How Sync Works
memrynote sync is end-to-end encrypted. The server stores ciphertext and never sees note content.
What Sync Is For
- Mirror your vault across multiple devices
- Recover after a device loss (with your recovery phrase)
- Persist a backup off-device that you control via passphrase
Sync is opt-in and requires a paid sync plan. If you never sign in, nothing leaves your device. If you sign in without an active paid plan, the app stays fully local — signing in on a free or lapsed plan never triggers a sync error. memrynote checks your plan once at sign-in, then will not contact the sync server again to start sync while you stay unpaid, so a signed-in unpaid account behaves exactly like a signed-out one. Activating a plan starts sync immediately, with no restart.
An unpaid account reads as Local only (gray), never as a sync error: the status indicator and Settings -> Account show what sync would give you and a button to start a plan, not a failure you cannot retry. If the server declines sync while your plan already reads Active, the same card switches to Finishing your activation with a refresh button — there is nothing to buy twice.
Paid Sync Plans
| Plan | Encrypted storage | Synced vaults | File limit | Version history |
|---|---|---|---|---|
| Plus | 1 GB | 1 | 5 MB | 30 days |
| Pro | 10 GB | 10 | 200 MB | 365 days |
| Believer | 50 GB | Unlimited | 200 MB | 365 days |
All record sync, CRDT sync, WebSocket sync notifications, and encrypted blob uploads are gated by the active plan on the sync server. The server still stores only ciphertext.
Start a paid plan from Settings -> Account -> Billing or Upgrade to Pro in the sidebar account menu. memrynote opens the plan picker on memrynote.com/account/sync, carrying a checkout token so you land there without a separate web login; after Paddle completes payment, return to the app from the success page so the desktop can reconcile the transaction and refresh sync. If the webhook is still processing, Billing shows Activation pending with a refresh button and the billing support email.
Billing management uses Paddle's hosted customer portal from the same Billing section. Refunds and chargebacks are handled by emailing support for now; memrynote does not automate those flows inside the app.
Status Indicator
A small indicator in the app chrome shows the current state:
| Color | Meaning |
|---|---|
| Green | Idle, in sync |
| Blue | Syncing right now |
| Yellow | Paused, retrying with backoff, or temporary error |
| Gray | Offline, or local only (no active sync plan) |
| Red | Authentication or quota issue requiring action |
Click the indicator for details, recent activity, and a pause toggle.
Pause / Resume
Pause sync from the indicator menu when:
- Working offline intentionally
- Investigating a sync issue
- Conserving bandwidth on a slow connection
Resume sync to push and pull queued changes. Outgoing changes queue locally until paused → resumed.
Quitting while paused or offline does not lose those queued note edits. Everything you typed is already on disk, and memrynote records which notes still owe the server an update. The next time sync runs — on the next launch, or as soon as the network comes back — it pushes those notes' current state. A long offline editing session also stays cheap in memory: queued edits for a note are merged together rather than kept one per keystroke.
The same startup check covers tasks, projects, inbox items, saved filters, bookmarks, templates, home boards, custom icons, reminders, canvas folders and task history: a change that was saved on disk but never handed to sync, for example because the app quit at the wrong moment, is pushed on the next launch.
Deletions are kept the same way, and they are kept for every delete, not only the ones raised while sync is between runs. When you delete a note, task, or project, memrynote records the deletion on disk before anything else and keeps that record until a full check of your account confirms the server no longer holds the item. Until then the record does two jobs. It is re-pushed at the next sync run, so a delete raised while the app was quitting, while you switched vaults, or while it was signing back in still reaches the server. And it blocks the item from being written back to this device, so replaying your account history cannot put it back. Nothing is recorded on an install that does not sync at all (signed out, or on the free plan): there is no other device holding a copy.
A folder syncs in its own right, so a folder you create and leave empty — and any empty folders inside it — appears on your other devices without needing a note in it. Renaming or deleting a folder carries its whole subtree with it. Folders that already existed before this was fixed are picked up once, the next time sync starts.
A delete also wins against an edit made elsewhere at the same time. If you delete an item on one device while another device edits it without having seen the delete yet, the delete stands and the second device drops its copy on its next sync, rather than the edit bringing the item back.
