Security & Sharing
Experimental — not yet independently reviewed. Encrypted workspaces ship as a preview. The cryptographic design has not been audited by an independent reviewer, and two-device evidence on real Android and iOS hardware is still being collected. Try it, but keep a backup of anything you cannot lose, and do not rely on it for material you must protect.
Security Center, rekeying, and published slices
Security & Sharing has two levels. The overview (first level) shows the protection status, Finish migration when plaintext leftovers remain, Remove the connection to the encrypted cloud, and two cards that open the second level — Devices & recovery and Share with others. On the second level the area navigation replaces the settings left column, grouped into Your access (Devices, Recovery) and Sharing (Members, Groups, Slices, Publications); ‹ Overview returns to the first level. Visible actions stay usable: Plainva opens the selected vault, connection setup, workspace setup, or unlock flow when a prerequisite is missing. Removing a device or member can start a durable full rekey; its object-by-object progress survives pause, crash, and restart. A future-only rotation changes only subsequent writes.
Create a Vault Slice with the four steps Details → Content → Permissions → Review. Publishing a slice to people outside the vault works on the desktop and on the phone: Create publication builds a separate encrypted workspace with its own keys in its own folder, Invite recipient lets somebody in, and Withdraw access or Withdraw publication takes it back — with one boundary: withdrawing does not retrieve what someone already copied, it only stops anything new from reaching them and makes the next key epoch unreadable for them. A sanitized publication additionally removes private frontmatter properties, neutralizes links to excluded notes, and omits excluded embeds; permissions at Google Drive, OneDrive, Nextcloud, Dropbox, WebDAV, or S3 are additional protection, never a replacement for the encrypted roles, and Plainva shows the advice for the provider you pick without changing any sharing setting for you. On the phone the same path runs through the slice’s row: Publish a Vault Slice creates it, after which it appears under Publications with mode, access, the number of objects, and its state — Up to date, how many changes are still pending, or Refresh failed with the reason. Tapping the row opens Recipients with Invite recipient and Withdraw access; a long press offers Withdraw publication. Public release remains blocked until the independent crypto review and real Android/iOS two-device evidence are recorded.
Last reviewed: 2026-09-04
Plainva can keep a vault as ordinary readable files on your device while storing its cloud copy as opaque encrypted objects. Open Settings → your vault → Security & Sharing after connecting a cloud account.
On mobile the area first names what this vault really is: On this device only without a cloud connection, This connection is not encrypted for an ordinary cloud vault — Set up encryption there runs the same three steps as on the desktop (identity → recovery file and code → activation with a resumable progress bar) — or the join steps as soon as the connection carries an encrypted workspace.
First setup
- Choose an owner and device name. Device keys stay in the operating-system keychain; where that is unavailable, Plainva asks for a local passphrase.
- Save the
.pvrecoveryfile and store the displayed recovery code separately — not in the vault it unlocks: Plainva refuses a location inside that vault, because there the one artifact you cannot recreate would stay readable exactly as long as you do not need it. Every code block has a visible group number; Plainva asks for two of them, and their values stay hidden while the question is open. Revealing them is allowed, but it draws a fresh pair — copying does not answer the question being asked here. A group you answered correctly comes back into view. You need both parts for recovery; neither contains cloud credentials. - Activate the workspace. Plainva publishes its signed owner policy and encrypts every local file into
.pvws/. The local vault remains readable. If the run breaks off — a crash, a power cut, a closed app — the status says Setup incomplete the next time you open it and offers Resume setup: your keys are long since saved at that point, only the rest of the conversion is missing.
Existing plaintext at the provider remains beside .pvws/ during migration. Only after the status is Protected can you explicitly remove it. This action never removes local files.
Everyday use
Offline changes stay in a durable queue. Every change is signed; remote deletion alone never deletes a local file, while a signed tombstone can. Parallel offline edits are preserved as .CONFLICT-… copies. Lock really deletes the workspace keys from memory — the signing key, the decryption key, and every group key the session fetched; Unlock fetches them again from the system keychain or local passphrase.
