All posts
Comparison38 min read

Encrypted Google Keep Alternative: Private Notes That Actually Respect Your Data (2026)

Google Keep encrypts your notes but Google holds the keys and can read them. Here is Filarr, a local-first, zero-knowledge encrypted Google Keep alternative, compared honestly.

MB

Mathis Belouar-Pruvot

Quick answer: Google Keep is a fast, free note app, but every note you write lives on Google's servers in a form Google can read. It encrypts your notes at rest and in transit, yet Google holds the keys, so there is no end-to-end or zero-knowledge protection. If you want the same instant, jot-it-down feeling but with your notes stored encrypted on your own machine, where nobody, not even the company that made the app, can read them, Filarr is the closest honest alternative. Filarr is a free, local-first workspace that encrypts every note and file with AES-256-GCM on your disk, keeps working fully offline, and only syncs to the cloud if you ask it to. Keep wins on speed, voice capture and deep Google integration. Filarr wins on ownership, real encryption, and keeping your notes and your files in one place.

The problem nobody notices until it is too late

Most people do not choose Google Keep. They fall into it. It is already there when you open a new Android phone, it is one click away in Gmail, and it syncs across every screen you own without you configuring a single thing. You start with a grocery list, then a phone number, then the address of a friend, then a rough draft of a resignation letter, then the recovery codes for another account because you were in a hurry. Over a few years, a tool you never really decided to trust becomes the quiet archive of your life. And the whole time, a fact sits in the background that almost nobody stops to examine: everything you typed is readable by Google. Not readable by a hacker who breaks in someday, readable by design, right now, by the company that runs the servers.

I am not saying that to scare you. I built an encrypted workspace, so of course I have an axe to grind, and I will be honest about that throughout this piece. But the point stands independent of my product. When you write a note in Keep, that note is encrypted on Google's disks and encrypted while it travels over the network, and both of those things are genuinely good. What they are not is end-to-end encryption. Google holds the keys. That means the content of your notes is available to Google's systems in cleartext for indexing, for features, for legal requests, and for whatever a future policy allows. There is no version of Keep where you hold the key and Google cannot look. That is not a bug. It is the architecture.

For a grocery list, who cares. For the address of an abuse survivor, the seed phrase of a crypto wallet, a list of medications, a client's confidential numbers, or the first draft of something you are not ready to show the world, the difference between "encrypted, but the provider can read it" and "encrypted, and only you can read it" is the entire ballgame. Most people never think about which of their notes fall into the second category until the day one of them leaks, and by then the note has been sitting in cleartext on someone else's computer for years.

This article is a careful, honest comparison between Google Keep and Filarr, the app I build. I am going to spend real time on where Keep is genuinely better, because it is, and a comparison where my own product wins every row would be worthless to you and insulting to your intelligence. But I am also going to show you exactly what changes when your notes are encrypted with a key that never leaves your device, and why, for a growing number of people in 2026, that trade is worth making.

Two products, two very different origin stories

Google Keep launched in March 2013 as Google's answer to Evernote and the sticky-note apps that were popular at the time. It was built the way Google builds most consumer products: server-first, cloud-native, tied tightly to your Google account, and optimized for the frictionless capture that Google does better than almost anyone. Over the years it gained labels, color coding, collaborators, image notes with optical character recognition so you could search text inside a photo, voice notes with automatic transcription, and reminders. It became a default fixture of the Android and Workspace ecosystems. It is genuinely good software, made by people who are very good at making software feel instant.

But Keep's history also tells you something about how Google treats it. Reminders, one of its signature features, began migrating to Google Tasks across late 2025 and rolled out more widely in January 2026. In that migration, Keep stopped sending reminder notifications itself and handed that job to Tasks and Calendar, and location-based reminders (the "remind me when I get home" feature) were dropped entirely because Tasks does not support them. If your reminder titles were long, they got truncated in the move. This is the pattern of a product that Google maintains but does not deeply invest in, the kind of app that lives on the edge of the graveyard that Google is famous for. That is not a reason to panic, but it is a reason to think twice before making Keep the permanent home of anything you cannot afford to lose or migrate.

