The big providers keep your notes in their cloud, synced through their servers, tied to an account. Alien Notes does the opposite: a local, encrypted notes and checklist app for Android / GrapheneOS and the Linux desktop — fully offline, no account, no server, no telemetry. The Android app requests no internet permission; the desktop version runs as a Flatpak without network permission and without access to your files. Your notes never leave the device in plaintext.
Sister app of Alien Pass and the Sachwert-Tresor — same architecture, same hardening, same Alien Investor style.
How to get it
As an app (Android / GrapheneOS): deliberately not on the Google Play Store, but via
signed releases. Easiest through Obtainium:
"Add app", enter the repo URL https://codeberg.org/Alien-Investor/alien-notes, and it will notify you of every update automatically.
Or install the latest APK directly.
Or straight from the Zap Store, the app store on Nostr.
Signature fingerprint (SHA-256) to verify authenticity with AppVerifier, identical across all versions:
F3:68:F9:0B:F8:DF:8C:55:BB:6C:28:6D:32:25:BA:8A:F4:45:22:7B:A6:9B:36:00:DF:BB:F6:A1:44:09:BA:7C
apksigner: f368f90bf8df8c55bb6c286d3225ba8af445227ba69b3600dfbbf6a14409ba7c
First start: you set your passphrase (at least 12 characters; the suggest button creates six dice words from the EFF list). The app measures how fast your device handles the key derivation and suggests a matching Argon2 level. No reset, no backdoor: forget the passphrase and the notes are gone. Make a backup and keep the passphrase safe.
What it does
- Notes and checklists — a note is free text (up to 100,000 characters), a checklist has up to 200 entries with boxes, "done to the bottom" and "clear ticks". Switch a note between the two: lines become entries and back, with a warning whenever something would be shortened.
- No save button — the app saves as you type (after 1.5 s) and when you leave the note, encrypted, the whole file every time. The title may stay empty; the first line then serves as the title.
- Markdown preview per note (switch, off by default) — headings (
#to###), bold, italic, lists, boxes (- [ ],- [x]), code, rules. A small own subset, no third-party renderer, no HTML, links deliberately stay plain text — the app has no network anyway. A cheat sheet in the editor shows "type this → looks like this" and inserts an example note on request. - Categories like folders (type freely, suggestions from existing ones, filter chips above the list, rename a category with all its notes), favourites, pinned notes at the top, an "Open" chip for checklists with unfinished entries, search across title, text, checklist entries and category. "Insert date" puts date and time at the cursor.
- Moving from Standard Notes (since 1.1) — reads a decrypted Standard Notes backup, the downloaded ZIP directly or the text file inside. Plain, Markdown, code, rich-text and Super notes become notes, checklists become checklists, the first tag becomes the category. Authenticator (2FA) entries, spreadsheets and files are never imported; a second import creates no duplicates.
- Several at once (since 1.1) — pick notes and move them to the trash together (one "Undo" for all, at most 200 at once), set a category or the favourite mark. Plus "Undo" after moving to the trash (six seconds), "no preview" per note, three font sizes — and every confirmation is an in-app dialog, because the Android system dialog does not inherit the screenshot protection.
- Copy with auto-clear — "Copy" puts the whole note into the clipboard; the app clears it after the set time (15/30/60 s, default 30 s, can be switched off) and on lock. In the Android app copied content is flagged sensitive so the system preview hides it (Android 13+). With "Lock in background: immediately" the copied note stays until the chosen time runs out so it can still be pasted into another app (since 1.3).
- Locking, more relaxed than a password manager — by default no lock after inactivity and in the background only after 30 minutes, both adjustable up to "never" / "immediately". The background lock applies when you return after the chosen time; until then the key stays in memory. "Lock now" clears the key and everything on screen at once. The file on the device is always encrypted. With "immediately" the Android app also locks while the file picker is open; unlock within five minutes and the import continues with the chosen file (since 1.2).
