DunneNote · Your data
Security and privacy
What stays on your computer, what doesn't, where secrets are kept, and how to report a security problem.
Your notes stay on your computer#
DunneNote works entirely offline. There is no account and nothing to sign into. A notebook is a folder on your disk, and every feature works with the network unplugged. There is an option to back up to a cloud instance that YOU own, or to a server process you run on your home system.
DunneNote connects to the network only when you set something up to do so:
- a backup destination you configure, such as an S3 bucket or another computer running DunneNote Host;
- a web link you choose to open, which opens in your browser.
With a licence key from a subscription, DunneNote
also renews the key with license.dunnecorp.com about once a month, until it
becomes yours. It sends only the key and the app's version, with no device ID.
Checking a key happens on your computer, so adding one never connects, and a
one-time licence never connects at all.
Settings ▸ General has an Allow downloading external reference data option. It is off by default, no feature uses it yet, and nothing is downloaded while it is off.
Link checking is offline#
When you follow a web link, DunneNote checks it against rules and a blocklist that ship with the app. No link is sent anywhere to be checked. The trade-off is that the blocklist is only as current as your copy of DunneNote. The alternative would mean sending every link you open to someone else. See Links and templates.
Secrets are kept in your system's credential store#
Backup passphrases and S3 access keys are kept in your operating system's own credential store: macOS Keychain, Windows Credential Manager or the Linux Secret Service. They are never stored in the notebook or in DunneNote's settings files, so they don't travel when you copy a notebook to another computer. The notebook is portable, but the right to write to your backup destinations stays on the computer where you set it up.
Settings ▸ Backup ▸ Lock now removes every saved backup secret from this computer.
Encryption#
Backups can be encrypted, and backups to S3 or to another computer must be. Encryption happens on your computer before anything is written. A passphrase you choose is stretched with Argon2id and protects a random key, and each item is sealed with XChaCha20-Poly1305. The destination only ever holds encrypted data, and a recovery code gives you a second way in. See Backup and restore.
The notebook on your own disk is not encrypted by DunneNote. Use your operating system's full-disk encryption (FileVault, BitLocker or LUKS) to protect it. That protects everything else on the computer too.
A restored copy of an unencrypted backup is also unencrypted, and DunneNote tells you so when it restores.
DunneNote Host#
The backup host listens only on the network address you give it, and only while you are logged in. Computers must be paired using a short-lived code before they can send backups, and they can only send encrypted backups.
Logs stay local#
DunneNote writes a daily audit log in its app-data folder (see Installing DunneNote). Each entry records what was attempted and what happened. Logs are never sent anywhere. Some logs name notebook folders, so treat them as private.
Where the builds come from#
The macOS build is code-signed and notarized by Apple, and so is the macOS DunneNote Host. The Windows and Linux builds are not yet signed: download them only from the download page, and compare each file's SHA-256 checksum with the one listed there. A signed Microsoft Store version of the Windows app is planned. See Installing DunneNote.
Reporting a security problem#
Please don't post security problems publicly. Signed-in customers can open a support ticket. Anyone else can use the contact form. Include as much detail as you can, and we'll follow up with you directly.
For a problem in the open format, its library or dnfmt, use GitHub's private
vulnerability reporting on the
dunnenote-format repository
(Security tab, then Report a vulnerability) rather than a public issue.
Something unclear or out of date? Open a support ticket.