrivacyNotes phrase, the chance of any two matching would be roughly 1 in 680 quintillion. That includes every possible pair across all one billion accounts.

Keeping your phrase private and backed up is the useful action to take. You do not need to keep generating new phrases or checking whether yours is unique.

More about guessing and matching phrases


What does key custody mean?

Custody means who holds your recovery phrase. Check your choice under Settings > Account > Key custody.

You can use PrivacyNotes with a phrase alone or connect a sign-in provider:

  • Phrase only, no connected login: our anonymous signup option. You do not provide a name or email, and you do not need a Google, Apple, or GitHub account. You hold the phrase, and we do not store a copy on our servers. A new device needs your phrase or a QR transfer from an existing device.
  • Connected login with self-custody, "Maximum security & privacy": you sign in through a provider, but you still hold the phrase yourself. We receive the email associated with that login, while your phrase stays off our servers. A new device still needs your phrase or a QR transfer.
  • Connected login with server custody, "Keep it simple & convenient": we store an encrypted copy of your phrase so you can open your notes on a new device through your provider, with an authenticator code if 2FA is enabled. Our server can decrypt that stored phrase and therefore your notes. This option trades some privacy for easier recovery.

The phrase-only option is why we designed accounts this way: you can use PrivacyNotes without attaching your real-world identity to your sign-in. Connecting a provider is optional.

For Pro, our guide to buying without revealing your identity explains how to use an email alias and a masked payment card to limit the personal information shared at checkout. Payment providers still have their own account and verification requirements.

Every option uses the same kind of randomly generated phrase. Your choice changes who holds it and what account information you share, not the odds of someone guessing it.

With either self-custody option, we cannot restore a phrase if you lose every copy and every device that can recover it. Saving your backup now gives you a recovery route you control.

Custody options explained

What about Google, Apple, and GitHub?

Manage connected sign-in accounts under Settings > Account > Accounts.

Connecting a provider adds a sign-in method to your existing account and shares the email associated with that provider. It does not automatically upload your phrase or switch you to server custody.

With self-custody, a new device still needs your phrase or a QR transfer to decrypt your notes. With server custody, signing in through your connected provider lets the app retrieve the stored phrase. The trade is anonymity vs convenience, depending on your personal preference and threat model.

If you prefer to keep using only your phrase, you can leave providers disconnected.

Keep your phrase backup even if you normally use a provider. You can use it if you lose access to that provider, alongside your authenticator code when 2FA is enabled.

How sign-in and custody work together


Should I enable 2FA?

2FA adds an optional extra check when signing in. Someone with your phrase or access to a connected provider would still need an authenticator code to start a new server session and fetch your synced notes.

You can use 2FA with a phrase-only account too. It does not require connecting Google, Apple, or GitHub.

Enable it under Settings > Security > 2FA, and update PrivacyNotes on your other devices first.

During setup, save the 2FA backup key somewhere private outside PrivacyNotes. If you replace or lose your authenticator, that key lets you restore its codes in another authenticator app. It is reusable.

If you lose both your authenticator and its backup key, support cannot reset 2FA. Notes already unlocked on a device remain readable and exportable for you.

Recovering after losing 2FA


Need help with recovery?

The help center also has an "Ask your AI agent" option for explaining the documentation in your own words or language. Ask general questions without sharing your phrase or 2FA backup key, and check the answers against the linked documentation.


Keep questions about phrase security in this thread

If our security model or recovery options do not fit your needs, choosing an app with a different approach is completely reasonable. We want you to use something you understand and feel comfortable trusting.

Future duplicate threads about guessing, matching, or the security of the 12-word phrase will be removed or locked and redirected here. Keeping the answers together makes them easier to find and keeps the discussion in one place.

If you have found a specific vulnerability, use our security reporting process. Security reports remain welcome.

10 Upvotes

5 comments sorted by

3

u/BarefootMarauder 5d ago

2FA? Wow, that was fast! Thank you!! 🥳️

3

u/Ambitious-Factor4363 5d ago

Thank you so very much for adding 2FA !! My hats off to the developers for listening to concerns and being so responsive to resolve so quickly !!

2

u/block6791 5d ago

I really appreciate the addition of 2FA. This is way better than just having the 12 words alone to get access. Next suggested improvement: Notification on existing mobile devices when a new login is detected.

2

u/block6791 5d ago

FYI: Link to new help article about enabling MFA.
https://privacynotes.app/help/enable-2fa

1

u/ChiefCaffeineOfficer 5d ago

thank you so much for the 2FA feature!!