Owldo — Feature
Privacy shouldn't be an afterthought. Because Owldo is built on a local-first SQLite architecture, we can offer true End-to-End Encryption (E2EE). Your data is locked on your device before it ever syncs to the cloud.

The Owldo security settings page showing End-to-End Encryption toggled 'On' and a prompt to backup the recovery key.
desktop · 16/10 · /public/screenshots/e2ee-hero.png
When you enable E2EE, Owldo uses standard encryption algorithms to encrypt your entire local database. The syncing engine (powered by ElectricSQL) only transmits and stores the encrypted blob. Because the decryption key never leaves your devices, it is mathematically impossible for anyone—including our engineers—to read your notes.
Whether you are a journalist protecting sources, a founder drafting confidential roadmaps, or just someone keeping a private journal, E2EE ensures your workspace remains a safe haven. It combines the seamless convenience of cloud syncing with the absolute privacy of an offline vault.
The mobile app displaying a subtle 'Encrypted' padlock icon in the bottom corner of the sidebar, confirming the vault is secured.
mobile · 9/16 · /public/screenshots/e2ee-lock.png
With true E2EE, there is no "Forgot Password" backdoor for your data. When you set up encryption, Owldo generates a master recovery key. Keep this key safe in a password manager. If you lose all your devices and the recovery key, the synced data will remain permanently locked. That is the price of true security.
Yes. When E2EE is enabled, your SQLite database is encrypted locally on your device before it ever touches our sync servers.
No. With End-to-End Encryption enabled, we do not have the key to decrypt your data. Even the synced copy on our servers is completely unreadable to us.
E2EE is optional. It is perfect for journals, sensitive project notes, or protecting journalistic sources. You control the encryption key.