Back to Notesnook

Locking notes with private vault

docs/help/contents/lock-notes-with-private-vault.md

3.4.10-android5.7 KB
Original Source

Locking notes

Notesnook is a private notes app: every note is encrypted by default, and nobody here can read your notes on our servers even if we wanted to. However you can still add an extra layer of security and encrypt your most important and sensitive notes by adding them to a vault.

Adding notes to private vault is useful when you do not want anyone to read your notes, even if they have access to your phone.

Creating a vault

  1. Go to {{settings}}.
  2. Go to {{vault}} in {{privacyAndSecurity}} section
  3. Click {{create}} button
  4. Enter the password for your vault (this password will be used to open all locked notes)
  5. Click {{create}} in the dialog to create the vault.

Lock a note

  1. Right click any note
  2. Select {{lock}} from the context menu
  3. Enter the password for the vault
  4. Press Enter key to lock the note

::: danger Locking a note deletes its history When a note moves into the vault, every stored version of that note is deleted. Restore or copy anything you still need from history before you lock it.

:::

Open/edit/delete a locked note

To open, edit or delete a locked note, you must provide the password for the vault to unlock it.

Unlock a note permanently

  1. Right click any note
  2. Click {{lock}} again — while a note is locked, a checkmark shows next to it
  3. Enter the password for the vault in dialog.
  4. Click {{unlock}} to remove note from vault

How long the vault stays unlocked

Once you enter your vault password, the vault stays unlocked for a while so you aren't retyping it for every note. You choose how long.

  1. Go to {{settings}}.
  2. Open {{vault}}.
  3. Set {{lockVaultAfter}} to 1, 5, 10, 15, 30, 45 minutes, 1 hour or Never.

{{never}} keeps the vault open until you close the app or lock it yourself. The setting only appears once a vault exists.

Unlock with biometrics

On mobile you can open locked notes with your fingerprint or face instead of typing the vault password. Turn on {{biometricUnlock}} in {{settings}} > {{privacyAndSecurity}} > {{vault}} — you unlock with your password once, and it is then stored in the device's own secure keystore, tied to that device. The toggle only appears if the device has biometrics available.

::: warning Biometrics are per device Turning biometrics on doesn't replace your vault password, and it doesn't travel with your account. On a new device you'll be asked for the password again — so don't rely on biometrics as your only copy of it.

:::

Change vault password

  1. Go to {{settings}}.
  2. Go to {{vault}} in {{privacyAndSecurity}} section
  3. Click {{change}} button next to {{changeVaultPassword}} heading
  4. Enter the old and new password for the vault
  5. Click {{changePassword}} to update the password

Clear vault

  1. Go to {{settings}}.
  2. Go to {{vault}} in {{privacyAndSecurity}} section
  3. Click {{clear}} button next to {{clearVault}} heading
  4. Enter your vault password and click clear vault. All notes in the vault will be deleted.

Delete vault

In the event that you have forgotten your vault password, you can delete the vault and (optionally) delete all the notes in it.

::: danger Permanent data loss Deleting the vault only requires your account password, but if you also choose to delete all the notes in it, those notes are permanently and irrecoverably destroyed. Because of end-to-end encryption, there is no way for Notesnook to recover a forgotten vault password or restore deleted vault notes afterwards.

:::

  1. Go to {{settings}}.
  2. Go to {{vault}} in {{privacyAndSecurity}} section
  3. Click {{delete}} button next to {{deleteVault}} heading
  4. Enter your account password and click {{deleteVault}} to delete the vault