Vault and locking
The Vault is myrna's optional end-to-end encryption, and it works as a single gate: one passphrase protects everything you choose to lock — individual notes, whole notebooks, and encrypted diaries in the Journal. Content is encrypted on your own device before anything is sent, so the server only ever stores the scrambled version. This page shows how to turn the Vault on, what exactly gets encrypted, how to unlock with your passphrase or biometrics, and what end-to-end encryption really means.
Enable the Vault
The Vault is off until you set it up. Enabling it means choosing a Vault passphrase — separate from your login password — that becomes the key to everything you lock. You do this once; after that, the same Vault protects as many notes, notebooks and diaries as you like.
- 1Lock something for the first time (for example "Lock note" in a note's context menu), or click the shield button in the top bar — it is there on every page.
- 2Type a passphrase of at least 8 characters — choose a long, unique phrase that only you know. It is separate from your login and the server never sees it.
- 3Confirm the passphrase by typing it again.
- 4Save the recovery key shown on screen, then tick the confirmation box stating you understand it cannot be recovered — the dialog does not let you continue (or close) until you do.
- 5If your device supports it, myrna offers to enable biometric unlock in this browser — accept or choose "Not now".
What the Vault protects
- Locked note
- The "Lock note" action encrypts the note's body. The title stays readable, so you can still find the note in lists and search — only its content is sealed.
- Locked notebook
- The "Lock notebook" action encrypts the title AND the body of every note inside it, in one go. Notes you later create in or move into a locked notebook are encrypted too.
- Encrypted diary
- In the Journal, encryption is per diary: an encrypted diary has its entries — text, tags, photos and details — stored as encrypted blobs, and the Vault gates access to it. An encrypted diary cannot be shared: only you hold its key.
Locking is also thorough about leftovers: the item is removed from public sharing, earlier plain-text version snapshots are purged, and plain-text copies still on your device (pending saves, list caches) are cleared — so nothing readable is left behind.
Lock notes and notebooks
- 1In the notes list, open the context menu of the note (or the notebook) you want to protect.
- 2Choose "Lock note" or "Lock notebook".
- 3If the Vault is locked, unlock it first with your passphrase or biometrics — if it does not exist yet, this is where setup starts.
- 4Done: the content is encrypted on your device and sealed whenever the Vault is locked. To make a diary encrypted, use the diary's own encryption option in the Journal.
Unlock to read and edit
While the Vault is locked, locked notes stay in the list but show a lock screen instead of their content, and encrypted diaries wait for the Vault before opening. Unlock once and everything the Vault protects is readable and editable again until it locks back up.
- 1Open a sealed note (or click the shield in the top bar).
- 2Enter your Vault passphrase — or choose "Unlock with biometrics" if you enabled it on this device. There is also "Use recovery key instead" if you forgot the passphrase.
- 3The content is decrypted on your device and stays available until the next lock.
Biometric unlock
On a supported device you can unlock with a fingerprint or face (Touch ID, Windows Hello) instead of typing the passphrase. myrna offers to turn this on once per browser, right after your first unlock; you can accept later from the unlock dialog. Each device is registered separately, the passphrase always keeps working as a fallback, and you can remove a device's biometric unlock in Settings. Some browsers lack the required security feature (WebAuthn PRF) — myrna tells you if that is the case.
Manage the Vault
Open Settings and go to the "Vault" section (unlock first to manage it):
- Change vault passphrase
- Sets a new passphrase. Your recovery key and biometric unlock stay valid, and nothing needs to be re-encrypted.
- Generate new recovery key
- Shows a fresh recovery key once and invalidates the previous one. See "Recovery, tokens and privacy".
- Biometric unlock
- Lists the devices registered for biometric unlock and lets you remove them.
What end-to-end encryption means
End-to-end means the encryption and decryption happen entirely on your device, inside the browser (AES-256, with the key derived from your passphrase). The server receives only the scrambled result — never your passphrase and never the open content. Everything you don't lock keeps working as usual.