
End-to-end encrypted notes: what the server can and can't see
What is end-to-end encryption? A plain-English guide for notes: who holds the key, what a server stores, and what it can and can't see about you.
Cappa Blog
Clear, careful explanations of how encryption protects what you write, what a server can and cannot see, and how to write and organize notes that stay useful for years.


What is end-to-end encryption? A plain-English guide for notes: who holds the key, what a server stores, and what it can and can't see about you.

Markdown for beginners: what it is, why plain-text notes last, every basic element with examples, a cheat sheet to bookmark and the mistakes to avoid.
What encryption protects, what it cannot, and what a server learns about you.

How long should a password be? For a master password, aim for 16+ random characters or six random words. Here is why, with honest crack-time estimates.

Forgot master password? With end-to-end encryption no one can reset it. How recovery codes work, how Cappa handles recovery and where to keep your code.

What does end-to-end encryption not protect against? Malware, phishing, unlocked devices, bad code and metadata. A plain threat model and checklist.

Is Notion private? Can Google Keep, Apple Notes or Evernote read your notes? A fair, sourced comparison of who holds the key in 10 notes apps.

Can AI crack passwords? A reality check on PassGAN and the 51% headline, what AI really changes for attackers (phishing, voice clones) and how to stay safe.

What are passkeys and how do they work? A plain guide to passkeys vs passwords, phishing resistance, syncing, losing your phone and what passkeys can't replace.
The building blocks behind private apps, explained without the math.

What is Argon2? A plain-language guide to password hashing, salt and memory-hard key derivation, how it compares with bcrypt, and how Cappa uses it.

AES-256 encryption explained without math: what the 256 means, how GCM's tamper seal and nonce work, who holds the key, and whether it is quantum safe.

Can quantum computers crack passwords? Shor breaks RSA and elliptic curves, Grover barely dents AES-256 and long passwords. What changes, when, and what to do.

What is post-quantum cryptography? ML-KEM, ML-DSA and hybrid key exchange explained simply, where you already use them, and the 2029 to 2035 migration timeline.
Write faster, format less and organize notes you will actually find again.

What is local-first software? How offline-first notes work, what happens in a sync conflict, and the honest limits of keeping notes on your own device.

How to make a Markdown table, task list, footnote, math formula and Mermaid diagram, with copyable examples and which apps support each feature.

How to organize notes you can find again: when to use folders, tags or links, a starter tag set, naming rules and a simple 10-minute weekly review.

Zettelkasten vs PARA: how the Zettelkasten method and the PARA method work, what each is good for, common mistakes, and a simple way to combine both.