Skip to content
Lockpad

Self-hosted notes

Your notes live on your hardware,
and nowhere else.

Runs on a NAS, a mini PC, or the old laptop you already have. Open it, write, close the tab. Nothing leaves the building.

  • Your network only
  • Per-note locking
  • No account, ever

AGPL-3.0Zero telemetryRuns on Docker

The Lockpad interface: a sidebar of folders and tags beside a grid of note cards, each with a coloured edge, tags and a timestamp.

Not “privacy-first.” Just private.

Every other private note app still involves someone else’s server. Even when your notes are encrypted, you’re trusting their infrastructure to stay up, stay honest, and stay in business. Lockpad doesn’t have that server, and here’s what that means:

  • Zero outbound network requests, by default.

    No analytics, no telemetry, no CDN fonts or scripts, no calls to any Lockpad-owned server, because there isn’t one.

  • Locked notes are encrypted on your device, before they’re ever saved.

    The server, which is also your own hardware, only ever stores unreadable ciphertext for locked notes.

  • Nothing is open to the internet unless you open it.

    Out of the box it only listens on its own machine. Reach it privately over Tailscale, or through a proxy you already run, and neither needs port forwarding.

  • You own the backups, and you can prove it.

    A nightly backup script is included, and there’s no hidden cloud copy or vendor-side convenience backup.

What it can do

The three below are shown running, because they are easier to watch than to describe. Everything under them is the everyday work of a notes app, and all of it is there today.

Write a note in seconds

The composer sits at the bottom of every list. Type the thought, press Enter, and it is filed with the folder and tags of wherever you already are. Nothing opens, and there is nothing to save.

Link notes together

Connect related notes and see what links back to each one. Your notes form a web, not just a flat list.

Lock any note

Password-protect individual notes with real client-side encryption, the same encryption the privacy section above describes. AES-GCM-256, key derived with PBKDF2-SHA-256 at 600,000 iterations, in the browser.

  • Tags

    Tag a note as many ways as you think about it.

  • Colour-coded folders

    Give a folder a colour and the notes inside take it as their accent.

  • Full-text search

    Postgres full-text search over a generated tsvector column, not a substring match.

  • Archive and trash

    Soft delete. Nothing you remove is gone until you say so.

  • Autosave

    No save button. Every edit writes itself, and closing the tab sends the last one.

  • Export

    Any note leaves as Markdown or a PDF, whenever you want.

How it runs

Three pieces, all on your own machine, and one way in. The database sits at the centre with nothing published to the outside at all.

How Lockpad runs on your own hardwareEverything runs inside one boundary labelled “your own server”, meaning the machine you install Lockpad on: a static frontend, which talks to a backend, which talks to a Postgres database. The database sits at the innermost point and has no connection of any kind leaving the boundary. It is not published on a host port. Outside the boundary sit the devices you read and write on: a laptop, a phone and a tablet, drawn as peers of one another. One path leads in, and it forks into two choices: a Tailscale channel using “serve”, marked as recommended, or a reverse proxy you already run, such as a VPS or a tunnel. Neither choice forwards a port on your home router, which is what the note beside the public internet says. The internet is drawn outside the boundary and reaches nothing inside it directly. There is no cloud component anywhere in the diagram.the internetno port forwardingyour deviceslaptopphonetablettailscale serverecommendedor your own proxyVPS or tunnelyour own serverfrontendVite + Reactstatic filesbackendFastify + PrismaREST/JSONpostgresno host portnothing leavesNo Lockpad server. No cloud database. No third party in this diagram.Every box above sits on a machine you own.

Add it to your home screen. It opens without browser chrome. No App Store, no review process.

Safari's share sheet open on Lockpad, with Add to Home Screen in the list.
An iPhone home screen with the Lockpad icon among the other apps, indistinguishable from an installed one.
Lockpad open on the phone, filling the screen with no address bar or browser chrome around it.
One install on a phone, left to right: the share sheet, the icon on the home screen, and the app running.

Common questions

Is Lockpad free?
Yes, and there is no paid tier behind it. It is AGPL-3.0, so you can read the source and change it.
Do I have to self-host it?
Yes. It runs on Docker, on hardware you already own, and there is no hosted version to sign up for right now.
Can you see my notes?
No. Your notes never reach a machine I control, and locked notes are encrypted on your device before your own database sees them.
What happens if you stop working on it?
Your notes are already in a Postgres database on your own hardware, and it runs whether or not I do. The code is AGPL-3.0, so anyone with a copy can pick it up.
How is this different from the notes app I already use?
Yours probably keeps your notes on someone else’s server, which is what makes it quick to start with. Lockpad asks you to set it up once instead, and after that nothing about your notes involves anyone else.

Why I built this

Hey, I’m Colbys

A Senior Product Designer who cares about people, about good technology, and about privacy holding the two together.

For years, Google Keep held every note I wrote, until I wondered why I was willingly handing over more of my personal data than I actually needed to.

Then LLMs came along. I started using them heavily at work, and before long I was building small tools for myself too: a personal finance tracker, a calculator for buying versus renting a home, and a few other things I never expected to make. Lockpad was one of them, my own replacement for Google Keep, running entirely on my NAS (Network Attached Storage).

I’ve been using it every day since, and enjoying it. So one day I asked myself: what if someone else could get some use out of this too? A month later, here we are.

Colbys Dovi

If you like Lockpad

This is a free, self-hosted, one-person project, with no subscription and no paywall, ever. If you’d like to help keep it going, a coffee is always appreciated.

The other way to help costs nothing. I built this while learning as I went, so an idea or a pull request on GitHub(opens in a new tab) is worth as much to me as a coffee, and it would be fun to make a side project multiplayer.