docs/help/contents/how-is-my-data-encrypted.md
Everything you write is encrypted on your own device before it is sent anywhere. The Notesnook server stores ciphertext it cannot open, which is why nobody here can read your notes — and why nobody here can recover them for you if you lose both your password and your recovery key.
::: info This is an explanation, not a specification This page describes how the encryption works in practice. It is not a formal spec.
:::
| Purpose | Algorithm |
|---|---|
| Encrypting and decrypting your data | XChaCha20-Poly1305-IETF |
| Deriving your master key from your password | Argon2i |
| Hashing your password for the server | Argon2id |
All of it comes from libsodium. Web, desktop and mobile use the same library for every cryptographic operation, so a note encrypted on one platform decrypts identically on the others.
When you sign up for an account, the app takes your password and hashes it using Argon2 with a predictable per user salt.
This predictable salt is generated using a fixed client salt + your email.
::: info Your password never leaves your device Only the hash is sent, never the password itself, so there is no way for us — or anyone who intercepts the request — to learn your password.
:::
After the hash is generated, it is sent to the server. This hash is used as a password and is hashed again to mitigate password passthrough attacks.
This process is repeated every time you sign in.
When you first sign up for an account, your client generates two encryption keys. One is a unique data encryption key that encrypts all your notes and other data. The second is your master encryption key, derived from your password and that predictable salt. This key protects all your encryption keys, like the aforementioned data encryption key. If you change your password, your client will re-encrypt your existing data encryption key with your new master key.
Instead of storing the key as plain text (and allowing anyone to copy/move it), we use browser's IndexedDB to store the key as a CryptoKey.
CryptoKey is stored securely by the browser and cannot be exported, viewed, or copied except by the app & browser.
Encryption takes place when you sync. Each item in the database is encrypted separately using XChaCha20-Poly1305-IETF.
cipheriv)saltalgid::: info See the whole process in action here.
:::
This object is then sent to the server for storage. The server performs no further operation on this data (because it can't).
No. Your notes are encrypted on your device with keys that never leave it, and the server only ever receives ciphertext. This is also why we cannot reset your password or recover your notes for you — see recovering your account.
Your account recovery key is the only way back into your data. Without your password and without that key, your notes cannot be decrypted by anyone.
Your data encryption key is created the next time you change your password.