Sync Setup
Last updated: 2026-08-21
Plainva optionally syncs each vault with a storage of your choice — straight from the app, with no Plainva-run service in between: your data travels exclusively between your computer and your own account/server. This page walks through the setup per provider.
Which services work in general (also via WebDAV or the provider’s desktop client) is covered in Sync Compatibility.
Basics
- Setup lives under Settings → your vault → Cloud accounts: Connect account… opens the assistant — pick the provider first, then tick the services (for file sync: Files), then sign in. The tile overview lists providers by real-world reach; Search providers… also finds the email providers that ship as presets. Exactly one account per vault carries the Files service. The Sync area then shows the connected account with its Cloud folder and holds the behavior (Sync interval, queue); Manage account leads back to the cloud accounts.
- For the Files service, besides Microsoft (OneDrive), Google (Drive), Dropbox, Nextcloud, Object storage (S3) and generic WebDAV / CalDAV, the tiles also include Fastmail, mailbox.org, Yandex, Mail.ru, Koofr and pCloud: there, your email address plus an app password is enough — the server addresses are already filled in (WebDAV-based; changeable via Advanced: set endpoints individually).
- Open an existing online vault from the start screen: Open Vault → Online vault walks you through the same three steps for every provider — 1. Connect (sign in or enter credentials), 2. Choose the folder in the cloud (a fresh folder can also be created there via New folder), 3. Choose or create the local folder. Alternatively you can set up sync for an already-open vault any time under Settings.
- Create a new vault in the cloud: New Vault → With an online service — first pick the starter structure (empty or a template like PARA), then connect and choose the target folder in the cloud or create it via New folder, finally the local folder. The structure is created in the local folder and uploaded automatically by the first sync.
- Local saves are uploaded immediately; Plainva checks for remote changes at the configured Sync Interval (seconds).
- Offline changes are queued and transferred on the next contact; the status bar shows Online/Offline and the sync indicator shows the state (Sync now on click). During a long or first-time sync the status bar shows the progress as a count (e.g. Sync 123/540), so you can see it working through the vault.
- If both sides change the same file, Plainva merges them automatically (3-way merge). If that is not possible, your version is safely preserved as a
.CONFLICTfile — nothing is ever lost (see FAQ). - Resolving conflicts: a banner in the affected note (and Resolve conflict… in the
.CONFLICTfile’s right-click menu in the tree) opens the comparison dialog — the file’s current state on the left, your preserved version on the right, editable with per-block take-over. Save right side & resolve writes the result into the file and cleans up the conflict copy; Keep the other side discards your copy (a version snapshot remains). The sync error dialog also lists existing conflict copies and takes you to the same comparison with one click. - Mass-deletion protection: if an unusually large share of the synced files is about to be deleted in the cloud at once (for example because the local vault folder was emptied or moved), Plainva holds the deletions and asks first: Delete in the cloud executes them, Don’t delete (restore) discards them and restores the files from the cloud on the next sync. Deletions you confirmed in Plainva yourself are not held — for large deletions (more than 10 files or more than 20% of the vault) Plainva instead asks a second time before deleting.
- Attachments (images etc.) are synced too.
- Empty folders sync as well: a folder created in Plainva appears in the cloud right away, and empty cloud folders appear on your other devices with the next full listing at the latest.
- Credentials and tokens are stored in the operating system’s keychain (status: Settings → App → About & diagnostics → OS keychain), never in files inside the vault.
- Stored access (Settings → Vault → Synchronisation) shows what Plainva has placed in the keychain — including entries from vaults you stopped opening long ago. Each row names the service and the vault; Remove asks first. Plainva never deletes anything here on its own.
- Keychain entries carry readable names —
plainva · <vault> · <service> · <account id> · #<fingerprint>instead of a base64 string. Plainva renames existing entries once, the first time a vault is opened; if a rename cannot be completed safely the old entry stays where it is and Plainva tries again on the next open. - Disconnect stops the vault’s sync; no files are deleted anywhere by doing so.
http://is allowed,https://is the recommendation. A server you run on your own network usually speaks plainhttp— that works, on the phone too. Across the internet you should not: WebDAV sends your password with every request, in the clear overhttp. If you enter an unencrypted address outside your own network, Plainva says so in the form — it does not stop you.
