End-to-end encrypted before they leave your device. Stored in Europe. Readable by you alone — not by us, not by anyone.
Not a privacy policy you have to trust — a design that makes the alternative impossible.
Encrypted on your device before it ever syncs. Not a paid add-on, not opt-in — the only mode there is.
EU company, EU servers, EU sub-processors. No Schrems II asterisks, no transfer-risk footnotes.
All the everyday features — rich editor, sync, search, sharing. The encryption is invisible plumbing.
Open-source clients, published audits, open export. No lock-in — your notes outlive us.
This table is the whole product. Every endpoint we ship is reviewed against it.
Held only on your devices, under keys we never receive.
A breach of our servers yields ciphertext and counters — nothing readable.
A note app you’d choose even if privacy weren’t the point.
Headings, checklists, tables, code, inline images and Markdown shortcuts — with autosave that works offline-first, so you never lose a keystroke.
Hand a notebook to a colleague using public-key key-wrapping. Only the recipient’s device can unwrap it. Our servers move sealed envelopes they can’t open.
Encrypted for each recipient’s public key.
Add up to ten devices, each with its own key you can revoke. Protect login with passkeys or TOTP. And a one-time recovery kit is the only — deliberately backdoor-free — way back in.
Modern, audited, crypto-agile. Open source, with reproducible builds and a public bug bounty.
Every object carries its algorithm IDs, so we can rotate ciphers and migrate to post-quantum without re-encrypting your life.
Argon2id stretches your password to a master key that never leaves the device. The server holds no master key, and no backdoor.
Published external audit before GA, an ongoing bug bounty, CRA-compliant disclosure and a periodic transparency report.
A detection order to scan your notes is something we are technically unable to satisfy — because we cannot read content in the first place.
EUR-native, annual discount, no ads — ever. Education, non-profit and journalist discounts available.
For subscription-averse privacy buyers — early cohorts are capacity-limited.
| Compare plans | Free | Personal | Pro | Team |
|---|---|---|---|---|
| Storage & history | ||||
| Encrypted storage | 1 GB | 20 GB | 50 GB | Pooled + 20 GB/seat |
| Max file / attachment | 25 MB | 250 MB | 1 GB | 5 GB |
| Version history | 7 days | 90 days | 1 year | Configurable |
| Selective sync | — | ✓ | ✓ | ✓ |
| Privacy & recovery | ||||
| Zero-knowledge encryption & EU residency | ✓ | ✓ | ✓ | ✓ |
| 2FA (TOTP / passkeys) | ✓ | ✓ | ✓ | SSO-enforced |
| Recovery kit | ✓ | ✓ | ✓ | ✓ |
| Recovery contacts | — | ✓ | ✓ | ✓ |
| Hidden / locked notes | — | ✓ | ✓ | ✓ |
| Productivity | ||||
| Import & full export | ✓ | ✓ | ✓ | + white-glove |
| On-device AI | — | ✓ | ✓ | ✓ |
| Web clipper | — | ✓ | ✓ | ✓ |
| Sharing & unlisted links | Receive only | ✓ | ✓ | ✓ |
| Agents — MCP / A2A | ||||
| Agent identities | — | 2 | 5 | Per-seat |
| Included calls / mo | — | 1,000 | 5,000 | Pooled |
| A2A multi-agent workspace | — | — | ✓ | ✓ |
| Self-hosted MCP | — | — | — | ✓ |
| Team & enterprise | ||||
| Team spaces (private + org-open, E2E) | — | — | — | ✓ |
| Page trees, roles & restricted pages | — | — | — | ✓ |
| SSO (SAML/OIDC) & SCIM | — | — | — | ✓ |
| Admin console & audit logs | — | — | — | ✓ |
| Org recovery key (opt-in) | — | — | — | ✓ |
| DPA & audit-evidence pack | — | — | ✓ | ✓ |
Import from the apps you’re escaping and the raw file formats underneath them — Markdown, Word, PDF, OpenDocument and more. Every file is converted on your device, so the plaintext never reaches us. Two-way on the formats that matter, with an honest fidelity report on every import.
Free to begin. No card, no ads, no one reading over your shoulder — including us.