Security and privacy
myrna is designed to keep what's yours under your control: your content is private by default, an optional Vault adds end-to-end encryption for what you choose to protect — locked notes, locked notebooks and encrypted diaries — and API tokens let you grant external tools access on your terms. This page is the overview — each topic has its own page below.
Overview
By default nothing is shared and only you can see your content. When you need more, the Vault adds end-to-end encryption: it is a single encryption gate, opened with one passphrase, that protects everything you choose to lock — notes, whole notebooks, and encrypted diaries in the Journal. Encryption and decryption happen on your own device, so the server never sees your passphrase or the open content. The Vault button (the shield) lives in the top bar on every page, so you can unlock or lock it from anywhere in the app.
Core concepts
- Vault
- The optional encryption gate. One passphrase unlocks everything it protects: locked notes, locked notebooks and encrypted diaries. See "Vault and locking".
- Recovery key
- A one-time code, shown once when the Vault is created (and again only if you generate a new one), that unlocks the Vault if you forget your passphrase.
- Biometric unlock
- On supported devices you can open the Vault with a fingerprint or face (Touch ID, Windows Hello) instead of typing the passphrase.
- Auto-lock
- The Vault locks itself after inactivity — with a warning about a minute before — and always locks when you sign out.
- API token
- A scoped credential that lets an external tool (for example an AI assistant via MCP) access your notes on your behalf. Managed in Settings, under "API / MCP".
In this module
Each topic below has its own page:
- Vault and locking
- Enable the Vault, lock notes and notebooks, encrypt diaries, and unlock with your passphrase or biometrics.
- Recovery, tokens and privacy
- The recovery key, API tokens for the MCP connector, data export, privacy and permanent account deletion.