Noter

Sync security

Updated 2026-10-01

Noter Sync keeps a vault the same on all of your devices.

Encryption

Noter Sync uses end-to-end encryption for every synced vault. There is no other mode.

What does end-to-end encryption mean?

Your device encrypts each file before it leaves the device. Only your own devices can decrypt it.

Galactus cannot read your notes. Neither can your internet provider or anyone else between your device and the sync service.

If someone breaks into the sync service, your files stay encrypted. Nobody can decrypt them without your vault password.

Noter does not encrypt the vault folder on your device. Turn on FileVault to protect the copy on your Mac.

What is encrypted?

  • The contents of every note and attachment
  • File and folder names
  • File change times

Each version of a file gets its own random key.

What can the sync service see?

  • Your account email and account ID
  • The name of each synced vault
  • Vault and device IDs, and each device's public key
  • A random ID for each file and each version, so it can tell which versions belong to the same file
  • Which device made each change
  • The size of each encrypted file, and how many encrypted pieces each version has
  • When changes happen, and which change follows which
  • Your IP address

The service uses this information to sign you in, sync changes, and track storage.

What encryption does Noter use?

Vault password
Argon2id with 64 MiB of memory, 3 passes, and a unique salt per vault
Files and metadata
XChaCha20-Poly1305 with 256-bit keys
Key derivation
HKDF-SHA-256
Signatures
Ed25519
Adding a device
HPKE (RFC 9180) with X25519
Connections
TLS 1.3, and secure WebSockets for live updates

Every change is signed by the device that made it.

Your vault password never leaves your device, and Noter does not store it.

Has Noter Sync had a security audit?

Not yet. No outside firm has audited Noter Sync.

Your vault password

What happens if I forget my vault password?

Nobody can reset or recover it, including Galactus.

Devices that already sync keep syncing. Your notes also stay on each device as normal files.

You need the password to add a device, remove a device, change the password, or unlock sync on a device.

How do I start over with a new password?

  1. Copy your vault folder to keep a backup.
  2. On every Mac, open Settings → Sync and choose Stop syncing on this Mac. On iPhone, open Settings and choose Disconnect.
  3. On your main Mac, open Settings → Sync and choose Delete next to the old vault.
  4. Enter a new vault password and choose Sync this vault.
  5. Wait until the status shows Up to date.
  6. On each other Mac, open a new empty folder in Noter. Open Settings → Sync, choose Sync next to the vault, and enter the new password.
  7. On iPhone, open Settings, choose Choose Vault, pick the vault, and enter the new password.

Deleting a vault

How do I delete a synced vault?

On a Mac, open Settings → Sync. Choose Delete next to the vault under Your synced vaults, or choose Delete synced vault for the vault that Mac syncs.

You do not need the vault password.

Deleting removes the vault and its history from the sync service and frees its storage. The notes on your devices stay where they are.

Convex backups keep a copy for up to 7 days. Encrypted backup archives made before the deletion keep a copy until those archives are deleted.

Hosting

Where is my data stored?

The sync service runs on Convex, in the AWS US East (N. Virginia) region.

Convex makes a daily backup and keeps it for 7 days.

Separate encrypted backup archives are stored in Vercel Blob.

Galactus accounts handle sign-in. Stripe handles payments.

Network access

Which domains does Noter Sync use?

On a network with a firewall, allow HTTPS to these domains:

auth.galactus.dev
Sign-in
optimistic-raven-661.convex.site
Sync requests
optimistic-raven-661.convex.cloud
Live change updates

Limitations

A new device trusts the service's history

A new device checks that every change is signed and matches your vault password. It cannot prove that the service shows the newest changes.

A device that has synced before detects if the service rolls its history back.

The service can hold back changes

A compromised service cannot read your notes or forge changes. It can stop delivering changes, or stop working.

Removing a device protects only future changes

A removed device cannot get new changes. It keeps the notes and keys that it already downloaded.

Weak passwords are allowed

Noter accepts any vault password. A short password is easier to guess if someone gets a copy of your encrypted vault. Use a long password and keep it in a password manager.

Not quantum-resistant

The encryption that adds a device is not designed to resist future quantum computers.

For account data and deletion requests, see Privacy.