Filarr's story is the opposite in almost every way. I did not build it inside a large company optimizing for engagement metrics. I built it because I wanted one app for my files, my notes, and the graph that connects them, all encrypted by default, all on my own machine, with no account required to start. Nothing like that existed the way I wanted it, so I wrote it. If you want the long version of that story, I wrote it up in why I built Filarr, but the short version is that the encryption is not a feature I bolted on for marketing. It is the reason the app exists. Filarr is an Electron and React desktop application for Windows, macOS and Linux, it is open source under the Business Source License 1.1, it passed a thousand users in 2026, and a mobile app is in final testing. It is young. It has fewer features than a product with more than a decade of Google engineering behind it. I will be the first to say so.

The fracture that everything else grows from

Underneath the feature checklists, Keep and Filarr disagree about one foundational thing: where your data lives and who can read it. Keep is cloud-first. Your notes are born on Google's servers, and your devices are windows into that server-side truth. The app on your phone is a cache and a keyboard; the real note lives in a Google datacenter, in a form Google can read, indexed and processed to make the product work. Offline access exists, but it is a convenience layered on top of a fundamentally cloud-based model. Take Google's servers away and Keep, over time, is a dead app.

Filarr is local-first. Your notes and files are born on your disk, encrypted, and they live there whether or not any server exists. The cloud, in Filarr's model, is optional and it only ever sees encrypted blobs it cannot read. If Filarr the company vanished tomorrow, the app on your machine keeps working, because there is no server it needs to phone home to for your data to exist. This is not a marketing distinction, it is an architectural one, and if you want the full framing of what local-first actually means, I laid out the seven properties in this piece on local-first software. The short version: in a cloud-first app you are a guest in someone else's house, and in a local-first app you own the house and can invite the cloud in as a helper if you want.

Let me make this concrete with a scenario, because philosophy is cheap. Imagine you keep a running note of everything related to a messy situation: a dispute with a landlord, a medical diagnosis you are researching, a business idea you have not filed paperwork for yet. In Keep, that note is legible to Google's systems every second it exists. If Google receives a valid legal request, the content can be produced, because Google has the keys. If a future feature decides to train on or scan note content, your note is in scope by default unless you opt out, if opting out is even offered. If Google's account systems ever lock you out, mistakenly or not, the note is gone with the account. In Filarr, that same note is a file on your disk that is encrypted with a key derived from your password. Google is not in the picture at all. A legal request to Filarr's cloud, if you even enabled sync, produces an opaque encrypted blob that reveals nothing without your password. That is the whole difference, dramatized. The tool you use is quietly deciding, every day, who else gets to read your mind.

What each tool is actually built to do

Google Keep is built for capture. It is the best app I know for getting a fleeting thought out of your head and into a durable place in under two seconds. You tap the widget, you speak or type, and it is saved and synced everywhere before you have finished the thought. The voice notes transcribe themselves. Photos become searchable because of the OCR. Checklists are frictionless. Sharing a list with your partner takes one tap and updates live. If your entire relationship with notes is "short things I need to remember and occasionally share," Keep is close to perfect, and honestly nothing I have built beats it at that specific job. Capture speed is Google's home turf.

Filarr is built for keeping. Not just jotting, but holding, organizing and connecting the things that accumulate over years. Notes are written in a rich editor with tables, code blocks, task lists and math, but the real point is that notes do not live alone. A note can link to a PDF, a PDF can be searched from inside the app, a file can be tagged, and everything you create shows up in a graph view that lets you see how your knowledge connects, the same way a knowledge base or a personal wiki does. And crucially, Filarr treats your files as first-class citizens alongside your notes, with support for 51 or more file formats, so the invoice, the contract, the photo and the note about them all live in one encrypted workspace instead of scattered across Keep, Drive, Downloads and three other apps. If you have ever felt the specific frustration of knowing you saved something but not knowing which of five apps it is in, that is the problem Filarr is designed to end, and I wrote a whole piece on organizing your digital life in one private workspace if that resonates.

So the honest framing is not "Filarr is better than Keep." It is "they are built for different halves of the same problem." Keep is a capture tool that happens to store notes. Filarr is a storage and knowledge tool that happens to include a fast note editor. If you want both instant capture and long-term private ownership, the realistic move for many people is to use Keep for throwaway captures and Filarr for anything you actually want to keep and protect, and I will come back to that hybrid approach at the end.

