Almost every notes app says your notes are encrypted. Almost none of them mean what people assume they mean.
There are two very different claims hiding behind the same word, and the gap between them is the entire question of who can read your notes.
The two kinds
Encryption at rest. Your notes are stored encrypted on the company's servers, with keys the company holds. This protects against a stolen hard drive or a breached data centre. It does not protect against the company itself, an employee with access, a subpoena, or a compromise of the systems that hold the keys. This is what most notes apps mean, and it is a genuine security measure — just not a privacy one.
End-to-end encryption (E2EE). Notes are encrypted on your device with a key derived from something only you have, usually your password. The server stores ciphertext it cannot decrypt. Nobody at the company can read your notes, even if compelled to. This is what most people picture when they hear "encrypted".
The practical test is one question: if you forget your password, can support recover your notes? If yes, they can read them. That is not a criticism of the company; it is arithmetic. Recovery requires access to the key.
What E2EE actually protects against
Worth being specific, because the threat model determines whether you should care.
It protects against: a server-side breach exposing your content, a rogue or curious employee, an acquisition changing who runs the company, a government request to the provider, and the company deciding to train models on your notes.
It does not protect against: malware on your own device, someone who knows your unlock code, a weak password, a compromised backup, or anything you copy out into another app. E2EE secures the pipe and the store. It cannot secure the endpoints, and the endpoint is usually the weak point — the EFF's guidance on this is worth reading if you are making decisions based on it.
The trade-offs are real
E2EE is not free, and vendors who offer it are making choices you should understand.
Search gets harder. The server cannot index text it cannot read, so search happens on-device, over notes that must be downloaded and decrypted first. This is why E2EE apps often have slower or more limited search, especially on the web, and why "search across 10,000 notes instantly" and "we cannot read your notes" are in tension.
Server-side features mostly disappear. Web clipping, link previews, collaborative editing, server-side AI over your notes, full-text search on a shared web app — all of these normally require the server to see plaintext. Some can be rebuilt on-device; several cannot be rebuilt well.
Recovery is on you. Lose the password and the notes are gone. This is the honest cost of the guarantee, and it is the single most common way people lose an encrypted archive. Some services offer a recovery key, which is a long random string you must store somewhere safe — a different problem, not a solved one.
Sharing is awkward. Sharing an E2EE note with someone requires key exchange, which is why most such apps either do not offer sharing or offer a limited version.
AI features become a fork in the road. Any assistant that processes your notes on a server needs them decrypted at some point. An app can do this honestly — decrypt on device, process locally — or it can quietly weaken the guarantee. Ask which, because "encrypted and AI-powered in the cloud" usually means one of the two claims is doing less than it sounds.
Where the mainstream apps stand
Positions change, so verify rather than trusting a summary, but the broad picture:
Apple Notes encrypts in transit and at rest by default, with keys Apple holds. Individual notes can be locked with a password, and those are end-to-end encrypted. Turning on Advanced Data Protection for iCloud extends end-to-end encryption to most iCloud data, including Notes — it is off by default and requires setting up recovery. That last detail is the one people miss.
Standard Notes is end-to-end encrypted by default and has published audits; that is the product, and the feature set is deliberately narrow as a result.
Obsidian stores plain markdown files locally, which is a different guarantee: nothing is on anyone's server unless you put it there. Obsidian Sync offers end-to-end encryption; a generic cloud folder does not.
Notion, Evernote, Google Keep and OneNote encrypt in transit and at rest, and the provider can access content. These are not privacy-first products, and their feature sets are the reason.
For a fuller comparison see the best private notes app and plain text notes.
Encryption is not the only privacy question
Two things get conflated and should not be.
Encryption decides who can read the content. Data practices decide what is collected around it: metadata, note counts, timestamps, device identifiers, analytics, and what the terms permit the company to do. An app can be end-to-end encrypted and still report a great deal about your usage.
Portability is the third leg. An encrypted archive you cannot export is still a trap — see export your notes. Privacy that ends when you leave is partial privacy.
How much should you care
Honestly: it depends on what you write, and most people underestimate it in one specific way.
Notes are not documents. They are the unfiltered version — the half-formed complaint about a colleague, the health worry, the thing you have not told anyone, the notes about people in your life. Nobody chooses that content deliberately; it accumulates because a notes app is where thinking goes. Five years of it is a more intimate record than your email.
That is the argument for defaulting to a strong guarantee even when you cannot name a threat. You are not protecting the note you are writing today. You are protecting a decade of them against a future you cannot see, including the company changing hands.
It is also why Clair Mind is built private-first, with notes staying yours rather than becoming training data. The question worth asking of any notes app, including ours, is the same one: if you forgot your password, could someone else get your notes back? Read the answer carefully.
More in syncing notes across devices, how to back up your notes, and personal knowledge management.