Your data is yours.
Period.
memrynote is local-first, end-to-end encrypted, and open source. We built it for people who take ownership of their data seriously.
Zero-knowledge
We cannot see your notes, even if compelled. The math guarantees it.
Plain files
Standard Markdown on your disk. No proprietary format, no lock-in.
Sync without vault-key custody
Sync accounts manage billing and devices. Vault keys stay on your devices.
How we protect your data
Six layers of privacy, from storage to sync.
Local-first storage
Your notes are plain Markdown files stored in a folder you choose. No proprietary database, no vendor lock-in.
- Plain .md files on your filesystem
- Pick any folder — iCloud, Dropbox, or fully offline
- SQLite for metadata, FTS5 for search
- Zero cloud dependency for core functionality
End-to-end encryption
When you sync, every byte is encrypted before it leaves your device. We cannot read your data. Nobody can.
- libsodium (XChaCha20-Poly1305) for all sync traffic
- At-rest encryption for local database
- Keys derived on-device, never transmitted
- OS keychain for credential storage
Minimal telemetry
We collect anonymous usage analytics to improve the app. That is it. Your content never leaves your device.
- Anonymous feature-usage counters only
- No content, filenames, or metadata collected
- No third-party trackers or ad networks
- Telemetry can be fully disabled in settings
On-device AI
AI is optional and can be turned on or off. With a local model, your notes are never sent to OpenAI, Google, or anyone else.
- AI can be disabled fully in settings
- Local inference via on-device model
- No API calls to external AI providers
- Context stays in your process memory
- Works fully offline
Encrypted sync
Paid multi-device sync uses CRDTs for conflict-free merging. Devices approve each other with QR codes, and vault keys stay off the server.
- CRDT-based sync via Yjs
- Conflict-free, deterministic merging
- QR code device linking
- Incremental sync with per-field vector clocks
Open source
memrynote will be fully open source. Audit the code, verify our claims, build on top of it.
- Repository coming soon at github.com/memrynote/memry
- AGPL-3.0 license
- Reproducible builds planned
- Security audits welcome
How the encryption actually works
Your vault key is the only thing that can decrypt your notes, and it never touches our servers. When you set a passphrase, memrynote derives a wrapping key from it with Argon2id — the same memory-hard key derivation function recommended for password hashing — and uses that to unlock your vault key locally. From there, per-item data keys, per-blob keys, and per-document keys are derived to encrypt your notes, attachments, and edit history with XChaCha20-Poly1305 authenticated encryption.
Add a second device and memrynote never sends your vault key across the network in the clear. It seals a copy of the key to that device’s own X25519 public key, so only that device’s private key can open it. Revoking a device cuts its access immediately — no vault-wide key rotation required — though you can rotate the vault key entirely (say, after a lost laptop), and every linked device is resealed automatically.
What “zero-knowledge” actually means here
Zero-knowledge is a specific, checkable claim, not a marketing line. The sync server stores your note titles, bodies, properties, attachments, task fields, and search queries only as ciphertext — it never holds the keys required to read them. Every synced item also carries an Ed25519 signature over its metadata, including deletions, so a compromised or hostile server cannot silently forge a delete or alter what it stores without the signature failing to verify.
If memrynote’s servers were subpoenaed, seized, or breached tomorrow, what an attacker would get is encrypted blobs and signed metadata — not your notes. Local use never touches a server at all: notes, tasks, calendar, and journal all work fully offline, with sync as something you turn on, not something the app depends on.
Found a vulnerability?
We take security reports seriously. Reach out and we will respond within 24 hours.
kaan@memrynote.com