The encryption, all the way down

Here is where the two apps stop being comparable and start being opposites, so let me slow down and be precise, because vague security claims are how people get misled. Google Keep uses encryption at rest and in transit. At rest means your notes are stored on encrypted disks in Google's datacenters. In transit means the connection between your device and Google is protected by TLS so a network eavesdropper cannot read it. Both of these are real and both matter. What neither of them provides is protection from Google itself. Google generates and holds the encryption keys, which means the plaintext of your notes is available to Google's own systems. There is no zero-knowledge mode for Keep. It is worth noting that Google Workspace does offer client-side encryption, where the customer holds the keys, for some products like Drive and Docs, but Keep is not one of them, and even that is an enterprise feature, not something a normal consumer account gets. If the difference between these terms is fuzzy, I wrote a plain-language breakdown of end-to-end versus zero-knowledge encryption that untangles it.

Filarr takes the opposite stance and I want to be exact about the mechanism, because "we use AES-256" is a claim that means very little without the details. Every file and note in Filarr is encrypted with AES-256-GCM, an authenticated cipher that both scrambles your data and detects if a single byte has been tampered with. Each file gets its own File Encryption Key, so cracking or leaking one key exposes exactly one file and nothing else. Those per-file keys are themselves wrapped by a Key Encryption Key that is derived from your password, never stored in the clear. The password is stretched into a key using PBKDF2-SHA512 with 600,000 iterations, which follows the OWASP 2024 guidance and makes brute-forcing your password enormously expensive, with Argon2id available as an even stronger option. If you want to understand why the two-layer key design matters so much, I broke it down in KEK and FEK explained, and there is a dedicated piece on what AES-256-GCM actually is. The key point is that the key lives with you, derived from a secret only you know, and Filarr's servers never see it in a usable form.

Abstract crypto specs are boring until you map them to things that actually happen, so let me walk four real threat models through both apps. First, the malicious or breached server. Suppose Google, or Filarr's cloud provider, is compromised by an attacker who dumps everything on the servers. With Keep, that dump contains your readable notes, because the server can read them, so the server-side attacker can too. With Filarr, if you even enabled cloud sync, the dump contains encrypted blobs that are useless without your password, which was never on the server. I wrote about exactly this asymmetry in what changes when your data leaks: one architecture leaks your documents, the other leaks noise.

Second, the stolen or lost laptop. Someone takes your machine. With Keep, if your browser session is logged in, they open a tab and read everything, and even if not, your notes are safe only because they are on Google's server behind your account password, not because of anything local. With Filarr, your notes are encrypted files on that disk, and without your Filarr password they are unreadable ciphertext, independent of your operating system login. Third, the weak password. This is the uncomfortable one, and I will not pretend encryption is magic. If your password is "password123," no scheme saves you, but Filarr's 600,000-iteration key derivation makes each guess costly enough that a decent passphrase is genuinely hard to crack offline, whereas with Keep the strength of your Google account password protects access to the account, not the readability of the underlying data by Google. Fourth, the legal request or subpoena. This is where the architectures diverge most sharply. Google can be compelled to produce the content of your Keep notes because it has the keys and the plaintext. Filarr, for data you kept local, has nothing to produce because it never had your data, and for data you synced, can produce only encrypted blobs it cannot decrypt. That is what zero-knowledge means in practice, and if you want the full mental model, this explainer on zero-knowledge encryption lays it out with diagrams.

How syncing and multiple devices really work

With Keep, sync is invisible and excellent, and I mean that as a compliment. Because your notes live on Google's servers as the source of truth, every device simply reflects that truth. You write on your phone, it is on your laptop before you have picked it up. There is no configuration, no conflict resolution you ever have to think about, no server you have to trust because you already trusted Google with the plaintext. The cost of that seamlessness is precisely the thing this article keeps circling: the server can read everything, because the server has to hold the readable truth for this model to work so smoothly.