WebDAV / Nextcloud
The simplest route for self-hosted servers and most cloud storages:
- In Cloud accounts → Connect account… pick the Nextcloud tile (or WebDAV / CalDAV).
- Enter the Server address, Username and Password or App Token — use an app password instead of your main password whenever possible (in Nextcloud: Settings → Security → App passwords).
- Connect validates the credentials; afterwards pick the Cloud folder via Choose folder….
Nextcloud special: ONE form covers files and calendar — Plainva derives the WebDAV and CalDAV endpoints from the server address itself (the derived addresses are shown in the assistant; Advanced: set endpoints individually allows separate URLs). Tick both services and a single pass connects both.
Typical server addresses (Nextcloud, Koofr, MagentaCLOUD, Storage Box and many more) are listed in Sync Compatibility.
If the app password changes later, enter it once in the account details under Credentials: Plainva verifies it against every service of that account and only stores it when all of them accept — so no service is left behind on an old password.
Google Drive
Google Drive currently runs with your own credentials (“Bring Your Own”): you create a free Google Cloud project once, owned by you alone. The step-by-step guide: Google Drive (BYO).
Short version: in Cloud accounts → Connect account… pick the Google tile, tick the Files service, enter the Client ID and Client Secret from your Google project, then Sign in with Google… — the sign-in opens in your browser. Once connected, pick the Cloud folder via Choose folder… straight from your Drive (subfolders included, default “Plainva”). Note: while your Google project sits in testing mode, the sign-in expires after 7 days — for good, because Google lets the refresh token expire too in that mode, so Plainva cannot renew it in the background. Sync then tells you the sign-in has expired, and Sign in again in the account details restores it — one round trip for all services of that account. If you would rather not do that weekly, set the Google project to In production in the console: the sign-in then stays valid (for an unverified app Google shows a warning screen once, which you can confirm as its owner).
If you tick Files and Calendar together while connecting, Google asks for your consent only once — requesting exactly the permissions of the services you picked. Adding another service later brings a second, incremental consent.
OneDrive
Plainva ships its own app registration — you no longer need your own ID:
- In Cloud accounts → Connect account… pick the Microsoft tile and tick the Files service (OneDrive) — on request together with Calendar & tasks and Email (one Microsoft account can carry all three services).
- Sign in with Microsoft… and confirm the sign-in in the browser. Done — Plainva creates the folder (default “Plainva”) and syncs its entire content, including externally added files.
- Optional: once connected, pick the Cloud folder via Choose folder… straight from your OneDrive (subfolders included).
Optional: via Use your own app ID you can instead supply a self-registered client ID (e.g. for corporate restrictions). Detailed guide: OneDrive & Dropbox (BYO).
When you connect several services of one account together — say Files and Calendar — the provider asks for your consent only once, and Plainva keeps a single sign-in for the whole account. This holds for Microsoft (files, calendar, mail) as well as Google (files and calendar; a Gmail mailbox stays out of it, because it runs over IMAP with an app password and needs no consent).
The wizard carries the provider you picked through every step: steps 2 and 3 open the matching form right away (the Google calendar form instead of a provider chooser, Gmail instead of a generic IMAP form) and never ask again who you wanted to connect. What one step collected is already there in the next — for Nextcloud, Plainva derives the CalDAV address from the server address of step 1, and a suite password is typed once instead of three times. Those details live in memory for the length of the run only; they are stored nowhere and are gone once the run ends — including when you end it with Leave wizard.
Accounts that still sign in per service are marked Old sign-in in the account list and offer One login for all services — in the list and in the account details, on the desktop as well as in the mobile app. One round trip, and afterwards every service shares the same sign-in. That is more than convenience: separate sign-ins could drift apart, leaving one service running while another one of the same account had quietly expired. For such accounts Sign in again now renews the whole account instead of a single service. The offer also stays when a shared sign-in already exists but does not cover every service of the account — because you left a tick off on the consent screen, say; Google cannot widen a consent it has already granted.
