Are my notes safe even without full disk encryption?

@aquasp welcome to the forum.

I believe that Windows and Mac use their encrypted keychains to store the password. On Linux it is stored in the Joplin database.

Joplin does not store your note data encrypted on your disk, even with End-to-End Encryption (E2EE) enabled.

E2EE is not a method of encrypting the your data on your device. It is for when the data leaves your device and is no longer under your control. It is a method of encrypting your data as it moves between clients. These are the "Ends" in the name.

When you send data without E2EE to the sync server so that other clients can pull it down, it is encrypted by HTTPS. However when that data is stored on the sync server HTTPS no longer applies (the transfer is complete) and it is no longer encrypted. This means that whoever controls the sync server can technically access your note data.

Enabling E2EE means that the data is encrypted by your Joplin client as it leaves you. As it travels to the sync server it is encrypted by E2EE and HTTPS. But when it lands on the sync server it is still encrypted by E2EE. This means that whoever controls the sync server cannot access your note data as it stays encrypted until it is unencrypted by your other Joplin client(s).


EDIT: Ninja'd by @Daeraxa !!!