Contents

Feature deep dives

Zero-Knowledge Encryption

What it does

Encryption in Lyunotes is something you switch on, notebook by notebook.

Open a notebook's settings, turn on encryption, and choose a password. That's the whole setup. The app then shows you a recovery key — once. Write it down, put it in a password manager, keep it somewhere you'd keep a spare house key. You will not be shown it again.

From that point on, the notebook has two states:

Unlocked. You enter your password and it behaves like any other notebook. Write, search, attach files, drop in images. Nothing about the experience changes.

Locked. The notebook is still there in your sidebar, but it doesn't say what it is. It shows a mask name and icon you chose yourself — not the real name, not the note titles, not the previews, not the images. Someone scrolling your sidebar sees that a locked notebook exists. That's all they see. Name it whatever you like — including something that gives nothing away.

Lyunotes with an encrypted notebook locked: the sidebar shows only a mask name, and the note list and editor are empty.
Locked. A mask name in the sidebar. No titles, no previews, no images.
The same Lyunotes notebook unlocked: its real name, note titles, previews and note contents are visible.
Unlocked. The same notebook, behaving like any other one.

Unlocked doesn't mean slower. Most encrypted vaults work by mounting the whole thing — unlock once, and everything inside gets decrypted into memory or a virtual drive, whether you're looking at it or not. Lyunotes decrypts one thing at a time: the note or file you actually open, the moment you open it, and nothing else. We call this On-Demand Decryption Optimization (ODO). It's why an encrypted notebook doesn't feel encrypted — no lag opening a note, no wait scrolling a list of thumbnails, no delay you learn to route around.

You lock and unlock on your terms. Lock a notebook when you step away. Leave another one open all day. Encrypted and ordinary notebooks live side by side in the same vault, and you decide which is which — including changing your mind later and turning encryption back off.

There's no account to create, no email to verify, no "sign in to continue." Your password never leaves your machine, because there's nowhere for it to go.

And the part most apps bury in a help article, we'll say here: if you forget your password and lose your recovery key, your notes are gone. Not delayed. Not recoverable through support. Gone. We have no override, no master key, no way in — and neither does anyone else.

Encryption protects what your notes say. Metadata visible to your cloud sync provider — things like file counts and sizes — is covered in our Privacy Policy.

Why it works this way

We can't read your notes. That's the same reason we can't get them back.

Every recovery feature you've ever used — a reset link, a support ticket, a security question — is a second door into your data. It exists because the company holds a copy of your key. That door is convenient right up until the moment someone who isn't you walks through it: a subpoena, a breached server, a social-engineered support agent, an employee having a bad year.

We didn't build that door. Not because we're careless about your data, but because a lock the locksmith can open is a lock that protects the locksmith, not you.

That's the trade, stated plainly: absolute privacy costs you the safety net of someone else being able to unlock it for you. If your device fails, your own backups and cloud sync still bring your vault back — as long as you remember the password. What we can't do is recover the password itself, or the door disappears entirely. We think that's the honest deal, and we'd rather you understand it on day one than discover it on your worst day.

Not everything you write is a secret.

Most privacy apps encrypt everything and call it a feature. In practice, that's a design that fights you — you pay the friction of a vault to store a grocery list. So people do one of two things: they stop using the vault, or they keep the real secrets somewhere else entirely.

So encryption here is per notebook, opt-in, and reversible. Your reading list stays open. Your therapy journal stays sealed. A vault you actually use beats a vault you route around.

We tell you where the walls end.

Encryption defends against a specific set of things: a stolen laptop, a cloud provider that can read what it stores, a housemate who opens your machine, a drive that outlives you and gets resold. It does not defend against a device that's already compromised while you're typing — no encryption does, and anyone claiming otherwise is selling you a feeling.

Naming the limits isn't a weakness in the product. Security you can't describe the edges of isn't security — it's a vibe. We'd rather hand you an accurate map than a comforting one.

A few more edges, stated the same way: a notebook you never turned encryption on for stays exactly as readable as any other file on your machine — encryption doesn't retroactively apply itself. An unlocked notebook is unlocked; anyone looking at your screen sees what you see, the same as with any app. And the recovery key we hand you once is the whole safety net — lose it alongside your password, and there's no second one in a drawer somewhere. These aren't gaps specific to Lyunotes; they're where encryption itself stops, in any app that's honest about it.

Use cases

Journals and personal writing. The things you only write down because no one else will read them. Therapy notes, grief, ambition you're not ready to say out loud, the draft of the message you'll never send.

Client and privileged work. NDAs, case notes, unreleased strategy, interview transcripts, source material you promised to protect. Confidentiality you can point to a mechanism for, not just a policy.

Documents you'd never email. Passport and ID scans, medical results, insurance and tax paperwork, account details for the people who'd need them if something happened to you.

