Private notes in Loknot

What is private should stay private.

A journal, medical notes, family matters, unpublished writing, interview material, and working theories are not always meant for anyone else's eyes. Yet an ordinary notes app may store them as readable data, expose a page in the recent-apps view, or leave an unprotected backup behind.

Loknot is built for writing that belongs to you. Notes are encrypted on the device. The app works without a mandatory account or internet connection and contains no ads or third-party analytics. When you need more protection, add a PIN, biometric unlock, auto-lock, and screenshot blocking.

A private journal without an unintended reader

A journal is valuable precisely because it can be honest. It may hold thoughts you would never publish, send through a messenger, or discuss even with people close to you.

If you have to keep wondering who might pick up your phone and what they could see, the journal is no longer entirely private. Loknot reduces that risk by storing entries in an encrypted database and placing a separate PIN or biometric check at the door.

Auto-lock secures the app again after it moves into the background. Screenshot protection also hides its contents from the preview shown in the recent-apps switcher.

That makes Loknot a good place for:

Reporting notes and other sensitive work

A reporter's notebook may contain source names, interview details, competing accounts of an event, contact information, an investigation timeline, and passages from a story that has not been published.

Losing those notes is more than a personal inconvenience; it can affect other people. The unfinished material deserves protection too: questions, doubts, connections between facts, and details that may never appear in the final story.

Loknot is well suited to keeping that material on the device:

Loknot is not a secure messenger or an anonymous channel for communicating with sources. It protects notes you have already made; it does not replace a reporter's broader security practice, including a well-secured device, current software, careful file handling, and appropriate communication tools.

What can go wrong in an unprotected notes app

Someone picks up an unlocked phone

You hand your phone to a friend, colleague, or child to show them a photo, or leave it unlocked on a table. In an ordinary notes app, one tap may be enough to open the latest entry.

Loknot can require its own four-digit PIN. After three failed attempts, entry is locked for five minutes, making a quick brute-force attempt impractical.

Fingerprint or face unlock makes routine access faster, while the PIN remains available as a fallback.

The app is left open in the background

You switch to a call or message and forget that the notes app is still open. A few minutes later, someone else has the phone.

Loknot can lock itself again after 30 seconds, 1, 3, 5, or 30 minutes in the background. A short delay is the sensible choice for particularly sensitive writing.

The note appears in the recent-apps switcher

Android displays previews of recently used apps. Someone may read a journal heading or several lines without ever opening the notebook.

With Extra security enabled, Loknot replaces that preview with a blank screen, so the note never appears in the thumbnail.

Someone takes a screenshot

A screenshot is easy to save, forward, or upload automatically to a cloud photo library. Once that copy exists outside the app, Loknot can no longer protect it.

Extra security blocks screenshots inside Loknot. It cannot stop someone photographing the screen with another device, so physical access to an open phone still matters.

The database file is copied from the device

Some apps merely hide their notes inside an internal folder. If someone gains access to the phone's files, that database may be readable like any other document.

Loknot encrypts the notes database. Its key lives in Android's secure key store — the same system used to protect keys for banking apps — and uses hardware-backed storage whenever the device supports it.

Copying the database file is not enough. Without the key, its contents remain unreadable.

A backup file falls into the wrong hands

A backup can be left in a shared folder, sent to the wrong person, or lost with a USB drive. An unprotected archive exposes every note at once.

Loknot can encrypt a local backup with a password. The normal minimum is eight characters. With Extra security enabled, the password must contain at least ten characters, upper- and lowercase letters, a number, and a special character. A strength meter helps you judge it.

You may still create an unprotected backup, but Loknot warns you first. Password hints are stored in plain text, so the hint must never contain the password itself or make it easy to guess.

A modified build is installed on the phone

An app downloaded from an unofficial source may look authentic while carrying someone else's code.

Loknot verifies its own signing certificate and raises a critical warning if the installed build has been altered. Even with that check, install the app only from an official store or another source explicitly named by Loknot.

Instrumentation tools appear on the device

Root access, Frida, Xposed, and similar tools can interfere with apps and bypass normal Android boundaries.

Loknot checks its environment and warns about root access, Frida or Xposed, an emulator, or an invalid app signature.

A warning does not remove the threat. No app can promise complete protection on a compromised operating system. Truly sensitive notes belong on a current, unmodified, non-rooted device.