Filarr's sync is built to give you multi-device convenience without giving up the keys, which is a genuinely harder engineering problem. The way it works is that files are encrypted on your device first, and only the already-encrypted blobs are uploaded. The backend, which runs on Cloudflare R2 for storage, stores those opaque blobs and literally cannot read them, because your key never reaches the server in cleartext. The code that handles this is explicit about being zero-knowledge, and I wrote a look inside that exact code path in how Filarr's optional cloud sync stays zero-knowledge. If you would rather not use Filarr's cloud at all, you can bring your own S3-compatible bucket, so even the storage provider is your choice. And if you never turn sync on, Filarr is 100 percent offline, with nothing leaving your machine ever.

The consequences of these two models show up most clearly at the edges, when things go wrong. What happens offline? Both apps work offline for a while, but Keep is a cache waiting to reconnect, whereas Filarr is fully functional with no expectation of a server. What happens if the server goes down? Keep degrades toward uselessness the longer the outage lasts, because the truth is on the server. Filarr does not notice, because the truth is on your disk, and sync simply resumes when the server returns. What happens if you stop paying, or the company folds? With Keep, your access is tied to your Google account, and if that account is ever suspended, you can lose everything at once. With Filarr, if you cancel sync or the company disappears, your local, decryptable data is still sitting right there on your machine, fully usable, because the app does not need a living server to open your own files. That last point is, to me, the deepest practical argument for local-first: your data should not have a heartbeat monitor wired to someone else's business model.

Recovery, and the day you forget your password

Every honest encryption conversation has to include the failure mode, because strong encryption cuts both ways, and anyone who glosses over this is selling you something. With Google Keep, recovery is Google's recovery. If you forget your Google password, you go through Google's account recovery flow, with its recovery email, phone number, and increasingly its device-based prompts, and because Google holds your keys, Google can restore your access to your readable notes. This is convenient and it is a real advantage for people who lose passwords often. The flip side is the mirror image of the same fact: because Google can restore your access to readable data, so can anyone who successfully impersonates you to Google's recovery system, and so can Google itself. Convenience and exposure are the same coin.

Filarr's recovery is designed around the constraint that Filarr genuinely cannot read your data, which means Filarr also genuinely cannot reset your password and magically decrypt your notes, because if it could, the encryption would be theater. Instead, when you set up encryption, Filarr gives you a 24-word BIP-39 recovery phrase, the same standard used by serious cryptocurrency wallets. That phrase is your lifeline. Write it down, store it somewhere safe and offline, and you can recover access even if you forget your password. Lose both your password and your recovery phrase, and your data is unrecoverable, by anyone, forever. I want to be brutally clear about that, because it is the price of real encryption and you should walk in with your eyes open. The upside is enormous: there is no recovery backdoor that an attacker, a rogue employee, or a government can walk through, because there is no backdoor at all. The downside is that the responsibility is now yours, and Filarr cannot save you from losing the keys to your own house.

The right way to think about this is not "which app is safer" but "which failure mode do you prefer." Do you want the failure mode where a company can always get you back in, which also means a company can always be compelled or tricked into getting someone else in? Or do you want the failure mode where only you can get back in, which means you must not lose your recovery phrase? Neither answer is wrong. They are different bets about who you trust more, a large company's security team or your own ability to safeguard a piece of paper. I made my bet when I built Filarr, but I respect the other one.

The comparison at a glance

Before the table, one warning about tables in general: they flatten nuance, and a checkbox that says "yes" hides a hundred details about how well something is done. Read the rows below as a map, not the territory, and let the prose around them carry the meaning.

Google KeepFilarr
Encryption at restYes, Google holds keysYes, AES-256-GCM, you hold keys
End-to-end / zero-knowledgeNoYes
Can the provider read your notesYesNo
Works fully offlinePartial (cache)Yes, by design
Cloud syncMandatory, always onOptional, encrypted blobs only
Bring your own storageNoYes, S3-compatible
Files alongside notesLimited (images, drawings)Yes, 51+ formats
Graph / linked knowledge viewNoYes
Voice notes with transcriptionYesNo
Image OCR searchYesNo
Live collaborationYesNo (single-user focus today)
Mobile appYes, matureIn final testing (2026)
Recovery if you forget passwordGoogle account recovery24-word BIP-39 phrase, self-custody
PriceFree (tied to Google account)Free local forever, sync from 4 EUR/month
Open sourceNoDesktop client, BSL 1.1

What this table should tell you is that these products barely overlap on the axes each one cares about most. Keep dominates the rows about capture, collaboration and ecosystem maturity. Filarr dominates the rows about ownership, encryption and file management. If you only glance at the table you might conclude they are close competitors, but they are really two tools optimized for two different definitions of what a note app is for. The rest of this article is about helping you figure out which definition is yours.