- Trash — deleted notes stay restorable for 30 days, up to 200 notes at a time; it shows only title, type and date, never the content. It is device-local: when merging, a deletion travels to your other devices, the content does not.
- Encrypted backup & merge — the
.notesfile is fully encrypted. Per note the newer change wins, deletions are carried for a year. Sync e.g. via Syncthing, also between phone and Linux desktop. - Aegis hurdle (optional) — an extra TOTP code from Aegis on unlock; key or otpauth link to copy, no QR. Honestly documented as a hurdle, not a second factor.
- Fingerprint unlock (optional, Android) as in Alien Pass, with the passphrase required after every restart unless "also after a restart" is ticked when enabling (off by default). Quick unlock by PIN (optional, desktop only) after a lock.
- Screenshots and app-switcher preview (Android) — blocked by default (FLAG_SECURE), can be switched off in Settings, because notes are not always secret. Locked and during setup the protection is always on.
- No Android autofill, not even third-party (since 1.4) — the app keeps its WebView out of the Android autofill framework. A password manager set up as the autofill service never sees the passphrase fields and cannot offer to save them. The HTML attribute
autocomplete="off"alone does not stop this, hence natively. - Bilingual — German and English, offline manual inside the app.
Security — and its limits
- Argon2id derives the key from your passphrase (32/64/128 MiB, self-benchmarked at setup) — memory-hard, so expensive for GPU attacks on a stolen file.
- AES-256-GCM via WebCrypto. Own file format
AINV1with its own keys — Alien Pass rejects a notes file and vice versa. - Markdown without attack surface. The preview is rendered only via
createElement/textContent— no HTML, links stay plain text. - No internet permission. Only USE_BIOMETRIC and USE_FINGERPRINT (up to Android 8.1) for the fingerprint sensor, plus the AndroidX-generated signature permission that grants nothing. Strict CSP:
connect-src 'none', no inline script. - No cloud, ADB or device-to-device backup. allowBackup=false plus data extraction rules — you make backups yourself via the encrypted
.notesfile. - Notes file in the private app folder, written atomically (temp file, fsync, rename) — never a half-written file. The 20 MB file limit is enforced on save as well; an oversized file still opens so you can tidy up.
- Internal security audit of the surface that is new compared to Alien Pass, before release (no independent audit): seven low-severity findings and one note, all fixed; a follow-up covered the file store and the 20 MB write limit added afterwards (one finding, also fixed before release). A second internal audit (25–26 September 2026, before 1.1) took apart the Standard Notes import including the ZIP reader, the confirmation dialog, undo and multi-select: no path from a foreign backup into markup or script; five findings without an outside attacker (among them a race on saving on Android, present since 0.1, that could silently drop a change), all fixed before release and covered by regression tests. Bundled Argon2 library (hash-wasm) hash-checked in the build.
Limits, stated honestly
- The keyboard learns along. It learns from what you type; a WebView cannot switch that off. If you do not want that, use a keyboard without personalised learning.
- "Never" means: key in memory. With "never" as the background lock, the key stays in memory until the system ends the process. Even with the default (30 minutes) it stays there until you return. "Lock now" clears it at once.
- FLAG_SECURE has limits. It blocks screenshots and the app-switcher preview; it is no protection against accessibility apps, root or a camera. If you switch it off, the unlocked app loses this protection.
- Clipboard in the background. The Android app only clears it as long as Android has not frozen the app (usually after the second app switch); otherwise on return. From Android 13 the system clears it by itself after about an hour, older versions do not.
- On the desktop no protection against screenshots and no automatic lock on screen lock or suspend — details in the Linux desktop section.
For the Linux desktop
The same code as on the phone, packaged with Electron as a Flatpak (x86_64). The file format is identical: import a backup from
the phone on the desktop and vice versa. The file is in the
Codeberg release, together with
SHA256SUMS and the signature SHA256SUMS.asc. Not on Flathub, no automatic updates.
