← Back to base

Alien Notes

Your notes and checklists — offline, encrypted, without an internet permission.

The big providers keep your notes in their cloud, synced through their servers, tied to an account. Alien Notes does the opposite: a local, encrypted notes and checklist app for Android / GrapheneOS and the Linux desktop — fully offline, no account, no server, no telemetry. The Android app requests no internet permission; the desktop version runs as a Flatpak without network permission and without access to your files. Your notes never leave the device in plaintext.

Sister app of Alien Pass and the Sachwert-Tresor — same architecture, same hardening, same Alien Investor style.

How to get it

As an app (Android / GrapheneOS): deliberately not on the Google Play Store, but via signed releases. Easiest through Obtainium: "Add app", enter the repo URL https://codeberg.org/Alien-Investor/alien-notes, and it will notify you of every update automatically. Or install the latest APK directly. Or straight from the Zap Store, the app store on Nostr.

Signature fingerprint (SHA-256) to verify authenticity with AppVerifier, identical across all versions:

F3:68:F9:0B:F8:DF:8C:55:BB:6C:28:6D:32:25:BA:8A:F4:45:22:7B:A6:9B:36:00:DF:BB:F6:A1:44:09:BA:7C apksigner: f368f90bf8df8c55bb6c286d3225ba8af445227ba69b3600dfbbf6a14409ba7c

First start: you set your passphrase (at least 12 characters; the suggest button creates six dice words from the EFF list). The app measures how fast your device handles the key derivation and suggests a matching Argon2 level. No reset, no backdoor: forget the passphrase and the notes are gone. Make a backup and keep the passphrase safe.

What it does

Security — and its limits

Limits, stated honestly

For the Linux desktop

The same code as on the phone, packaged with Electron as a Flatpak (x86_64). The file format is identical: import a backup from the phone on the desktop and vice versa. The file is in the Codeberg release, together with SHA256SUMS and the signature SHA256SUMS.asc. Not on Flathub, no automatic updates. Step-by-step install and update instructions: Flatpak guide (for all desktop apps) or the README (German).

Prerequisite: Flatpak with the Flathub remote (for the runtime org.freedesktop.Platform 25.08, which Flatpak fetches during installation):

flatpak remote-add --user --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo

1. Download three files from the release: alien-notes-1.5-linux-x86_64.flatpak, SHA256SUMS, SHA256SUMS.asc.

2. Verify the signature. The checksum is signed with the Alien Investor GPG release key — the same key as for Alien Pass and Sachwert-Tresor: alien-investor-release-key.asc. Compare the fingerprint through a second channel:

100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81

gpg --import alien-investor-release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS      # expected: Good signature from "Alien Investor (Release-Signatur) …"
sha256sum -c SHA256SUMS                     # expected: …flatpak: OK

3. Install and run:

flatpak install --user alien-notes-1.5-linux-x86_64.flatpak
flatpak run org.alieninvestor.notes

Alien Notes then appears in the application menu.

Update: Flatpak (as of 1.14) does not install a new bundle over an existing installation. Download and verify the new version (steps 1–2), then:

flatpak uninstall --user org.alieninvestor.notes    # deletes NO data (without --delete-data)
flatpak install --user alien-notes-X.Y-linux-x86_64.flatpak

Your notes live in ~/.var/app/org.alieninvestor.notes/data/alien-notes/notes.ainv and stay in place. Still make a backup first.

Check for yourself that the app has no network:

flatpak info --user --show-permissions org.alieninvestor.notes

Expected exactly:

[Context]
shared=ipc;
sockets=wayland;fallback-x11;
devices=dri;

No network, no filesystem.

The desktop version, honestly assessed

File format

One file with the magic AINV1: Argon2id parameters and salt in the header, below it the data key wrapped with the passphrase key and the notes encrypted with the data key (AES-256-GCM each). The header is authenticated as additional data (AAD) — an altered header makes decryption fail. Backups carry the extension .notes.

Open source on Codeberg

The client code is open source (MIT license) and free, the desktop shell is fully in the repo. No accounts, no server dependency.

🔗 codeberg.org/Alien-Investor/alien-notes

Version 1.5 (26 September 2026): hardening: another app could make Alien Notes crash on closing via certain autofill start data — the app now removes it at start (finding from the Alien Pass review); an import during which the app is locked and unlocked again no longer ends up in the new session. Version 1.4 (26 September 2026): the app keeps its fields out of the Android autofill framework — a third-party password manager set up as the autofill service used to offer itself in the passphrase fields (finding from the Alien Pass device test). Version 1.3 (26 September 2026): with "Lock in background: immediately" the copied note stays until the chosen time runs out and can still be pasted into another app (finding from the Alien Pass device test); the remembered import file reference also expires when the clock was set back. Version 1.2 (26 September 2026): import resumed after unlocking — with "Lock in background: immediately" the file chosen in the picker used to be lost (finding from the Alien Pass device test). Version 1.1 (26 September 2026): moving from Standard Notes, multi-select, "Undo" after deleting, rename categories, "Open" chip, "no preview", three font sizes, confirmations as in-app dialogs; plus the findings of the second internal audit fixed. First release 0.1 on 24 September 2026. Alien Notes is free. If it helps you, the mothership appreciates some fuel — see below. Sister apps: Alien Pass for passwords and the Sachwert-Tresor for Bitcoin, gold and silver holdings.


Charge energy (Donate)

Send fuel to the mothership