Where Google Keep genuinely wins

Let me spend real words here, because if I rush this section you should not trust the rest. Keep wins on capture speed, full stop. The combination of the widget, the voice input, the instant sync and the sheer lack of friction means that Keep gets thoughts out of your head faster than anything I have used. When you are walking, driving, or half-asleep, that speed is not a luxury, it is the difference between capturing the idea and losing it. I have shipped an encrypted workspace and I still occasionally reach for Keep in those moments, and I am not going to pretend otherwise.

Keep wins on the intelligence features that only a company with Google's machine learning resources can offer cheaply. Optical character recognition that makes the text inside your photos searchable is genuinely useful, and it is hard to build well. Automatic transcription of voice notes is the same story. These features exist because your data is readable on Google's servers, which is exactly the trade this article is about, but if you value those features more than you value privacy for that particular content, Keep delivers them and Filarr does not. That is an honest trade, not a dodge.

Keep wins on collaboration and sharing. Sharing a note or a checklist with another person and watching it update live is a one-tap operation, and for shared grocery lists, trip planning, and quick coordination it is excellent. Filarr today is built around single-user private workspaces and encrypted file sharing via links, not live multi-person editing of a note, so if real-time shared notes are central to your life, Keep is simply the better tool right now, and I would rather tell you that than lose your trust by pretending otherwise.

Keep wins on ecosystem and maturity. It is thirteen years old, it is woven into Gmail, Docs, Calendar and Android, it works on every platform including a mature mobile app, and it has been stress-tested by hundreds of millions of users. Filarr is young, its mobile app is in final testing in 2026, and its ecosystem is a fraction of Google's. If you live inside Google's products all day, Keep's integration is a real, daily advantage that no amount of encryption can substitute for. And Keep is free, with nothing to configure and no recovery phrase to safeguard. For a huge number of people, that combination of free, frictionless and familiar is exactly right, and there is no shame in choosing it for the notes that do not need protecting.

Where Filarr genuinely wins

Filarr wins, decisively, on the single question that started this article: can anyone but you read your notes. With Keep the answer is yes, Google can. With Filarr the answer is no, because the encryption key is derived from your password and never leaves your device in usable form. If you have anything at all that you would not want a stranger, an employer, an insurer, a government or a future policy change to read, that difference is not a nice-to-have, it is the whole reason to switch. Everything else Filarr does is downstream of getting this one thing right, and I designed the entire architecture around it rather than treating it as a feature to advertise. The full defensive picture, layer by layer, is documented in Filarr's security architecture writeup if you want to verify my claims rather than take my word.

Filarr wins on keeping your notes and your files together. Keep is a note app that can attach images and drawings, but it is not where your PDFs, contracts, spreadsheets and photos live. In practice, Keep users end up with notes in Keep and files in Drive and downloads elsewhere, which is exactly the fragmentation that makes people lose things. Filarr holds notes and files in the same encrypted workspace, lets you link them to each other, search inside documents, and see the whole web of connections in a graph view. If you have ever wanted the note about a document and the document itself to actually live next to each other, that is the daily experience Filarr is built to give you, and I wrote about that specific relief in stop losing files.

Filarr wins on genuine offline independence and ownership. Because it is local-first, the app does not need a server to be alive. Your data is yours, on your disk, working with or without an internet connection, with or without a subscription, with or without the company that made it continuing to exist. Keep, by contrast, is only ever as alive as your Google account and Google's servers. If you value the idea that your archive should outlive any company's business decisions, Filarr is built on that principle from the ground up rather than as an afterthought.

