Three of my apps have been available for the Linux desktop since September 2026: Alien Pass (since v1.7), the Sachwert-Tresor (since v3.3) and Alien Notes (since v0.1). All three run as a Flatpak (x86_64) with the same shell: no network, no file access, files only through the system dialog. They are deliberately not on Flathub and do not update themselves — you download the file from the Codeberg release, verify the signature and install it yourself. This page shows the way once for all three apps.
1. Prerequisite: Flatpak with Flathub
The apps need the runtime org.freedesktop.Platform 25.08, which Flatpak fetches from Flathub during installation. Once, as a user
(no root, no sudo):
flatpak remote-add --user --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
2. Download three files from the release
From the latest release on Codeberg you need the bundle, the checksum file and its signature:
- Alien Pass:
alien-pass-X.Y-linux-x86_64.flatpak,SHA256SUMS,SHA256SUMS.asc - Sachwert-Tresor:
sachwert-tresor-X.Y-linux-x86_64.flatpak,SHA256SUMS,SHA256SUMS.asc - Alien Notes:
alien-notes-X.Y-linux-x86_64.flatpak,SHA256SUMS,SHA256SUMS.asc
An -rN in the file name (such as alien-pass-1.8-r2-…) is a rebuild of the shell with the app unchanged.
3. Verify authenticity: GPG-signed checksum
The file SHA256SUMS is signed with the Alien Investor GPG release key — the same key for all desktop apps.
The public part is here on the website (alien-investor-release-key.asc) and in all three repos.
Compare the fingerprint through a second channel before trusting the key:
100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81
gpg --show-keys alien-investor-release-key.asc # prints the fingerprint — compare with the line above
gpg --import alien-investor-release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS # expected: Good signature from "Alien Investor (Release-Signatur) …"
sha256sum -c SHA256SUMS # expected: …flatpak: OK
The checksum is signed, not the bundle itself — hence both commands: gpg --verify proves the checksum comes from me,
sha256sum -c proves the bundle matches that checksum. If either fails, do not install.
4. Install and run
flatpak install --user alien-pass-X.Y-linux-x86_64.flatpak
flatpak run org.alieninvestor.pass
flatpak install --user sachwert-tresor-X.Y-linux-x86_64.flatpak
flatpak run org.alieninvestor.tresor
flatpak install --user alien-notes-X.Y-linux-x86_64.flatpak
flatpak run org.alieninvestor.notes
The apps then appear in the application menu. A backup from the phone (.vault, for Alien Notes .notes) is imported through the file dialog — the format is identical.
5. Update: uninstall, reinstall
Flatpak (as of 1.14) does not install a new bundle over an existing installation. Download and verify the new version (steps 2 and 3), then:
flatpak uninstall --user org.alieninvestor.pass # deletes NO data (without --delete-data)
flatpak install --user alien-pass-X.Y-linux-x86_64.flatpak
For the vault the same with org.alieninvestor.tresor, for Alien Notes with org.alieninvestor.notes. Your data stays in place:
- Alien Pass:
~/.var/app/org.alieninvestor.pass/data/alien-pass/vault.aipv - Sachwert-Tresor:
~/.var/app/org.alieninvestor.tresor/data/sachwert-tresor/vault.aisv - Alien Notes:
~/.var/app/org.alieninvestor.notes/data/alien-notes/notes.ainv
Still make a backup before every update. Close a running window first — otherwise the old version keeps running.
6. Check for yourself that the app has no network
flatpak info --user --show-permissions org.alieninvestor.pass
Expected exactly this output (identical for the vault and for Alien Notes):
[Context]
shared=ipc;
sockets=wayland;fallback-x11;
devices=dri;
No network, no filesystem. This is not a setting inside the app but the system itself: inside the Flatpak sandbox there
is no network without the network permission, and the app only reaches files you pick in the dialog.
What the desktop version can do — and where its limits are
- No network, enforced by the system. Backup, import and exports go through the file dialog, which only grants the chosen file.
- Its own browser engine. The apps ship Electron themselves. Security updates for it only arrive with a new app version, not through the system.
- No protection against screenshots (Linux has no counterpart to FLAG_SECURE). Under X11 every running program can read keyboard and clipboard; Wayland separates programs better.
- On screen lock and suspend the apps do not lock by themselves. Use the system lock plus a short inactivity lock; Ctrl+L locks immediately. Minimised or hidden counts as background, switching windows only clears typed passphrases.
- No fingerprint. The passphrase remains the key; on the desktop Alien Pass and Alien Notes optionally offer quick unlock with a PIN, the vault does not.
Details per app: Alien Pass on the desktop · Sachwert-Tresor on the desktop · Alien Notes on the desktop.