This page explains, in plain English, how Nodra encrypts your vault, what its server can and cannot see, and what each of the two protection modes means for who can read your notes. It also lists what Nodra does not protect you from. Nodra is in beta, and parts of this design are still provisional.
In short
| Managed (default) | Private | |
|---|---|---|
| Signing in on a new device | Your login. | Your login, plus your Encryption Password and Account Secret Key. |
| What you keep | Nothing beyond your login. | A Setup Kit (with the Secret Key) and a Recovery Kit. |
| Forgot everything | Recover the account through your login email. | Only the Recovery Kit recovers it. Without it, your data is gone. |
| Can Nodra read your notes? | Yes. The server keeps an escrow of your keys. | No. |
| What Nodra claims | Encrypted in transit and at rest. | Private mode is end-to-end encrypted, with the limits below. |
Every account starts in Managed mode. Private mode is available on every plan, Free included, and you can switch between the two from the account settings.
What is encrypted, and where
Your vault is encrypted by the Nodra client itself, the Obsidian plugin or a browser you trusted, before anything is uploaded. Each file's content is encrypted with AES-256-GCM under a vault key that only your account and the devices you enrolled can open. Nodra's storage holds that encrypted content, and it travels over TLS. The file names and folder paths travel inside the encrypted data too.
Both modes use exactly the same encryption: the same keys, formats and sync protocol. The only difference is whether Nodra's server also keeps an escrow, a copy of the key that unlocks your account, so it can recover the account for you. That escrow is what decides who can read your notes.
On your computer, the vault itself is a normal folder of plain Markdown files, as Obsidian keeps it. What Nodra stores locally for its own work (pending changes, caches) is encrypted with a key that never leaves that device.
What the server sees
Nodra's server stores encrypted content. It does not store the names, paths and contents of your files in readable form. It does see:
- how many files, versions and changes your vaults have, and the encrypted size of each;
- when and how often you make changes;
- your devices and trusted browsers, and when each was last active;
- your account email, your plan and billing status.
On a Managed account, the server can also decrypt the content itself, through the escrow described next.
Managed mode: recovery by email
When you create an account, your browser generates a random key that unlocks your account's keys. In Managed mode, a copy of it is kept by Nodra's server, wrapped with a server key that is held apart from the database. That copy is the escrow. Nodra's server keeps an escrow of your keys, so it can read your notes, and that is also what lets you recover everything through your login email after forgetting it all.
What that means in practice:
- Whoever controls your login, your Nodra password or your email account, can read your notes. Protect your email account well.
- Nodra, and anyone who compromises Nodra's server code or its escrow key, can read the content of Managed accounts. So can a legal request addressed to Nodra.
- Removing a device stops its sync, but a removed device that still has your login can sign back in and unlock the account again.
For Managed accounts, Nodra only says your notes are encrypted in transit and at rest.
Private mode: two secrets and a Recovery Kit
Private mode is end-to-end encrypted. In Private mode there is no escrow: the key that unlocks your account comes from your Encryption Password and your Account Secret Key, and neither is ever sent to Nodra or stored by the plugin or the web app. In Private mode, Nodra's storage and database do not hold the keys needed to read your notes.
- Encryption Password: a password you choose, separate from your login password. It is stretched with Argon2id on your device.
- Account Secret Key: a random key of at least 128 bits, printed on your Setup Kit. Because it is random, a stolen database alone gives no way to guess your password offline.
- Recovery Kit: a master key for the account. It recovers it if you lose your password or Secret Key. Anyone who steals it can read everything, so keep it offline.
If you lose your Encryption Password or your Secret Key, and also your Recovery Kit, nobody can recover your data, Nodra included. Lose all three and your data is gone for good.
The Recovery Kit does not replace your login: to use it you must still be able to sign in to your Nodra account. If you lose access to your login email for good, the Recovery Kit alone does not bring the account back.
Switching between modes
From Managed to Private: everything you write after the switch is out of Nodra's reach. Your earlier notes and history are re-encrypted in the background, and the app shows its progress. Until that finishes, Nodra could still read the earlier history, and it could have copied it at any time while the account was Managed.
From Private to Managed: Nodra gains read access to all your notes again, everything already written and everything you write afterwards. Nothing is re-encrypted. Your old Recovery Kit still opens everything written before the switch, so destroy it.
Recovery delay and veto
On a Private account, three operations can hand control of the account to someone holding only one of your two authorities: a reset with the Recovery Kit, replacing the Recovery Kit, and switching to Managed. Each one first waits 72 hours. Nodra notifies you, in the app and by email, when one is requested, and during those 72 hours the other authority can veto it: your password and Secret Key veto a reset made with the kit, and the kit vetoes a kit replacement or a switch to Managed. A thief holding one of them has to get past the holder of the other.
This depends on Nodra's server enforcing the wait and on the email reaching you in time; your devices cannot check that the 72 hours really passed. Managed accounts have no delay, because their login already controls the content.
Trusted browsers and devices
Each plugin install and each browser you trust gets its own device key. It is created on that device, kept in the browser's or Obsidian's storage as a key that cannot be exported, and your account grants it access to your vaults. A trusted browser keeps an encrypted copy of the vault so it can work offline.
You can list your devices, with their names and last activity, and remove any of them from the web app's settings or the plugin's Manage devices. Removing one creates new vault keys that it never receives, so it gets nothing written afterwards. What it already downloaded stays on it. Nodra also notifies you, in the app and by email, when a device is added or removed.
The web app is part of what you trust
In a browser, the code that encrypts and decrypts your notes is the JavaScript Nodra serves. If that code were altered while you used it, for example through a cross-site scripting bug, it could read everything that browser can decrypt, in either mode. Nodra's measures against that:
- the web app at app.nodranotes.com runs under a strict Content Security Policy and loads no third-party scripts;
- this marketing site is a separate app, and runs no JavaScript at all;
- the payment checkout lives on a single page of this site, nodranotes.com/checkout, never inside the web app;
The Obsidian plugin's bundled code is not obfuscated, so you can inspect exactly what runs on your computer.
What Nodra does not claim
- Nodra's encryption has not yet had an external cryptographic review. One is planned; until it happens, treat Nodra as a young system.
- It does not protect you from a compromised Nodra server that actively works against you. Such a server could hide, roll back or delete data, skip the recovery delay, or show an outdated list of devices to a device that was offline. There is no public transparency log to catch that.
- It cannot protect a device that is itself compromised: malware or a keylogger on your computer can read whatever that device can decrypt.
- It does not hide the metadata listed in What the server sees.
- A removed device keeps whatever it downloaded before you removed it.
If you find a security problem, write to legal@nodranotes.com. How Nodra handles your personal data is in the Privacy Policy.