Filarr wins on the optionality and transparency of the cloud. With Keep, the cloud is mandatory and readable. With Filarr, the cloud is optional, and when you do use it, it stores only encrypted blobs, and you can even bring your own storage bucket. On top of that, the desktop client is open source under BSL 1.1, so the encryption claims I am making are not something you have to take on faith, you can read the code. Keep is closed source, so its security is a promise, and Filarr's is a promise you can verify. For a certain kind of person, that verifiability is worth more than any feature, and if you are that kind of person, you already know it.

Migrating from Keep to Filarr without losing anything

Moving out of Keep is more manual than I would like, and I will not pretend it is one click, because the friction is real and you deserve to know before you start. The export path runs through Google Takeout, which is Google's data export service. You select Google Keep, request the archive, and Google produces a zip file containing each note as an HTML file and a JSON file, plus any attached images. This works, but there are sharp edges worth naming. Takeout notes cannot be re-imported back into Keep, so it is a one-way door, and on managed enterprise or education accounts Takeout can be disabled entirely by an administrator, in which case there is no supported mass-export at all. Google has also been testing an export-to-Markdown feature on Android, spotted as a debug option in late 2025, which would make moving notes to other apps much cleaner if it ships, but as of this writing it is not a finished, reliable path you can count on.

Once you have your Takeout archive, the practical migration into Filarr looks like this. The JSON and HTML files are plain files, and Filarr is built to hold files of many formats in an encrypted workspace, so the simplest robust approach is to bring the exported notes into a Filarr workspace as files, then recreate the notes you actively use as native Filarr notes so they gain the rich editor, linking and graph features. For most people the honest reality is that you do not need to migrate everything. The vast majority of Keep notes are dead weight, old grocery lists and expired reminders, and the migration is a chance to keep only what matters. Move the twenty or fifty notes you actually reference, protect them properly, and let the rest stay in the Takeout archive as a cold backup. I wrote a detailed, step-by-step migration guide for a similar move in how to move a Notion workspace to an encrypted app, and the same principles of export, verify, and rebuild-what-you-use apply cleanly to Keep.

What you gain in the move is ownership and encryption for the notes you kept, and the ability to finally put your files next to them. What you lose, and I will say it plainly, is Keep's voice capture, its OCR, its live sharing, and its zero-effort sync. That is why, for a lot of people, migration is not really about abandoning Keep entirely but about drawing a line: the sensitive and long-term stuff moves to Filarr, and Keep, if you keep using it, becomes a scratchpad for throwaway captures that you consciously decide do not need protecting.

What you actually pay, in three real scenarios

Keep is free, and Filarr is free for local use forever, so the pricing conversation is narrower than it looks, but it is worth doing carefully because "free" always has a shape. Keep's price is zero money and a non-zero amount of your privacy: you pay by having your notes readable on Google's servers, and by being inside an ecosystem whose incentives are not aligned with your data staying private. Filarr's local tier is zero money and zero privacy cost, because nothing leaves your machine, and its optional cloud sync starts at 4 EUR per month if you want encrypted multi-device sync. Let me run three concrete scenarios so you can see what you would actually spend.

Scenario one, the single-device privacy-conscious user. You work mostly on one laptop, you want your notes and files encrypted and owned, and you do not need to sync to a phone constantly. Here you pay Filarr exactly nothing, because the free local tier does everything you need, and you get real encryption that Keep cannot offer at any price. Keep would also cost you nothing in money, but you would be paying in readability of your data. For this person, Filarr is strictly better and strictly free, which is about as clean a win as pricing analysis ever gets.

Scenario two, the multi-device user who wants encrypted sync. You work across a laptop and a phone, and you want your encrypted notes and files to follow you. Keep does this for free but readably. Filarr does this for 4 EUR per month, storing only encrypted blobs the server cannot read, or for zero money if you bring your own S3-compatible storage bucket and point Filarr at it. So the real question in this scenario is whether roughly 48 EUR a year, or a bit of self-hosting effort, is worth having your synced data be genuinely unreadable by the provider. For anyone syncing sensitive material, that is one of the cheapest privacy upgrades available, and it is a fraction of what encrypted cloud storage services typically charge.

