Sync security
Updated 2026-10-01
Noter Sync keeps a vault the same on all of your devices.
Encryption
Noter Sync uses end-to-end encryption for every synced vault. There is no other mode.
What does end-to-end encryption mean?
Your device encrypts each file before it leaves the device. Only your own devices can decrypt it.
Galactus cannot read your notes. Neither can your internet provider or anyone else between your device and the sync service.
If someone breaks into the sync service, your files stay encrypted. Nobody can decrypt them without your vault password.
Noter does not encrypt the vault folder on your device. Turn on FileVault to protect the copy on your Mac.
What is encrypted?
- The contents of every note and attachment
- File and folder names
- File change times
Each version of a file gets its own random key.
What can the sync service see?
- Your account email and account ID
- The name of each synced vault
- Vault and device IDs, and each device's public key
- A random ID for each file and each version, so it can tell which versions belong to the same file
- Which device made each change
- The size of each encrypted file, and how many encrypted pieces each version has
- When changes happen, and which change follows which
- Your IP address
The service uses this information to sign you in, sync changes, and track storage.
What encryption does Noter use?
- Vault password
- Argon2id with 64 MiB of memory, 3 passes, and a unique salt per vault
- Files and metadata
- XChaCha20-Poly1305 with 256-bit keys
- Key derivation
- HKDF-SHA-256
- Signatures
- Ed25519
- Adding a device
- HPKE (RFC 9180) with X25519
- Connections
- TLS 1.3, and secure WebSockets for live updates
Every change is signed by the device that made it.
Your vault password never leaves your device, and Noter does not store it.
Has Noter Sync had a security audit?
Not yet. No outside firm has audited Noter Sync.
Your vault password
What happens if I forget my vault password?
Nobody can reset or recover it, including Galactus.
Devices that already sync keep syncing. Your notes also stay on each device as normal files.
You need the password to add a device, remove a device, change the password, or unlock sync on a device.
How do I start over with a new password?
- Copy your vault folder to keep a backup.
- On every Mac, open Settings → Sync and choose Stop syncing on this Mac. On iPhone, open Settings and choose Disconnect.
- On your main Mac, open Settings → Sync and choose Delete next to the old vault.
- Enter a new vault password and choose Sync this vault.
- Wait until the status shows Up to date.
- On each other Mac, open a new empty folder in Noter. Open Settings → Sync, choose Sync next to the vault, and enter the new password.
- On iPhone, open Settings, choose Choose Vault, pick the vault, and enter the new password.
Deleting a vault
How do I delete a synced vault?
On a Mac, open Settings → Sync. Choose Delete next to the vault under Your synced vaults, or choose Delete synced vault for the vault that Mac syncs.
You do not need the vault password.
Deleting removes the vault and its history from the sync service and frees its storage. The notes on your devices stay where they are.
Convex backups keep a copy for up to 7 days. Encrypted backup archives made before the deletion keep a copy until those archives are deleted.
Hosting
Where is my data stored?
The sync service runs on Convex, in the AWS US East (N. Virginia) region.
Convex makes a daily backup and keeps it for 7 days.
Separate encrypted backup archives are stored in Vercel Blob.
Galactus accounts handle sign-in. Stripe handles payments.
Network access
Which domains does Noter Sync use?
On a network with a firewall, allow HTTPS to these domains:
- auth.galactus.dev
- Sign-in
- optimistic-raven-661.convex.site
- Sync requests
- optimistic-raven-661.convex.cloud
- Live change updates
Limitations
A new device trusts the service's history
A new device checks that every change is signed and matches your vault password. It cannot prove that the service shows the newest changes.
A device that has synced before detects if the service rolls its history back.
The service can hold back changes
A compromised service cannot read your notes or forge changes. It can stop delivering changes, or stop working.
Removing a device protects only future changes
A removed device cannot get new changes. It keeps the notes and keys that it already downloaded.
Weak passwords are allowed
Noter accepts any vault password. A short password is easier to guess if someone gets a copy of your encrypted vault. Use a long password and keep it in a password manager.
Not quantum-resistant
The encryption that adds a device is not designed to resist future quantum computers.
For account data and deletion requests, see Privacy.