What Gets Synced
| Item | Sync? |
|---|---|
| Notes (Yjs CRDT) | ✓ |
| Journal entries | ✓ |
| Tasks (field-level vector clocks) | ✓ |
| Projects | ✓ |
| Inbox items | ✓ |
| Templates (custom) | ✓ |
| Tags and properties | ✓ |
| Settings (selected, opt-in) | ✓ |
| Bookmarks and reminders | ✓ |
| Attachments (encrypted blobs) | ✓ |
| Agent chat conversations and terminal messages (paid accounts) | ✓ |
| Folders (including empty ones) and their icons | ✓ |
| Custom icons (uploaded images) | ✓ |
What Does Not Get Synced
- Open tabs, sidebar collapse, panel widths (UI state)
- Folder view configuration (named views, columns, formulas, summaries) — per device; applying a synced folder icon or changing a folder template preserves it
- Cached AI models and embedding vectors
- Voice transcription model files
- AI provider API keys
- In-progress agent streaming tokens
- Built-in templates (baked into the app version)
- Local logs
Frequency
Sync runs continuously while the app is open and online:
- Push fires within seconds of a local change
- Pull runs on a polling interval and after every push
- Backoff with jitter on repeated errors
There's no "sync now" button because there doesn't need to be — but you can pause and resume to force a fresh attempt.
End-to-End Encryption
Before any data leaves your device, it's encrypted with:
- XChaCha20-Poly1305 for content
- Ed25519 signatures over metadata + content hash
- Argon2id key derivation from your passphrase
The server stores the ciphertext, signatures, and metadata — but cannot decrypt anything. See Cryptography for the details.
Agent chat follows the same rule: conversation titles, message bodies, and message attachments stay encrypted on disk and in sync payloads. Sync only uploads completed agent messages, so a partially streaming response remains local until it reaches a terminal status. Attachments include structured references created by inline Agent mentions, including notes, tasks, journals, inbox items, and calendar events.
Where the Server Lives
- Edge API — Cloudflare Workers (Hono framework)
- Metadata — Cloudflare D1 (sync items, vector clocks, blob keys)
- Blobs — Cloudflare R2 (encrypted payloads)
You don't manage any of this directly — it's the sync backend behind your account.
Multi-Device
Linking another device requires a one-time approval from a currently-signed-in device. After linking, the new device decrypts the same vault using the per-device sealed key.
When Lists Refresh
Tasks and projects that arrive from another device appear as sync applies them — nothing to click. If a device has been sitting untouched for a long time, returning to its window refreshes those lists as well, so coming back to a machine you left alone is enough to see the other one's changes. Restarting the app is never required to pick up tasks or completed tasks from another device.
Which Account a Vault Syncs With
Every vault remembers the account it syncs with, inside its own folder. Signing out keeps your vaults on this computer, and they stay tied to your account. Nothing syncs them to someone else.
When you sign in or open a vault, memrynote checks that link before syncing:
| The open vault | What happens |
|---|---|
| Already syncs with your account | Syncs as usual |
| Empty | Joins your account and syncs |
| Has notes your account has not seen yet | Asks you once; nothing leaves the device before |
| Was synced by a different account | Stays on this computer; never syncs with yours |
| Could not be checked (offline) | Waits and checks again when the account answers |
When memrynote asks, you can:
- Add as a separate vault — the vault joins your account next to the vaults you already have. This uses a synced-vault slot on your plan.
- Merge into your account's vault — only offered when your account already has a vault. The notes on this computer are added to that vault.
- Keep on this device — the vault is not synced and memrynote does not ask again. Choose Sync this vault from the sync status popover to change your mind later.
Press Escape to decide later; the question comes back the next time the vault opens.
Deleting a Vault
Remove a vault you no longer want from Settings -> Vault or the sidebar vault switcher. memrynote offers two distinct actions:
| Action | Local list | Server copy | Files on disk |
|---|---|---|---|
| Remove from list | removed | kept | kept |
| Delete from account | removed | purged | kept |
Delete from account purges the vault's encrypted server copy — every synced record, CRDT update, and attachment blob — and frees the synced-vault slot it counted against your plan. This is how you clear a cloud-only vault that no longer has a local copy on any device.
Your files are never touched. A memrynote vault is an Obsidian-compatible folder you may also open in other tools, so deletion only removes the server copy and the app's reference to it — the folder and its notes stay exactly where they are on disk. Because nothing on disk is lost, the confirmation is a single dialog with no type-to-confirm step.
A few limits:
- The active vault can't be deleted — switch to another vault first.
- Deletion is not a permanent tombstone. If another signed-in device still holds the vault locally, it re-registers on its next launch and the vault reappears in your account. Delete it from the last device that holds a local copy — or remove those local copies first — to keep it gone.
Missing vault folders
If a vault's folder is no longer reachable on this computer, the vault switcher keeps the vault in the list, greyed out and marked Folder not found. The folder may have been deleted, or it may sit on an external drive or network share that is not connected. memrynote never forgets a vault on its own, so a vault on an unplugged drive can be opened again once the drive is back. Use Remove from list to forget a folder you deleted on purpose.
See Also
- Linking Another Device
- Recovery Key & Rotation
- Conflict & Health
- Sync Protocol (architecture deep-dive)