Research and IP. Lab notes, prior art, manuscripts, formulas, and the half-finished ideas that are worth something precisely because nobody's seen them yet.

Shared and borrowed machines. A family computer, a desk in an open office, a laptop that goes through airport security. Locked notebooks show a mask, not a title.

Your own cloud, your own terms. Keep your vault in whatever cloud folder you already use. What syncs is ciphertext — your provider holds the box, you hold the only key.

Specs

Cipher AES-256-GCM (authenticated encryption)
Decryption model On-Demand Decryption Optimization (ODO) — decrypts only the note or file you open, not the whole vault
Key derivation Argon2id (memory-hard, tuned against brute force)
Scope Per notebook — opt-in, reversible
Recovery One-time recovery key, shown once at setup
Server involvement None. No account, no key escrow, no recovery desk
Password storage Never stored, never transmitted, never seen by us
Locked state Mask name and icon; real names, titles, previews and attachments hidden

Encryption covers the contents of your notes. For what your cloud sync provider can still observe, see our Privacy Policy.

Notes

What it does

Fast to create, easy to find again, never locked into one way of looking at them.

Tap the new-note icon in the list header — or the "+" button at the bottom, or a keyboard shortcut — and you're writing, no folder to pick first, no template to dismiss. It's the same icon on the smartphone version, so switching devices doesn't mean relearning where things are. Pin the notes you're mid-thread on, sort by whatever order makes sense today (newest, oldest, last updated, title, or random for rediscovery), and switch between four list views — thumbnail grid, list with previews, plain list, or a dense one-line mode — per notebook.

Every note has a stable internal link you can copy and paste into another note; click it and you jump straight there. Duplicate a note, move it to a different notebook, or select a batch of them and delete, tag, or file them together in one pass.

Delete doesn't mean gone. Notes go to Trash first, where you can restore them or remove them for good.

Lyunotes on the desktop: a notebook sidebar, a note list with previews, and the note editor open on a note.
The default view: sidebar, note list with previews, and the editor open on a note.

Specs

Sort orders Newest, oldest, last updated, title, random, custom
List views Grid (thumbnails), list with previews, plain list, one-line
Trash Restore or permanently delete individual notes
Note links Internal deep links between notes — copy, paste, click to jump
Duplicate & move Copy a note, or move it to a different notebook
Multi-select Batch delete, tag, or file notes together
Export Save any note as Markdown

Resources

What it does

Every note has its own resource space — every file you attach to it lives there, browsable on its own, never buried inside the note's body text.

Add files by dragging them in or picking them from a folder. Organize them into folders the same way you'd organize any other files. Switch between a thumbnail grid and a list view, and when you want to use one in a note, pick it from that note's resources instead of hunting for the original file again.

On the smartphone version, point the camera at a document and Lyunotes scans the pages into a single PDF right there — no separate scanner app, no detour through your camera roll. It lands straight in that note's resources.

If a resource ever goes missing from the index — a sync hiccup, an interrupted write — Lyunotes can rescan the notebook's folder on disk and rebuild it, rather than leaving you to track it down by hand.

Lyunotes Resources tab for a note: a grid of folders and files, including an images folder, a PDF, and a text file, inside an encrypted notebook.
Every resource for this note in one place — folders, files, and a one-click virtual drive.
Lyunotes add-resource menu on the smartphone version, showing Photo Library, Camera, Files, From resources, and Scan Document options.
On the smartphone version, Scan Document turns paper straight into a PDF in that note's resources.

Specs

Scope Each note has its own resource space
Views Thumbnail grid or list
Folders Nested folders for organizing resources
Document scanning On the smartphone version — scan paper documents straight into a PDF
Insert into notes Pick any resource and drop it into the note you're editing
Recovery Rescan-from-disk if the resource index goes missing
Encrypted notebooks Resources are encrypted at rest and decrypted only when viewed

Folios

What it does

A way to group notes inside a notebook without moving them anywhere.

A folio is a tab, not a folder — create one, give it a color, and add notes to it. The same note can belong to several folios at once, so a single project note can sit in "Active," "Q3," and "Client X" simultaneously without you ever duplicating or relocating it. Nest folios inside each other when a flat list stops being enough.

Click a folio to filter the note list down to just what's in it. Remove a note from a folio and it stays exactly where it was — folios organize, they don't own.

Lyunotes Folio tab for a note: the note belongs to two folios, 'Weekend Wanders' and 'Coastal Walks', shown as removable tags with an option to add more.
A note can belong to several folios at once — add or remove membership without ever moving the note.

Specs

Nesting Folios can contain child folios
Membership A note can belong to multiple folios at once
Color 9 tab colors to tell folios apart at a glance
Filtering Click a folio to filter the note list to its members
Reordering Drag and drop to reorder folios