Scenario three, the household or the person deep in Google's ecosystem. You share grocery lists with your family, you live in Gmail and Calendar all day, and most of your notes are genuinely mundane. Here Keep's free tier and live sharing are hard to beat, and I would not tell you to pay for Filarr just to replicate what Keep already does well for free. The smart spend for this person is a hybrid: keep using Keep for the shared and disposable stuff at zero cost, and add Filarr's free local tier for the handful of things that actually need encryption, upgrading to sync only if and when your private material needs to travel. In that setup your total cash outlay can still be zero, and you have simply stopped putting your sensitive notes in a place the provider can read.

Open source, and what the license actually means for you

Google Keep is closed source, which means every security claim it makes is a claim you have to trust rather than verify. That is not unusual for consumer software, and Google has a serious security team, but it does mean that when Google says your data is encrypted at rest, you are taking their word for it and, more importantly, you already know the conclusion: they hold the keys, so the encryption does not protect you from them. There is no reading of Keep's source that changes that architecture, because the architecture is the point.

Filarr's desktop client is open source under the Business Source License 1.1, and I want to be precise about what that does and does not mean, because open source is a term people wave around loosely. BSL 1.1 means the source code is published and you can read it, audit it, build it, and verify that the encryption works the way I claim it does. It is not a fully permissive license like MIT, because it places some restrictions on commercial resale for a period before typically converting to a more open license over time, and I explained my full reasoning for choosing it in Filarr goes open source. For you as a user, the practical upshot is simple and important: you do not have to trust my marketing about the encryption, you can go read the code that does it. When an app's entire pitch is "we cannot read your data," the ability to check that claim is not a nice bonus, it is the thing that makes the claim believable. One clarification worth keeping straight, since I care about accuracy: the desktop client is BSL 1.1, while the Filarr website itself is a separate project under AGPL-3.0, so do not conflate the two licenses.

Which one is right for you

Let me get specific with a few personas, because "it depends" is a cop-out and you came here for an actual recommendation. If you are a fast-moving generalist who mostly captures short, disposable notes and shares lists with people, and privacy is not a driving concern for that content, choose Google Keep and do not overthink it. It is free, it is instant, it is everywhere, and for genuinely mundane notes the encryption question simply does not matter. Buying a lock for a diary that contains only grocery lists is not wisdom, it is anxiety, and I am not going to sell you anxiety.

If you are a developer, knowledge worker, or privacy-aware person who keeps things you would not want anyone else to read, credentials, client data, medical notes, early-stage ideas, personal writing, choose Filarr, and specifically choose to actually move the sensitive material rather than just admiring the idea of encryption. This is the persona I built Filarr for, and the value is concentrated exactly here: your private notes become genuinely private, verifiably so, and your files finally live next to them. If you are comparing several options in this category, I put Filarr in context against the whole field in the best encrypted note-taking apps of 2026, and I tried to be honest about where each one leads.

If you are a self-hoster or someone who has decided, on principle, to get off cloud SaaS wherever possible, choose Filarr and use the bring-your-own-storage option so that even your synced encrypted blobs sit in a bucket you control. This gives you the fullest possible ownership: local-first data, encryption you hold the keys to, and storage infrastructure you rent directly, with no intermediary who could read your data even if they wanted to. Keep is architecturally the opposite of what you want, and no configuration bridges that gap.

And if you are, like most people, somewhere in the middle, choose both, deliberately. Use Keep as a fast scratchpad for the throwaway stuff where speed matters and privacy does not, and use Filarr's free local tier as the vault for the things that actually need protecting. This is not a cop-out, it is the mature answer, and it is how I personally operate. The mistake is not using Keep. The mistake is using Keep for the one note that should never have been readable by anyone but you, and only realizing it the day it leaks. If you want a broader practical framework for thinking about which notes need what level of protection, I wrote a guide on how to encrypt your notes that walks through exactly that decision.

The bottom line

Google Keep is a genuinely good app that made one foundational choice: your notes live on Google's servers in a form Google can read. Everything convenient about Keep, the instant sync, the OCR, the transcription, the effortless recovery, flows from that choice, and everything concerning about it flows from the same place. For a great deal of what people write, that trade is completely fine, and I am not here to convince you to encrypt your shopping list. But for the notes that matter, the ones you would never post publicly and would hate to see leaked, "encrypted, but the provider holds the keys" is not the same as "encrypted, and only you hold the keys," and no amount of Google's engineering closes that gap, because the gap is the design.

