Klarinotte / Security & Privacy
Home Launch App

Security & Privacy

How Klarinotte keeps your data safe and private.

The short version: Your notes are yours. They're stored locally on your device. When you use sync, your data is end-to-end encrypted before it leaves your device — we cannot read it. We don't track you, profile you, or sell your data.

Local-First Storage

By default, all your data lives exclusively on your device in the browser's IndexedDB — a local database that never leaves your machine:

We have no access to your locally stored data. If you clear your browser data, local data may be lost — we recommend using the sync feature or maintaining backups via export.

End-to-End Encryption

If you create an account and enable sync, your data is encrypted on your device before upload using AES-256-GCM. The encryption key is derived from your password and never leaves your device.

Zero-Knowledge Architecture

Our servers store only encrypted blobs — your notes and attachments in encrypted form that we cannot read. The sync protocol uses encrypted metadata (timestamps, device identifiers, sync IDs) needed for synchronization. Your account email and a hashed password derivative are stored for authentication — never your plaintext password.

On-Device AI

Both OCR and semantic search are powered by AI models that run entirely in your browser:

What We Do NOT Collect

Your Rights

For the complete legal privacy policy, see our Privacy Policy page.