Security

How MyNout protects your notes

Your notes are personal. Here is exactly what we do to keep them yours, without marketing language.

  • Passwords are hashed, never stored
  • Two-factor authentication with backup codes
  • Your data exportable and deletable at any time

Passwords

Passwords are never stored. MyNout keeps only a salted scrypt hash, compares it in constant time and rate-limits sign-in attempts, so a leaked database cannot be replayed and guessing is slow.

In practice that means a stolen copy of the database is not a copy of anybody's password. The comparison runs in constant time so it cannot be probed by timing, and both sign-in and password reset are rate-limited per address and per account, which makes brute force slow enough not to be worth attempting.

Two-factor authentication

Turn on time-based one-time codes with any authenticator app. Each code works only once, backup codes cover a lost phone, and the 2FA secret is encrypted at rest.

Codes are single-use per time step, so a code someone glimpses over your shoulder cannot be replayed a second later. A password reset never skips the second factor: resetting the password still leaves the account behind your authenticator app. Backup codes are 80 bits of randomness, single-use, and shown once so you can store them somewhere safe.

Sessions you control

Every sign-in gets its own session, showing the device, the address it signed in from and the one it is using now. Review them in your account, sign out of any one of them, and changing your password signs out everywhere else automatically.

Sessions are stored as a hash of the token, so even a leaked database row cannot be turned into a working login. They slide forward while you use them and expire on their own after thirty days of silence, and changing your password signs out every other session immediately.

Locked notes

Protect a single note with a PIN. Its body is withheld until the PIN is verified, in the app, in shared links and in version history, so a diary stays private even on a shared screen.

The lock is enforced where the data is read, not in one screen: a locked note's body is withheld from the app, from any share link, and from the version history until the PIN is verified. That means there is no path — no export, no preview, no snapshot — that quietly shows what the lock is meant to hide.

End-to-end encryption, if you want it

Turn it on in Settings and choose a passphrase. The notes you encrypt are encrypted in your browser before they are saved, with a key that never reaches our server in a readable form — we store only ciphertext that we cannot open.

That protection comes with a condition we state up front: nobody can reset a forgotten passphrase, so you get a recovery code to keep somewhere safe, and if you lose both, the encrypted notes are gone. Encrypted notes cannot be shared or hold pictures, you search them in your own browser, and folders, tags and dates stay unencrypted so the app can still organise them. It is off by default, and you can decrypt everything again at any time.

Sharing on your terms

Public links are unguessable and read-only, can require a password and can be turned off at any moment. Collaborators see only what you invite them to, and you can revoke access with one click.

A public link is a random, unguessable address that serves one note, read-only, with search engines told not to index it and remote images blocked so nobody can embed a tracking pixel. A note locked with a PIN keeps it on a public link too: nothing of the note is shown until the visitor enters it. End-to-end encrypted notes cannot be shared at all. Collaborators are invited by address, get exactly the permission you choose, and can be removed with one click.

Your data stays yours

Export everything as Markdown, plain text, PDF or a single archive whenever you like, and delete your account with all of its notes in one step. There is no advertising profile and your notes are never sold.

Everything you write stays yours: export any note as Markdown or PDF, download all your notes, folders and tags at once, and delete the account with everything in it in a single step. There is no advertising profile, no third-party analytics without your explicit consent, and nothing that would make leaving harder than arriving.

The application itself

The site sets a strict content security policy, sends the usual protective headers, and serves everything over HTTPS with HSTS in production.

Note content is rendered through the editor's own parser rather than injected as raw HTML, so a note cannot carry a script that runs in somebody else's browser. Uploaded images are checked by their actual file signature, stored outside the web root under unguessable names, and capped both per file and per account. Sign-in with Google only links to an existing account when Google states the address is verified, which closes the classic account-takeover route.

Security

What MyNout never does

  • Never sells or rents your notes, your e-mail address or your usage to anyone.
  • Never reads your notes to build an advertising profile or to train a model.
  • Never loads analytics or advertising scripts before you have accepted them.
  • Never stores your password, in plaintext or in any reversible form.
  • Never asks for your encryption passphrase — it does not leave your browser.
  • Never locks your data in: export everything, any time, in open formats.

Questions people ask about security

Are my notes encrypted?

It is your choice. By default, notes are stored in our database, protected by your account, by the note lock if you use one, and by encrypted connections — but not end-to-end encrypted, so the server can read them. Turn on end-to-end encryption in Settings and the notes you encrypt are encrypted in your browser with a key that only your passphrase unlocks: we store nothing we can read, and could not recover it for you. Folders, tags and dates stay unencrypted, and encrypted notes cannot be shared.

What happens if I lose my two-factor device?

Use one of the backup codes shown when you turned two-factor on; each works once. If the codes are gone too, contact us from the e-mail address on the account and we will verify ownership before restoring access.

Who can see a note I shared with a link?

Anyone who has the exact link, which is why it is long and random. Set a password on the link if that is not enough, and turn the link off when the note has served its purpose — access stops immediately for everyone.

Privacy Policy

Start your notebook today

Create a free account and keep all your notes in one place.

Create your free account

Free forever · No credit card · Takes less than a minute