Skip to content

Privacy

Private work needs clear promises.

Onnoir's privacy model is practical: keep the notebook vault local, avoid account requirements, make network behavior explicit, and give you clear ways to leave or recover your work.

Vault

Your library starts local.

Onnoir stores notebook content in an encrypted vault on your device. The desktop app does not require an account and does not host your writing on Onnoir servers.

Access

Your passphrase and recovery key matter.

The desktop app uses your passphrase and a local recovery-key flow for access. Keep both somewhere safe; Onnoir cannot reset them through an account.

Network

No required sync.

Onnoir is built around a local desktop vault. Manual update checks and website download redirects are separate from your notebook content. Future services such as Sync or Publish will be opt-in.

Diagnostics

Anonymous and optional.

Onnoir stores limited diagnostic state and logs locally outside the encrypted vault. If you opt in, anonymous diagnostics may send app-health details, but never note content, capture text, search queries, file names, media names, local paths, passphrases, recovery keys, or vault identifiers.

Portability

Keep a copy outside the app.

Export Markdown for readable files and create encrypted .onbk backups before updates. Portability is part of the workflow, not an emergency feature.

Read the full Privacy Policy →

Start with the free local app.

Available for macOS and Windows with no account required. Before updates, create and verify a recoverable backup.