Devices and recovery
To add your own second device, open Devices & recovery → Devices → Add another device: Plainva shows an invitation code bound to your own membership — it does not create a new member. Paste it on the second device (Security & Sharing → join) and approve it on a device that is already in; compare the fingerprint on both devices first. While the second device waits, it shows how long the request stays valid and prompts for the fingerprint comparison exactly as the approving side does — a comparison only helps when both sides look. If asking fails, the reason is there; before, a broken connection looked exactly like “nobody approved yet”. To bring in another person instead, use Share with others → Members → Invite a person (see below). A removed device cannot sign new valid changes. Both the invitation and a joining device’s pairing request are also shown as scannable QR codes — on mobile, Scan invitation reads a code with the camera instead of pasting text.
Removing a device or a member offers two costs, and the phone offers both as well. Future only ends access to new keys straight away and is quick. Full rekey also rewrites everything already encrypted; it is long work, it continues in the background, and it picks itself back up after a restart — a card of its own shows a progress bar and an object counter while it runs, and says there that the run survives a restart. Neither can take back anything the other side already downloaded, which is why the question says so before you choose. You can never remove the device you are holding: that would lock this device out with only the recovery package left.
Where no system keychain answers — typically a Linux machine without a desktop session — this device’s keys sit under a local passphrase. You can change it: Devices & recovery → Devices → Change passphrase. Plainva asks for the current passphrase even while the workspace is unlocked — an unattended unlocked machine is exactly the case where a silent change would lock the owner out. Only the keys on this device are resealed: your recovery file and its code stay valid, and other devices notice nothing. The phone has no such button, because there is nothing there to change — Android and iOS always have a key store, so the passphrase variant never applies.
Recovery lives under Devices & recovery → Recovery, split into Current status (is a recovery package saved, and the workspace fingerprint) and the Recovery workflow. If every device is lost, choose Restore access there and open the .pvrecovery file with its separately stored code; Plainva creates a new owner device, can revoke the lost devices, and does not rewrite content objects. Renew recovery replaces the old recovery set through a dual-signed anchor chain. Store the new file and code separately again; the old set is invalid afterwards. Plainva asks before it rotates, because the file in your hands stops working the moment it does.
Members, roles, and vault slices
Owners and admins can invite members, create groups, and scope roles to the whole workspace, a slice, or one object. An Editor can read and edit, a Commenter can read and comment, a Reader can only read, and a Contributor can only submit new content to the assigned scope — and because a contributor may not read the existing material but must be able to keep writing their own note, their write permission covers everything they created themselves. The full table sits under What the roles allow in the Members area; that is also where the sentence lives that would otherwise be half-repeated in every dialog: provider permissions are a second lock, never a replacement for encrypted roles. Plainva checks this before every local disk write and again before signing, so it also covers imports, restores, automations, AI actions, and changes made by other local programs.
Ownership can move to another active member. Open Share with others → Members (on the phone: the Team area) and choose Transfer ownership next to that person. It needs the current recovery file and its code, because ownership and the recovery set move together: Plainva builds a replacement recovery package first and hands over only after you have saved it. Give that file and its new code to the new owner through separate channels — you become Admin, and they are the only Owner afterwards.
A slice can contain a folder, an explicit object selection, or a dynamic rule over path, type, tags, and properties. All three are chosen, not typed: you tick group members in a list, you search and tick the notes of a selection slice, and you build a dynamic rule row by row from field, comparison, and value — the tag and property suggestions come from the same objects the preview matches against, so what is offered here can actually match something. The stored raw value stays reachable under Technical details and remains editable; a hand-written rule the builder cannot express is never silently rewritten. The folder of a folder slice is picked straight from the vault with Choose folder… — on the phone as well; whoever prefers typing the path still can.
Always use Preview before creating it — on the phone as well. Only the displayed stable object IDs are materialized; one file can carry encrypted envelopes for several groups. Unauthorized objects are not materialized and never enter search, graph, or preview data. What you can create on the phone is a folder slice; selection and dynamic rule stay on the desktop, because both need a picking surface over the whole object set.
If a slice’s definition can no longer be read — a hand-edited entry, a broken rule — then it grants nothing, not even through the objects it last covered. Both shells name the reason instead of showing “0 objects”: a zero reads like an empty share, not a broken one. And when you move a note out of a shared folder, Plainva asks first and names the groups that lose access — you notice your own loss immediately, someone else’s never.
Comments, versions, and security review
Comments and suggestions — the column, the anchors, the suggest mode, the overview and the notifications — are described on Comments & Suggestions; they work in every vault. This page keeps only what hangs on the workspace.
