SECURITY

Built so we can’t read your notes.

How Scribbit keeps your notes to your own Macs: the encryption, the keys, what our servers hold, and what no app can protect you from.

The promise

Only your own devices can read your notes. Not us, not our hosting provider, not someone who copies our database, not anyone watching the network.

  • Encrypted on your MacEverything is encrypted before it leaves your Mac, with keys our servers never have.
  • The AI stays on your MacCleanup, search and voice notes run on your Mac. Nothing goes to an AI company, including Apple’s cloud.
  • We keep as little as we canYour email, your devices’ names, and when they sync. Never what you wrote.
  • Nobody can recover it for youLose every Mac and your recovery key, and your notes are gone. That’s what encrypted means.

“Your notes” means everything you wrote and everything made from it: your pages and their history, images, files and their names, voice notes, what Cleanup organized (tasks, labels, people, projects), the data search uses, and the links you saved.

How your notes are protected

On your Mac

Your notes live in an encrypted database (SQLCipher) whose key is kept in the macOS keychain, behind your login. Attachments are encrypted file by file. So a locked or switched-off Mac, or a Time Machine backup, holds only ciphertext.

When they sync

Before anything leaves your Mac, it’s encrypted with XChaCha20-Poly1305 under keys derived from your account’s key. Each piece is sealed to your account: if a server moved it to another account, or changed a single byte, it would fail to open. Short pieces are padded to at least 512 bytes, and longer ones rounded up, so their sizes say little about what’s inside.

Our servers store and pass along what they can’t read. They can decide whether to deliver it, but not what it says.

Your keys

Your account’s key is 256 random bits, made on your first Mac. It never leaves your devices unencrypted: our servers keep it only sealed, once for each of your Macs and once with your recovery key.

  • Your recovery key is shown once, when you set up. Keep it in a password manager or on paper. With it you can add a Mac when you have none left.
  • Adding a Mac needs one you already have, with a pairing code you type and a short code both screens show to compare, or your recovery key. The server carries the messages; it never gets to decide.
  • Signing a Mac out gives your account new keys for everything written after. The Mac you signed out keeps what it already had.

What our servers hold

WhatWhy
Your email address, and your name if you give itSigning in, receipts
Your devices’ names and platforms, and when they were last usedChoosing and signing out devices
When you sign in and sync, and from which IP addressRunning the service, stopping abuse
Your encrypted notes and files, with their padded sizesSync and backup
Your account’s key, sealed so only your devices or recovery key can open itAdding and signing out Macs
Your plan, and a customer record at Stripe if you payBilling

Never: what you wrote, titles, file names or types, people or project names, labels, links, the data search uses, or even which day a note belongs to. All of that is inside the encryption.

How long each is kept, and your rights over it, are in the privacy policy.

Signing in

You sign in with a code or a link sent to your email, so there’s no password for us to leak. Signing in gives a Mac no keys: someone who gets into your email can’t read your notes, and can’t change or remove anything, since that takes one of your Macs or your recovery key.

If they ask to delete your account, it’s scheduled a week out: we email you, every signed-in Mac shows it and can cancel it, and they can’t sign your Macs out to stop you.

The app itself

  • Keys are handled only by Scribbit’s core, never by the window that shows your pages. Even if something went wrong in that window, the keys couldn’t be taken out through it.
  • That window runs only Scribbit’s own code and can’t reach the internet by itself. Pasted content is cleaned to plain blocks, and scripts in it are dropped.
  • API keys and passwords you write are masked everywhere, shown only with Touch ID, and never given to the AI, search or the index.
  • Exporting everything needs Touch ID or your Mac’s password.
  • When downloads open, they’ll be signed and notarized by Apple, so macOS can check they came from us and weren’t changed.
  • Every dependency is pinned, and nothing published in the last week is used, to stay clear of freshly compromised packages.

Before launch, we’ve reviewed the server, the app, and everything the server keeps. An independent audit is planned before launch.

What we can’t protect against

  • Someone using your unlocked Mac, or malware running on it, can see what you can. An optional app lock asks for Touch ID or your password when Scribbit opens.
  • Losing every Mac and your recovery key. Nobody, including us, can bring your notes back.
  • When and how much you sync. Our servers see when your Macs sync, from which address, and roughly how much. Never what.
  • Your exports. An export is a plain copy of your notes, for you to keep safe.

Report a vulnerability

If you find a security problem in Scribbit, the app, our servers or this site, emailsecurity@getscribbit.com with how to reproduce it. We’ll reply within a few working days and keep you told as we fix it.

We won’t pursue good-faith research that respects others’ privacy, doesn’t destroy data or disrupt the service, stays within your own account, and gives us reasonable time to fix a problem before it’s made public. We don’t run a paid bounty yet; we’ll credit you, if you’d like.