Step-by-step install and update instructions: Flatpak guide (for all desktop apps) or the
README (German).
Prerequisite: Flatpak with the Flathub remote (for the runtime org.freedesktop.Platform 25.08, which Flatpak fetches during installation):
flatpak remote-add --user --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
1. Download three files from the release: alien-notes-1.5-linux-x86_64.flatpak, SHA256SUMS, SHA256SUMS.asc.
2. Verify the signature. The checksum is signed with the Alien Investor GPG release key — the same key as for Alien Pass and Sachwert-Tresor: alien-investor-release-key.asc. Compare the fingerprint through a second channel:
100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81
gpg --import alien-investor-release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS # expected: Good signature from "Alien Investor (Release-Signatur) …"
sha256sum -c SHA256SUMS # expected: …flatpak: OK
3. Install and run:
flatpak install --user alien-notes-1.5-linux-x86_64.flatpak
flatpak run org.alieninvestor.notes
Alien Notes then appears in the application menu.
Update: Flatpak (as of 1.14) does not install a new bundle over an existing installation. Download and verify the new version (steps 1–2), then:
flatpak uninstall --user org.alieninvestor.notes # deletes NO data (without --delete-data)
flatpak install --user alien-notes-X.Y-linux-x86_64.flatpak
Your notes live in ~/.var/app/org.alieninvestor.notes/data/alien-notes/notes.ainv and stay in place. Still make a backup first.
Check for yourself that the app has no network:
flatpak info --user --show-permissions org.alieninvestor.notes
Expected exactly:
[Context]
shared=ipc;
sockets=wayland;fallback-x11;
devices=dri;
No network, no filesystem.
The desktop version, honestly assessed
- No network, enforced by the system. A Flatpak without network permission and without file access; files only through the system file dialog.
- Its own browser engine. The desktop app ships Electron itself. Updates for it only arrive with a new app version, not through the system.
- Limits: no protection against screenshots. Under X11 every program can read keyboard and clipboard. On screen lock and suspend the app does not lock by itself — Ctrl+L locks immediately. No fingerprint.
- Quick unlock with a PIN (optional) — taken over from Alien Pass: the PIN only protects a copy of the key in memory, at most 24 hours, never the file. The detailed assessment is on the Alien Pass page.
File format
One file with the magic AINV1: Argon2id parameters and salt in the header, below it the data key wrapped with the passphrase key
and the notes encrypted with the data key (AES-256-GCM each). The header is authenticated as additional data (AAD) — an altered header
makes decryption fail. Backups carry the extension .notes.
Open source on Codeberg
The client code is open source (MIT license) and free, the desktop shell is fully in the repo. No accounts, no server dependency.
Version 1.5 (26 September 2026): hardening: another app could make Alien Notes crash on closing via certain autofill start data — the app now removes it at start (finding from the Alien Pass review); an import during which the app is locked and unlocked again no longer ends up in the new session. Version 1.4 (26 September 2026): the app keeps its fields out of the Android autofill framework — a third-party password manager set up as the autofill service used to offer itself in the passphrase fields (finding from the Alien Pass device test). Version 1.3 (26 September 2026): with "Lock in background: immediately" the copied note stays until the chosen time runs out and can still be pasted into another app (finding from the Alien Pass device test); the remembered import file reference also expires when the clock was set back. Version 1.2 (26 September 2026): import resumed after unlocking — with "Lock in background: immediately" the file chosen in the picker used to be lost (finding from the Alien Pass device test). Version 1.1 (26 September 2026): moving from Standard Notes, multi-select, "Undo" after deleting, rename categories, "Open" chip, "no preview", three font sizes, confirmations as in-app dialogs; plus the findings of the second internal audit fixed. First release 0.1 on 24 September 2026. Alien Notes is free. If it helps you, the mothership appreciates some fuel — see below. Sister apps: Alien Pass for passwords and the Sachwert-Tresor for Bitcoin, gold and silver holdings.