Privacy · The security model

Strong locks. Plain limits.

What it protects, and what it leaves to you.

There is no server of ours to break into. The key to your notes is made on your own devices, and sync between them is encrypted twice. The part left to you is guarding each device.

Report a vulnerability
A pencil drawing of a padlock and the key that opens it.

your device,
locked

the vault's key,
made on your devices

What it protects

The locks live in HootBook itself, on each of your devices.

  1. Keys made on your devices

    Your vault, meaning all of your notes, pictures and changes, is kept encrypted with a key made on your devices. A new device receives that key from one already in your vault. We never hold a copy.

  2. Six digits to join

    To add a device, you type the six digits your first device shows. The code works for one minute and five tries, and it can't be tested offline, so a stranger's guess has next to no chance. Then both screens show a second code to compare, and your first device approves. Only it can add or remove devices.

  3. Sync, encrypted twice

    Your devices talk only over your own private Tailscale network, which encrypts the traffic. Inside it, HootBook encrypts everything again, and each device must prove it is on your vault's list. Any other caller is turned away.

  4. Every change checked

    A change from another device is checked before it touches a note: it must be signed by a device in your vault and arrive unaltered. A change that fails is refused, however many devices send it.

  5. AI keys stay put

    An AI provider key stays on the device where you entered it, and never syncs. Claude Code and Codex keep their own sign-ins, which HootBook never reads.

  6. Notes can't call out

    Nothing in a note reaches the internet by itself, unless you turn on link previews. A picture from the web loads only after you choose to load remote images for that note.

  7. No telemetry

    No analytics, crash reports or advertising IDs, and the app's log stays on the device. The only request HootBook makes on its own is a daily check for a newer version. It carries no identifier, you can turn it off, and HootBook never downloads or installs an update.

Also guarded

  • AI tools kept apart

    When you ask Claude or ChatGPT through Claude Code or Codex, HootBook starts the tool in an empty folder, unable to change your files.

  • Link previews

    Off unless you turn them on, and they never open addresses on your own network.

  • Speech-to-text

    Its models download from fixed addresses, and each file is checked before use.

  • Both edits kept

    When two devices change the same note before they sync, both versions are kept for you to settle.

What it does not protect

Read this before you put anything sensitive in a note.

Between your devices, HootBook guards your notes. On each device, the device's own locks are what count.

Anything running as you
Any program running under your login can read your notes and saved AI keys on that device. No setting in HootBook stops it. On Android, the device's own key isn't kept in the phone's secure key store.
The key on disk
On each device, the vault's key is stored beside the vault, with a plain copy of every note for search.
Lost devices and backups
A lost device is protected by its disk encryption and screen lock, not by HootBook. A backup of HootBook's folder holds everything, the key included.
Removing a device
It stops the device getting anything new, but can't erase what it already holds.
A copy of the vault
Without the key it can't be read, but it still shows which device changed which note, and when.
Locks on single notes
Not available yet. Every note in a vault is protected the same way.
Voice
Off unless you turn it on. When you ask in a voice conversation, the assistant can add to, create or file a note without a confirmation step. It can't delete.

Guard each device

Four habits cover what HootBook can't, on every computer and phone that holds your vault.

Encrypt the disk

Turn on FileVault on a Mac and BitLocker on Windows. It covers the key and the notes stored on disk.

Lock the screen

Use a screen lock on every device. An unlocked device is open to whoever holds it.

Encrypt your backups

Encrypt the backup disk, or make a Backup pack: an encrypted file of your notes and pictures, sealed with a passphrase you choose.

Keep a real backup

Your other devices are copies, not backups. Sync copies mistakes too: delete a note on one device, and it is deleted on the others.

Report a vulnerability

Found a security problem in HootBook? Please tell us privately, not in public.

Email security@kuon.ai with the version, the platform, what you did and what happened. A proof of concept helps.

Private reporting on GitHub opens with the public release.

Reply
We acknowledge a report within 3 business days, and keep you posted.
Credit
In the release notes, unless you would rather we didn't.
Disclosure
We ask for 90 days of coordinated disclosure from the first report, or until a fix ships if that is sooner.
Versions
Only the latest release. Fixes ship in a new release.

In scope

  • The vault: how changes are signed and checked, and how devices are added and removed.
  • Sync and joining: the encrypted session, the six-digit join and the approval.
  • The app window, the command-line tool, outbound requests and keys on the device.
  • AI that makes HootBook take an action you did not ask for, such as writing a note.
  • The Android app, and the build and release checks.

Already known

  • Everything under What it does not protect. Please don't report it as new.
  • HootBook does not update itself. That is by design.

Out of scope

  • Our website: write to the same address, but it is not a product vulnerability.
  • Other companies' services and software, such as AI providers and Tailscale: report those to them. Do report HootBook misusing one.
  • Flaws in dependencies with no shown way to exploit them through HootBook.
  • Social engineering, physical access to an unlocked device, and running up your own AI bill.

Early access

HootBook is in early access in the US: a public preview, in daily use, with rough edges. Tell us a little about how you'd use it, and we'll be in touch.

Mac
Apple silicon, macOS 14.2 or newer
Windows
Windows 11 (x64)
Android
7.0 or newer. A phone joins a vault started on a Mac or Windows PC.
Mac, Windows and Android · US

Request early access