When a note is published and its recipients have written something, that appears below your own threads — one section Sent back from “…” per publication, with the names from its member list. Those remarks live in the publication’s workspace, never in your vault, so you can only read them here. Replying, resolving or applying a suggestion would be a write into the publication and is not possible from this side. If the publication carries a sanitised version, the card says the suggestion cannot be applied here; if someone lost access, that is stated too. If a publication is locked or its key is missing on this device, its section is simply absent — your own comments are unaffected. The phone does not have this column.
Version history reads encrypted workspace revisions and restores an older revision as a new signed change or as a copy.
Malformed remote artifacts are isolated under Integrity & local forks. You can retry them, export their ciphertext, mark an externally repaired artifact as repaired, or deliberately ignore it. One malformed file does not stop valid synchronization, and remote absence alone is never interpreted as deletion. A local program’s unauthorized change is retained as a private fork copy. A local fork — the copy this device keeps when a write was refused — carries Compare: the same comparison view as a conflict, with the exits Adopt, Keep both and Discard; afterwards the fork leaves the list. The same on the phone.
What Integrity & local forks says
When an artifact from the cloud fails a check, it stays in quarantine and sync carries on for everything else. The card shows one group per cause and device — with the number of entries, an explanation and, where there is one, a line What you can do. The most common group is a broken chain: this device expects change no. 14 from another one while the cloud holds no. 16 — usually a second copy of the same device is behind it (a development instance with its own storage, say) or a device that was reconnected and counts from 1 again. Check again waits for the next sync and says what is still open; whatever passes disappears from Open by itself and stands under All as resolved. Export diagnosis writes a JSON file with cause, device, sequence numbers and times (to the clipboard on the phone), never with content. Behind ⋯ sit Mark as fixed and Ignore group — ignoring is final, the group’s changes are then lost. Show entries names the cloud key and the technical reason per artifact.
Removing an encrypted vault the right way
When you no longer need an encrypted vault, decommission it in Plainva before you delete the cloud folder. The order matters: the fail-closed guard keeps sync stopped if the cloud copy disappears while Plainva still expects the connection to be encrypted — this protects you from an attacker stripping the encryption to force plain text.
- Open Settings → your vault → Security & Sharing.
- On the overview, in the Encryption card, choose Remove the connection to the encrypted cloud. Plainva clears the local keys and workspace data on this device and reopens the vault as a normal vault. (This is device-local: the cloud copy stays encrypted. To get it back as plain text, Lift encryption is the way — see the paragraph below.)
- Only now delete the cloud folder (the
.pvws/objects) at your provider if you want it gone. Plainva does not delete the encrypted cloud objects for you.
On the phone the same step sits in the same place, with one difference: you confirm it by typing the vault’s name. Everything else is identical — the local keys and workspace data go, the vault reopens as a normal vault, and the encrypted objects in the cloud stay until you delete them yourself. It works without a connection, because nothing about it is remote.
To instead end encryption entirely and keep the vault in the cloud as ordinary files, choose Lift encryption in the same Encryption card: Plainva reopens the vault as a normal cloud vault and re-uploads all of your notes to the same cloud as plain files, then stops encrypting. Local files are never changed and nothing is deleted; the old encrypted .pvws/ folder stays until you delete it at your provider (Plainva cannot remove those immutable objects for you). Confirm the danger prompt first — the notes leave the encrypted store as plain text. On the phone the same action sits in the Security overview next to Disconnect from the encrypted cloud; the plain-text upload continues through the normal sync queue there — even after switching apps, under the mobile-data rules — and a card counts how many files are still waiting.
If you already deleted the cloud copy and sync now fails with a “workspace is missing” or “manifest is missing” error, the fix is the same reset, offered where the error appears:
- For an encrypted workspace, open Security & Sharing. The status shows an error with a recovery note; in the Encryption card choose Remove the connection to the encrypted cloud to reset the workspace on this device so sync works again.
- For a content-encrypted sync connection, click the sync status to open the sync-error dialog and choose Reset encryption. This button only appears when the remote encryption data is missing or invalid.
Both actions are explicit and confirmed. Plainva never silently downgrades an encrypted connection to plain text, and neither action deletes any local files. If the cloud still holds encrypted content you actually want, cancel instead — resetting would resume plain-text sync.
Removing a vault with Forget app data (Splash → remove a vault → also forget app data) clears these encryption markers too, so a vault removed that way leaves nothing behind that could block a later re-connection.