# Are my notes safe even without full disk encryption?

**URL:** <https://discourse.joplinapp.org/t/are-my-notes-safe-even-without-full-disk-encryption/38064>\
**Category:** Support\
**Created:** [11 May 2024 14:00 UTC](https://discourse.joplinapp.org/t/are-my-notes-safe-even-without-full-disk-encryption/38064 "2024-05-11T14:00:27Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![dpoulton](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/dpoulton/32/29723_2.png) [@dpoulton](https://discourse.joplinapp.org/u/dpoulton)\
**Post date:** [11 May 2024 14:17 UTC](https://discourse.joplinapp.org/t/are-my-notes-safe-even-without-full-disk-encryption/38064/3 "2024-05-11T14:17:45Z")

</div>

@aquasp welcome to the forum.

> [@aquasp](#):
>
> since it does not requires a password to unlock my notes, looks like it caches the master password somewhere correct?

I believe that Windows and Mac use their encrypted keychains to store the password. On Linux it is stored in the Joplin database.

> [@aquasp](#):
>
> Let's say that I have a laptop and this laptop does NOT have full disk encryption. If my laptop is stolen, are my notes compromised?

Joplin does not store your note data encrypted on your disk, even with End-to-End Encryption (E2EE) enabled.

E2EE **is not a method of encrypting the your data on your device**. It is for when the data _leaves_ your device and is no longer under your control. It is a method of encrypting your data as it moves between clients. These are the "Ends" in the name.

When you send data without E2EE to the sync server so that other clients can pull it down, it is encrypted by HTTPS. However when that data is stored on the sync server HTTPS no longer applies (the transfer is complete) and it is no longer encrypted. This means that whoever controls the sync server can technically access your note data.

Enabling E2EE means that the data is encrypted by your Joplin client as it leaves you. As it travels to the sync server it is encrypted by E2EE _and_ HTTPS. But when it lands on the sync server **it is still encrypted by E2EE**. This means that whoever controls the sync server **cannot** access your note data as it stays encrypted until it is unencrypted by your other Joplin client(s).

* * *

**EDIT:** Ninja'd by @Daeraxa !!!

---

_[View the full topic](https://discourse.joplinapp.org/t/are-my-notes-safe-even-without-full-disk-encryption/38064)._
