Alien Notes

Android
Android

Alien Notes is a local, encrypted notes and checklist app. It runs fully offline — no cloud,
no server, no account, no telemetry. The app requests no INTERNET permission — only the two
normal permissions for the fingerprint sensor (USE_BIOMETRIC, USE_FINGERPRINT up to Android 8.1).
Your notes never leave the device in plaintext. Sister app of Alien Pass and Sachwert-Tresor.

Features:

  • Notes (free text, up to 100,000 characters) and checklists (up to 200 entries with boxes, "done to the bottom",
    "clear ticks"); switch a note between the two — lines become entries and back, with a warning whenever something would be shortened
  • No save button: the app saves as you type (after 1.5 s) and when you leave the note — encrypted, the whole file every time;
    the title may stay empty, the first line then serves as the title
  • Markdown preview per note (off by default): headings, bold, italic, lists, boxes, code, rules — a small own subset, no third-party
    renderer, no HTML, links stay plain text; a cheat sheet in the editor shows "type this → looks like this"
  • Categories like folders (filter chips, suggestions, rename a category with all its notes), favourites, pinned notes, search across title,
    text, checklist entries and category, "insert date", an "Open" chip for checklists with unfinished entries
  • Moving from Standard Notes (since 1.1): reads a decrypted Standard Notes backup — the downloaded ZIP directly or the text file inside — and
    turns plain, Markdown, code, rich-text and Super notes into notes, checklists into checklists, the first tag into the category; 2FA
    (Authenticator) entries, spreadsheets and files are never imported; a second import creates no duplicates
  • Select several notes at once (since 1.1): trash (with one "Undo" for all, at most 200 at once), set a category or the favourite mark
  • "Undo" after deleting (six seconds), "no preview" per note (the list shows only the title), three font sizes, and every confirmation is
    an in-app dialog — the Android system dialog does not inherit the screenshot protection
  • Copy puts the whole note into the clipboard; auto-clear after 15/30/60 s (default 30 s, can be switched off) and on lock; copied content
    is flagged sensitive so the Android 13+ system preview hides it. With "Lock in background: immediately" the copied note stays until the
    chosen time runs out so it can still be pasted into another app (since 1.3)
  • Locking, more relaxed than a password manager: by default no lock after inactivity and in the background only after 30 minutes
    (both adjustable up to "never" / "immediately"); "Lock now" clears the key and everything on screen at once; the file is always encrypted.
    With "immediately" the Android app also locks while the file picker is open — unlock within five minutes and the import continues with the chosen file (since 1.2)
  • Trash: deleted notes stay restorable for 30 days, up to 200 at a time; shows only title, type and date, never the content;
    device-local — a deletion travels to your other devices when merging, the content does not
  • Encrypted .notes backup and merge between devices (newer change wins, deletions carried for a year), also between phone and Linux desktop
  • Optional Aegis hurdle: an extra TOTP code on unlock (key or otpauth link to copy, no QR; honestly documented as a hurdle, not a second factor)
  • Optional fingerprint unlock (Android keystore, passphrase required after every restart unless "also after a restart" is ticked, off by
    default) and optional quick unlock by PIN on the Linux desktop — both taken over from Alien Pass and documented there
  • Screenshots and app-switcher preview blocked by default (FLAG_SECURE), can be switched off in Settings — notes are not always secret;
    locked and during setup the protection is always on
  • Argon2id key derivation (32/64/128 MiB, self-benchmarked at setup) + AES-256-GCM via WebCrypto; own file format AINV1 with its
    own keys — Alien Pass rejects a notes file and vice versa
  • Notes file in the private app folder, written atomically (temp file, fsync, rename) — never a half-written file; 20 MB file limit
    enforced on save as well, an oversized file still opens so you can tidy up
  • Linux desktop edition (Flatpak without network permission and without file access, GPG-signed checksum) — see the Codeberg release
  • No INTERNET permission; only USE_BIOMETRIC and USE_FINGERPRINT (up to Android 8.1) for the fingerprint sensor
    (plus the AndroidX-generated signature permission that grants nothing),
    allowBackup=false + data extraction rules (no cloud, adb or D2D backup),
    WebView excluded from the Android autofill framework (a third-party autofill service never sees the passphrase fields, since 1.4)
  • Strict CSP: connect-src 'none', no inline script; Markdown rendered only via createElement/textContent; bundled Argon2 (hash-wasm)
    hash-checked in the build; internal security audit of the new surface before release (no independent audit)
  • German / English, offline in-app manual, open source (MIT)

Signing certificate SHA-256 (verify with AppVerifier), identical for every version:
F3:68:F9:0B:F8:DF:8C:55:BB:6C:28:6D:32:25:BA:8A:F4:45:22:7B:A6:9B:36:00:DF:BB:F6:A1:44:09:BA:7C
apksigner (no separators): f368f90bf8df8c55bb6c286d3225ba8af445227ba69b3600dfbbf6a14409ba7c