OutOfWater I somehow missed that FAQ page and that is impressively extensive.
Doing more checking into this app because now I'm even more curious and interested in it, but still very skeptical.
It's affiliated with PrivacyTools.io as well as funded by it which supposedly has been around for a decade. I've never heard of it, I'm more familiar with Privacy Guides. But I did checkout the Privacy Tools website and it seems like it could be another good resource possibly.
On Reddit in the Privacy Notes subreddit someone asked who the company was as they couldn't find any information. When I tried to find the same thing it led me down a maze of different websites but I couldn't piece any of them together in a way that made sense. Turns out this was done on purpose:
https://www.reddit.com/r/PrivacyNotes/comments/1w82w36/who_are_you/
LifetimeLabs
•
6d ago
I'll include this question from 4d ago from another thread here on reddit. For more context, so both get answered together.
I agree, would love to know more about who is behind this product. There's no "About" info on the website that I can find. I've been a long time Standard Notes user and could definitely see this replacing it. But who/what has created PrivacyNotes? What is support like? Is it a company or just one person? 🙂 How do I know I can actually trust this software, I'm not a developer who can read all the code and figure out what I'm looking at.
Since launch we get emails asking for our home address, office address, social media profiles, photos, and more than once what race/ethnicity we are. From people using a free and open-source privacy app. We built this so nobody gets to know where or who you are, and somehow the first thing some folks want is to know where we are. We're confused by those inqueries, but they keep happening. Parts of this reddit reply also went onto the about page we just put up, which is why it's long, and we discussed this already as a team earlier this week.
We're Lifetime Labs, small core team, German and Swiss, none of us in the US. Our two Swiss devs were building the app part-time, stuck in their old jobs, when they met the PrivacyTools.io owner (u/BurungHantu) in person during a business trip in Singapore by chance. He liked the idea and agreed on funding it fully, so they could go full-time and has been on it since, mostly usability, privacy consulting, marketing and the general direction / vision. Our reliable Freelancers are based in the Philippines for testing, UI work and social media marketing. All funding came from personal savings, no venture capital and no obligations.
How it got built: by hand, for a long time, before it even had a name. Encryption core, sync protocol, sign-in flow, all written by people next to day jobs through 2025. The crypto core is still done that way, nothing automated goes near it. By spring 2026 the foundation was solid and the problem changed: 17 languages to keep in sync, a help center to write, a UI wishlist longer than the team. Translations were the first thing we handed to AI tools, and the FAQ says so without hiding it. Then help articles. Then, under a fixed protocol, UI features and non-security bugs. Anything touching encryption, sync or sign-in still is only touched by skilled people. AI has been incredible helpful fixing non-critical bugs / rare edge cases, that would've taken us weeks otherwise to fix / pin down. It also helped us to implement testing scripts / protocols that improved the overall code quality and styles, to ensure that multiple developers are forced to use standards.
No ticket desk for support. A help center with close to 100 entries and GitHub issues. We'd rather fix something once in public than answer emails and cut our dev time short. Our GitHub repo is a great platform for this purpose. Our goal is that everything just works. If it's broken, it gets fixed, and every question from reddit or email ends up in the FAQ, translated, so it helps everyone instead of one person.
You asked how to trust software you can't read. Same way you trust a lock that's been on the market a while: enough people have tried to pick it. The clients are open source, so the people who can read code do, on GitHub, in the open. There's a verify script you can run without an account that shows your notes are encrypted before they leave your machine. Export any time. Pay once, no subscription holding your notes hostage.
Could we do it the other way? Sure. Put a Sam Altman on stage, nice guy, great keynote, "your data is safe with us." People relax on flowery words with nothing behind them. You can't verify a promise, and relaxed people stop checking. That's Big Tech's approach, and we're trying to get you out of it. We'd rather you never had to take our word for anything, including this post!
About page: it's up, lifetimelabs.dev/about, mostly because of this thread and the email influx. We weren't planning one. Everyone here is on 16-hour days right now and a page about ourselves was the last thing on the list, but the stream doesn't stop, so apparently now is the time. Anything missing on it? If it makes the software more trustworthy, it goes up. If it leads strangers to our doorstep, it doesn't, and it wouldn't make the encryption any better anyway.
Side note: the banned account posted one of our dev articles in a few subs at once. Reddit called it spam, fair enough. We stay in our own sub now.
Official accounts:
Subreddit: https://www.reddit.com/r/PrivacyNotes/
Company account: https://www.reddit.com/user/LifetimeLabs
Announcements: https://www.reddit.com/user/PrivacyNotesApp
I have to say, reading this and the about page they linked, this feels very at home with GrapheneOS's views and unwavering stance on security. But they are still so new and haven't established a track record. The pricing still feels too good to be true and I've been burned by lifetime plans before when it became unsustainable for the company to continue to honor.
If I wear to switch I would need to immiediately go with the lifetime plan + yearly storage upgrade because my notes are 1.5GB due to various attachments. They seem to be willing to explore the idea of self-hosting, but until then it doesn't make sense for me to switch no matter how tempting they are making it with their stance on privacy.