Privacy by design

Zero-knowledge encrypted.
Not even we can read your notes.

TreeNotes encrypts your notes, titles, and attachments on your device before they sync. Our servers store ciphertext — not your meaning.

Can anyone see my data?

No — in any meaningful sense. TreeNotes is genuinely zero-knowledge. Every label, note, attachment, and filename is stored and returned only as ciphertext.

Cross-user access is gated by ownership and per-user encryption key checks. Other users cannot reach your data. A database compromise — or a TreeNotes administrator — yields no readable content: notes, titles, filenames and attachments are ciphertext and cannot be decrypted server-side.

What such access would reveal is the scaffolding around your notes, not the notes: your account details, how many notes you have and where they sit in your tree, when you changed them, and who you have shared with. We consider saying so part of being trustworthy — see our Privacy Policy for the full list.

The fact that we cannot reset your password is not a limitation — it is proof that we never hold your encryption keys.

What our server sees

aG9sZSt2KzRrZGY3Qx9f...

Zk1xT3BXcjhMNnZ5c2Vj...

dXJlZGJ5ZGVzaWduX7Plq...

Your keys stay yours
Plaintext never reaches the server
Sharing is encrypted per person

What is encrypted

Everything you write

Not just note bodies — every piece of content that could reveal what you store. Structural metadata is a deliberate exception, described below.

Note content

Rich text, plain text, galleries — every word is encrypted with AES-GCM on your device before it syncs.

Titles and metadata

Folder names, note labels, and the metadata attached to a note are encrypted too. A title like "Bank login" never reaches our servers as readable text.

Attachments and filenames

Files you attach — documents, images, exports — are encrypted along with their filenames. The server stores opaque blobs.

Shared branches

When you share a subtree, encryption keys are wrapped individually for each recipient via X25519. Everything else stays yours alone.

What is not encrypted

Your account details and the shape of your tree — note count, position, timestamps, node type for plan limits, and who you shared with. The server needs these to run the service, so encrypting them with a key it holds would protect nothing.

Under the hood

How encryption works

Three layers that keep your data readable only to you.

01

Your password stays on your device

TreeNotes derives two separate keys from your password using Argon2id — one for authentication, one for encryption. Login uses a challenge-response proof, never your raw password.

02

Every note gets its own key

Each note and folder has a unique encryption key. That key is wrapped for every authorized user, so compromising one note does not expose your entire tree.

03

Only ciphertext syncs

Our server is a blind persistence layer. It enforces access control — who owns what, who has been shared with — but never sees or decrypts your content.

Safe for passwords and secrets

TreeNotes is not a password manager — it is a zero-knowledge encrypted workspace. But if you store logins, API keys, recovery codes, or any other sensitive information in a note, it receives the same end-to-end encryption that protects everything else in your tree.

We never see the plaintext. Only you — and people you explicitly share with — hold the keys to decrypt it.

Account password tip: We recommend a dedicated password manager for your TreeNotes account password itself. TreeNotes focuses on encrypted notes — not autofill, breach monitoring, or password generation — but the encryption strength is identical for any sensitive note content you store.

Your account password creates the encryption key that unlocks all your data. If you lose it, we cannot recover your notes — by design.

What we deliberately cannot do

Trust through transparency. These are intentional design choices, not missing features.

  • Read your notes, even under legal pressure — we do not hold the keys
  • Reset your password — doing so would require access to your encryption keys
  • Search your decrypted content on the server — search runs locally in your browser
  • Recover lost encryption keys — this is intentional proof of zero-knowledge

Protected by True Client-Side Encryption

Every plan includes the same zero-knowledge security. Your data is encrypted on your device before it ever leaves it.

  • True End-to-End Client-Side Encryption
  • Zero-Knowledge Architecture (server cannot read your data)
  • All notes & attachments encrypted before leaving your device
  • Encrypted in transit & at rest
  • Your notes never reach our servers unencrypted

Stop writing lists.
Start growing trees.

Your first idea takes thirty seconds to plant. Free forever, encrypted from the very first keystroke.

Zero-knowledge encrypted · No credit card required