Dropbox
Plainva ships its own Dropbox app — no own app needed:
- In Cloud accounts → Connect account… pick the Dropbox tile (it carries only the Files service).
- Sign in with Dropbox… and confirm in the browser. Done (default folder
/Plainva). - Optional: once connected, pick the Cloud folder via Choose folder… straight from your Dropbox (subfolders included).
Optional: via Use your own app ID you can instead supply a self-registered app key. Detailed guide: OneDrive & Dropbox (BYO).
S3-compatible storage
For AWS S3, Cloudflare R2, Backblaze B2, MinIO, Wasabi, Hetzner and others — key-based, no browser sign-in at all. In Cloud accounts → Connect account… pick the Object storage (S3) tile and fill in the fields:
| Field | Meaning |
|---|---|
| Endpoint | Base URL of the S3 API, e.g. https://s3.eu-central-1.amazonaws.com, https://<account>.r2.cloudflarestorage.com or http://127.0.0.1:9000 for local MinIO |
| Bucket | Bucket name |
| Region | SigV4 region; us-east-1 works for most non-AWS stores, Cloudflare R2 uses auto |
| Access Key ID / Secret Access Key | An API key pair from the provider |
| Key Prefix (optional) | Subfolder inside the bucket for the vault; empty = bucket root |
| Path-style URLs | Recommended (MinIO, R2 and most compatibles); disable only for virtual-hosted AWS buckets |
You can pick the Key Prefix (the cloud folder) via Choose folder… straight from the bucket once connected.
After Connect, sync starts right away.
See also
- Sync Compatibility — which services work and how, including the desktop-client route
- FAQ & Troubleshooting — conflict files, offline behavior
Sync encryption (passphrase)
Replaced in P3: The controls described below are no longer used for vault content. Use Security & Sharing for the current encrypted-workspace setup. The passphrase controls that remain on this page protect only the optional settings/secrets sideband.
Plainva can encrypt what leaves your device for the sync server, while your local vault always stays plain Markdown that Obsidian can read.
Open Settings → Synchronisation → Sync passphrase & encryption:
- Set a passphrase. This creates an encryption key for the vault and shows a one-time recovery code — store it safely; it is the only way back in if you forget the passphrase. From then on the vault’s synced settings travel encrypted.
- Encrypt vault content (optional). The Encrypt button re-uploads every note to the sync server as ciphertext. Your local files stay plain Markdown, so a local vault is never at risk — try it on a throwaway vault first. When the upload has finished, use Finish migration to accept only ciphertext from then on.
- On another device, open the same synced vault. Plainva detects that the vault is encrypted and prompts for the passphrase (or the recovery code). After you unlock, the notes are decrypted and appear locally.
The unlocked key is cached on each device. Turn on Require passphrase at every start to re-enter it after each restart instead, and use Lock to remove the cached key from this device.
Accounts on all your devices is three steps. 1 · Settings and accounts: puts vault settings and your accounts (calendars, mailboxes, calendar selection) into a small file in the vault — as long as no passphrase is set up this needs none; once there is one, every device has to enter it before settings travel from there. 2 · Sync passphrase (optional): only needed if sign-ins should travel too; it additionally encrypts the settings from step 1. 3 · Carry sign-ins: additionally carries static IMAP and CalDAV passwords, encrypted, and can only be switched on once step 1 runs and the passphrase is unlocked — a password can only travel to an account the device already knows. Not carried: device-specific paths and OAuth sign-ins (Microsoft, Google); their tokens are device-bound, so the account appears on the new device and needs Sign in there once.
On the phone you find the same chain on the vault page — the same three steps and the same lock. Accounts arriving from another device are created there; you no longer enter them by hand. Take over from another device now fetches them at once instead of waiting for the next round.
