Safety and privacy
n0te handles your notes, so here is everything it does that reaches beyond the window.
Privacy
- No network. n0te makes no network connections: no telemetry, no update checks, no accounts. The only time anything leaves your machine is when you open a web link, which goes to your browser.
- No index or cache. n0te reads your notes when it needs them and keeps nothing about them on disk. The only things it writes outside your notes are listed in Files and environment.
- Private runtime files. The socket, log and stdin copies live in
$XDG_RUNTIME_DIR, or an0te-UIDfolder that only you can read. n0te never puts them in a shared/tmp, where another user could read or replace them.
Your files
- Atomic saves, so a crash or power cut mid-save leaves the old file or the new one, never half of one. (The one exception is a note in a folder you can’t write to, which is saved in place; see Saving.)
- Merges, not overwrites, when a file changes on disk while you edit.
- Holds for the cases n0te can’t settle safely: conflict markers in code, a file moved away, a file turned binary.
- Binary files are read-only. n0te opens text. A file with NUL bytes or invalid UTF-8 shows a short page explaining why, and n0te never writes to it.
- No surprises from links. Web, mail and
obsidian://links open on a click. Any other scheme (file:, other apps’ handlers) first shows its target, and opens only on a second click, since link text can hide where a link goes.
Your system
- Setup is explicit. Nothing changes in Hyprland, the app menu or xdg-mime until you run
n0te --setupor flip a switch on the settings page, andn0te --setup removeundoes it. - Your edits are kept. Setup leaves the app entry, the theme template and the completion file alone if you’ve changed them, and it keeps symlinked dotfiles as symlinks.
- The settings page reads the real state. It never trusts a cached copy of Hyprland’s or xdg-mime’s settings.
Reporting a problem
If n0te ever loses or mangles text, that’s the most serious kind of bug. Note the steps, what the status line said, and anything in n0te-service.log (see The service). n0te’s issue tracker, and private reporting for security problems, open with the public repository.