Locked notes and Vault

Some notes hold things you'd rather keep to yourself. For that, myrna lets you lock an individual note or an entire notebook: the content is encrypted on your own device, so the server never sees the plain text. Locking relies on a "vault" protected by a password that only you know — its button lives in the global top bar, on every page. This page explains, from the Notes side, how to lock and unlock; creating and configuring the vault in detail lives on the "Vault and locking" page of the Security section.

What it means to lock

Locking protects content with encryption performed right on your device, before anything is sent: all that reaches the server is the encrypted result, unreadable without your key. There are two granularities, with a subtle difference:

Locked note
Locking a single note ("Lock note") encrypts its body. The note stays in the list with its title readable, but the content only opens with the vault unlocked.
Locked notebook
Locking a whole notebook ("Lock notebook") encrypts the title AND body of every note inside it, in one go. In lists, the encrypted titles are replaced by the "Locked note" placeholder while the vault is closed — the ciphertext is never shown.
  • Locking also removes the note from public sharing and keeps it out of search results while locked.
  • Locking purges the note's earlier version snapshots, which were stored as plain text — history restarts from the encrypted edits.
  • Notes created in, or moved into, a locked notebook are encrypted automatically and inherit the protection.

The Vault

All locking relies on a vault: a protected space that holds the key used to encrypt and decrypt. Instead of setting a password per note, you create the vault once and use it for as many notes and notebooks as you like. The shield button in the global top bar shows its state and lets you unlock ("Unlock vault") or lock ("Lock vault") it from anywhere in the app.

Vault passphrase
The vault's main key (at least 8 characters). Without it, locked content cannot be opened. Choose something strong that you won't forget.
Recovery key
A code generated when the vault is created, shown only once, that serves as a backup if you forget the passphrase. Keep it somewhere safe, off the device.
Unlock with biometrics
On compatible devices, unlock the vault with a fingerprint or face recognition instead of typing the passphrase.
Auto-lock
The vault locks itself after a period of inactivity — with a warning one minute before, so you can choose to stay unlocked. Signing out also locks it.

Lock a note or a notebook

  1. 1In the notes list, open the context menu of the note and choose "Lock note" — or, in the notebooks area, choose "Lock notebook" to protect it whole.
  2. 2If the vault isn't unlocked yet, the vault dialog opens: enter the passphrase (or use biometrics; if you don't have a vault yet, it walks you through creating one).
  3. 3The content is encrypted on your device and sent to the server already scrambled.
  4. 4To undo, use "Unlock note" / "Unlock notebook" in the same menu: the content is decrypted and stored as plain text again.

How it looks when the vault is locked

While the vault is closed, locked content is sealed. In place of the note, the editor shows a lock screen titled "Locked content", with the explanation "This content is locked. Unlock the vault to view it." and an "Unlock vault" button. For a locked notebook, the whole view becomes the lock screen — the note list isn't shown either.

Click "Unlock vault" and enter the passphrase (or the recovery key, or biometrics) to read and edit again. After a period of inactivity, the vault locks itself and the notes go back to being sealed.

Important warnings

If you lose both the passphrase AND the recovery key, the locked content cannot be recovered by anyone. Because encryption happens on your device, there's no way for myrna to open the notes for you. Keep the recovery key somewhere safe.
When you export your notes, locked notes come out with an empty body (and, in locked notebooks, a placeholder title) to preserve secrecy. Unlock before exporting if you want to include that content.

Configure the vault

To create and manage the vault — change the passphrase, generate a new recovery key, and enable biometric unlock — see the "Vault and locking" page in the Security section.