If Plainva warns that an older version is still publishing retired account data, update Plainva on every device that uses this vault. The current device ignores old Google client credentials and keeps its own working sign-in. Do not confirm removal of the old remote data until every participating device has been updated. Plainva offers the button for that in the notice under Settings → Vault → Synchronisation → Diagnostics: Remove retired entries — the question it asks is exactly that confirmation.
Where that sign-in happens depends on the service: a mailbox shows a Sign in on this device button on its own row in the Email area, a calendar or files account does so in Cloud accounts. A Microsoft mailbox always leads to Cloud accounts, because its sign-in runs in the browser.
When you set the encryption up fresh, step 3 is on from the start — otherwise every further device would sit there without sign-ins for good. For a vault you already use, nothing changes quietly: Plainva asks once and remembers your answer.
If one account shows up as two cards, Plainva could not fetch the identity from the provider — and it must not guess. Open either card under Cloud accounts and use Merge to say it is the same account; Plainva shows what will be carried over before it does anything.
If Calendar lists two rows for the same calendar, Plainva reports it and does not fold them on its own: folding costs the calendar selection and the link to mirrored tasks. Check which row carries your selection and remove the other one.
An account you remove stays removed: the deletion travels through the settings sync to your other devices instead of coming back from there on the next round.
What travels, and what stays here
If Review duplicate accounts appears under Cloud accounts, Plainva deliberately does not guess from the name. Choose Keep this account on the correct card. The confirmation names the target, sources and affected services, and creates a backup on this device first. Cancel changes nothing. Merging removes only orphaned local accounts, caches and credentials — nothing is deleted at the provider.
| Travels with the vault | Stays on this device |
|---|---|
| Accounts — calendars, mailboxes, cloud accounts, bookmarks | Absolute paths — vault location, backup destination |
| Folders and templates — daily notes, template, inbox and attachments folders, task database | Sign-in tokens for Microsoft and Google |
| Calendar settings — meetings folder, default calendar | Which mailbox and folder you last had open |
| Mail settings — capture folder, remote images | This device’s starting arrangement for new vaults |
| Backup rules — snapshot interval, retention, archives | Static passwords — unless step 3 is on |
| Sync interval | |
| Bar arrangement (desktop) |
The phone carries slightly less: the arrangement of the four desktop bars stays on the computer — its own navigation bar does travel, and so does the meeting folder. Its own chain on the vault page shows what it carries, and below it both devices state what the sync actually did last — naming the settings that travelled, and on a receive the ones that changed. The message “Settings adopted from another device” appears at most once per session and only when something really changed — after that it stands in these lines. New in this revision, the phone also adopts the daily-note file format, the OKF type of new notes and your bookmarks — before, a vault with a different date format got a second daily note for the same day as soon as the phone touched it.
Diagnostics now separate last checked (local profile fields), last downloaded, last applied and last actually sent. “Sent” changes only after a successful cloud write; unchanged rounds therefore update the check and download, but not the sent time. Secret results appear separately as counts for imported, unchanged, rejected, stale, failed or waiting for an account. They contain only stable reason codes — no account id, password, token or raw error. A legacy-client notice means Plainva should be updated on every participating device; this device ignores the retired Google client data.
Errors and automatic retries
The sync error dialog preserves the exact failed attempt even when an automatic retry has already changed the live status. It shows when a retry is running or has recovered successfully. Reconnecting is recommended only for authentication errors; network, timeout, and provider failures retain their concrete cause and are retried automatically. The settings sync waits out temporary failures too: a timeout first appears as a quiet note with a counter and only turns into a red message after the third failure in a row — an expired sign-in, by contrast, straight away.
Names that differ only in spelling
Google Drive matches names case-insensitively when it searches, and Windows and macOS store Note.md and note.md in the same file. The same character can also be stored two ways: ü as one character, or as u with a trailing diaeresis. For that spelling Plainva now means the same file and keeps syncing normally, as long as there is only one match.
When two names differ in capitalization, however, they are two files. Plainva then changes and deletes nothing and shows the card Two spellings, one file with both names — on mobile on the vault page, on the desktop in the sync settings. Every other file keeps syncing. Rename one of the two notes and the card disappears by itself.