Filarr exists to close it. It gives you the same jot-it-down experience for the stuff that needs protecting, stores it with AES-256-GCM on your own disk, keeps the keys in your hands via a password only you know and a recovery phrase only you hold, works fully offline, and only ever sends encrypted blobs to a cloud if you choose to turn sync on. It is younger and less feature-rich than Keep, it does not do voice transcription or live collaboration, and its mobile app is still in final testing as of 2026. I would rather you know all of that going in than discover it later. But if what you actually want is private notes that respect your data, notes that are yours in the deepest sense of the word, then the honest recommendation is to keep Keep for what it is good at and move everything that matters somewhere it can finally be private. That somewhere is what I have spent years building.

FAQ

Is Google Keep encrypted? Yes, but only in a limited sense. Google Keep encrypts your notes at rest on its servers and in transit over the network, which protects against outside attackers and network eavesdroppers. It is not end-to-end or zero-knowledge encrypted, because Google generates and holds the keys, which means Google's systems can read the plaintext of your notes. If you want encryption where only you can read your notes, Keep does not offer it.

Can Google read my Keep notes? Yes, technically it can. Because Google holds the encryption keys and stores your notes in a readable form to power features like search and OCR, the content of your notes is accessible to Google's systems, and can be produced in response to valid legal requests. This is not a security flaw, it is how Keep is architected. An app like Filarr, which derives your key from your password and never sends it to the server, is built so that even the provider cannot read your data.

What is the most private alternative to Google Keep? For genuine privacy you want a zero-knowledge, local-first app where the encryption key never leaves your device. Filarr fits that description: it encrypts every note and file with AES-256-GCM on your own disk, keeps the keys in your hands, works fully offline, and only syncs encrypted blobs the server cannot read. Other encrypted note apps exist too, and I compare the field honestly in my guide to the best encrypted note-taking apps of 2026.

Is Filarr free like Google Keep? Yes, Filarr is free forever for local use, with no account required to start, and that free tier includes the full encryption. The only paid part is optional cloud sync, which starts at 4 EUR per month for encrypted multi-device syncing, and you can even avoid that cost by bringing your own S3-compatible storage bucket. If you only use one device, Filarr costs you nothing and still gives you real encryption that Keep cannot.

What happens if I forget my Filarr password? When you set up encryption, Filarr gives you a 24-word BIP-39 recovery phrase. If you forget your password but still have that phrase, you can recover access. If you lose both your password and your recovery phrase, your data is unrecoverable by anyone, including me, because Filarr genuinely cannot read your data. This is the price of real encryption, and it is why you should store your recovery phrase somewhere safe and offline. Keep, by contrast, offers Google account recovery, which is more forgiving but also means Google can restore access to readable data.

How do I move my notes from Google Keep to Filarr? Use Google Takeout to export your Keep notes, which produces a zip file with each note as an HTML and JSON file plus any images. Note that Takeout exports cannot be re-imported into Keep and may be disabled on managed accounts. From there, bring the exported files into a Filarr workspace and recreate the notes you actively use as native Filarr notes. In practice most Keep notes are disposable, so migration is a good chance to keep only what matters and protect it properly.

Does Filarr have a mobile app like Google Keep? Not yet a released one. As of 2026, Filarr's encrypted mobile app is in final testing, alongside a web app and a large desktop update, all expected within roughly one to two months of that announcement. Keep has a mature mobile app across Android and iOS, so if constant mobile access is essential to you today, that is a real advantage for Keep in the short term while Filarr's mobile app finishes testing.

Why should I trust that Filarr cannot read my notes? Because you do not have to trust it, you can verify it. Filarr's desktop client is open source under the Business Source License 1.1, so the encryption code is published and auditable. You can read exactly how keys are derived, how files are encrypted, and what the sync code sends to the server. Google Keep is closed source, so its behavior is a promise you cannot check. When an app's whole value is that it cannot read your data, being able to verify that claim in the code is what makes it believable.

#google keep#encrypted notes#local-first#zero-knowledge#privacy#notes app#filarr#alternative

Related articles