Security and privacy

myrna is designed to keep what's yours under your control: your content is private by default, an optional Vault adds end-to-end encryption for what you choose to protect — locked notes, locked notebooks and encrypted diaries — and API tokens let you grant external tools access on your terms. This page is the overview — each topic has its own page below.

Overview

By default nothing is shared and only you can see your content. When you need more, the Vault adds end-to-end encryption: it is a single encryption gate, opened with one passphrase, that protects everything you choose to lock — notes, whole notebooks, and encrypted diaries in the Journal. Encryption and decryption happen on your own device, so the server never sees your passphrase or the open content. The Vault button (the shield) lives in the top bar on every page, so you can unlock or lock it from anywhere in the app.

The Vault is a zero-knowledge model: encryption happens in your browser, so support cannot read or recover locked content for you. Your recovery key is the only backup. And note what the Vault is not: it is an encryption gate for your own content, not a password manager.

Core concepts

Vault
The optional encryption gate. One passphrase unlocks everything it protects: locked notes, locked notebooks and encrypted diaries. See "Vault and locking".
Recovery key
A one-time code, shown once when the Vault is created (and again only if you generate a new one), that unlocks the Vault if you forget your passphrase.
Biometric unlock
On supported devices you can open the Vault with a fingerprint or face (Touch ID, Windows Hello) instead of typing the passphrase.
Auto-lock
The Vault locks itself after inactivity — with a warning about a minute before — and always locks when you sign out.
API token
A scoped credential that lets an external tool (for example an AI assistant via MCP) access your notes on your behalf. Managed in Settings, under "API / MCP".

In this module

Each topic below has its own page:

Vault and locking
Enable the Vault, lock notes and notebooks, encrypt diaries, and unlock with your passphrase or biometrics.
Recovery, tokens and privacy
The recovery key, API tokens for the MCP connector, data export, privacy and permanent account deletion.
Without your passphrase AND your recovery key, locked content cannot be recovered by anyone — there is no back door. Keep the recovery key somewhere safe.