The app quietly reports to third parties

Free apps often include advertising or analytics libraries. Even when they do not send the note itself, those components may collect information about the device, activity, and app usage.

Loknot contains no advertising or third-party analytics. The developer does not receive your notes or keep them on a company server.

The app only needs the internet to check for updates and to sync with your Google Drive — and sync happens only if you turn it on.

Protection that is on from the start

Immediately after installation, with no extra setup:

Extra security when you need another layer

PIN

A separate four-digit code protects entry to Loknot. After three failed attempts, the app waits five minutes before accepting another try.

The PIN cannot be recovered. If you forget it, you will need to reinstall the app and restore your notes from a backup.

Biometric unlock

Unlock with a fingerprint or face scan. The PIN remains in place as a fallback when biometrics are unavailable.

Auto-lock

Locks the app again after 30 seconds, 1, 3, 5, or 30 minutes in the background. It can be disabled, although that is not a good choice for private writing.

Screenshot blocking

Prevents screenshots inside Loknot and replaces the app's recent-apps preview with a blank screen.

Stronger backup-password rules

Prevents a backup from being protected with a weak password. The password must contain at least ten characters, upper- and lowercase letters, a number, and a special character.

System status: security you can inspect

Run a security check from System status. Loknot gives a clear overall result: All good, Needs attention, or Critical.

Database encryption

The check confirms that encryption of the notes database is active.

Loknot also rotates its encryption key about once every six months. A month beforehand, the app asks you to make a backup. This is routine maintenance, not a sign that something is broken.

Data integrity

Loknot checks the notes database for damage and explains what to do if it finds a problem.

Key protection

Loknot reports how the encryption key is stored:

  • hardware-backed — inside a dedicated secure component;
  • software-backed — protected by the operating system.

Both protect the key, although hardware-backed storage is the stronger option.

Threat checks

The app looks for root access, Frida or Xposed, an emulator, and an unexpected signing certificate.

Network protection

The status check confirms that unencrypted traffic is blocked and connections are authenticated.

Backup status

Loknot shows when you last made a local backup and adds a quiet reminder to System status once more than thirty days have passed.

Local backups

A local backup places all notes and folders into one file. It does not depend on a Google account or an internet connection.

Protect the archive with a password. On restore, notes are added to what is already there, while duplicates are skipped.

A backup password cannot be recovered. That is not a missing feature; it is a consequence of encryption. If support could reset the password, so could an attacker.

Store the password in a trustworthy password manager or keep a separate paper copy somewhere safe.

Important: Google Drive sync

When you enable sync, copies of your notes leave the device and are stored in your Google Drive app-data folder. You are responsible for securing your Google account and access to Google Drive.

Loknot never receives your Google password and cannot manage the security of your account. If someone gains access to the account, an active Google session, or a device that is already signed in, the cloud copy may be exposed.

Protect your Google Drive yourself:

  • use a strong password that you do not reuse elsewhere;
  • enable two-step verification or a passkey;
  • secure the account-recovery methods;
  • review signed-in devices and active sessions;
  • never leave the account open on someone else's device;
  • revoke any session you do not recognise.

Sync in the current Free edition is not end-to-end encrypted. Notes are kept in a private Google Drive app-data folder that only Loknot can access through the Drive interface, but Google can technically read the data.

End-to-end encrypted sync is planned for Pro, which is still in development. Do not rely on that protection until Pro has actually shipped.

If a note is too sensitive to leave the device, do not sync it. Loknot lets you disable sync for a particular folder and keep its contents local. Use a strongly encrypted local backup to protect those notes against loss.

What Loknot cannot protect

Honest security starts with knowing where its boundaries are.

Loknot cannot protect a note when:

Loknot protects data inside its own boundary. Once you export, send, or upload a note to another service, that service's security rules take over.

A private-notes setup checklist

A place where you can write honestly

Privacy is not only for people with something to hide. It is for anyone who wants room to think, doubt, capture unfinished ideas, and write without an unseen reader looking over their shoulder.

Loknot helps create that room without ads, a mandatory account, or a company server holding your writing. Notes are encrypted on the device, access can be locked down, the environment can be checked, and local backups remain under your control.

Your journal, working material, and private thoughts should belong to you. Loknot is designed to help keep them that way.

Get it on Google Play

For detailed setup instructions, see Security and privacy and Sync and backups in the guide.

Updated: