SecBoss stands out as a local-first, zero-knowledge Secure Notes App that keeps your notes encrypted directly on your device, never permanently stored in the cloud. Your master password and encryption keys never leave your device, and even during device sync, data is encrypted end-to-end. With minimal data collection (email only), offline-first access, and no backdoors or admin recovery access, SecBoss is built for users who want maximum privacy, control, and true security ownership over their notes.
Your notes are stored locally on your device with military grade encryption. We do not store your sensitive data on our servers - only your encrypted email for authentication purposes. Your data remains on your device until you manually delete it.
During device synchronization (triggered manually), your data is encrypted end-to-end using military-grade encryption. The data is only temporarily held during the sync process and is immediately deleted after successful transfer/sync. Transit time is within a matter of seconds.
Device sync uses temporary OTP codes or QR codes that expire quickly. Your data is encrypted before leaving your device, transferred/synced securely, and the temporary data is deleted immediately after successful sync. No permanent copies are made.
Yes! SecBoss allows syncing your vault across devices, but the number of devices depends on your plan.
Free Plan: You can sync across up to 2 devices.
Pro Plan: You can sync across unlimited devices.
Each device must be authenticated with your master password and temporary OTP codes. Your data remains encrypted during sync, and temporary data are deleted immediately after the process.
Yes. You can access, add, edit, delete, and search your stored notes without an internet connection. Internet is only required for account registration and login, subscription validation, managing devices or account settings in the Member Portal, and syncing between devices. Your records data always remains stored locally on your device.
We only store your email address for future upgrade purposes. All your notes remain encrypted and stored locally on your device. We never have access to your actual records.
Yes. SecBoss is designed with privacy in mind. Since all sensitive data remains encrypted and stored locally, and only your email is stored for authentication purposes, the app aligns with GDPR, CCPA, and other privacy-focused regulations.
Your master password is never stored anywhere. It's used to derive encryption keys locally on your device. Even we cannot recover your master password - that's why the recovery phrase or key is so important.
The recovery phrase or key is your only way to restore access if you forget your master password. It's encrypted and stored locally. Keep it safe and never share it.
Biometric login is a convenience feature that unlocks your locally stored encryption key. It cannot be bypassed without your biometric data or master password. The encryption key itself remains protected at all times.
Your data is encrypted, making it extremely difficult to access without your master password. However, you should change any critical passwords as an extra precaution. Use your recovery phrase to restore your records on a new device. The Pro plan includes a remote data wipe feature that can be used to wipe your data on a lost device.
Session timeouts can be customized in settings. Default is 5 minutes of inactivity. After timeout, you'll need to re-enter your master password or use biometric authentication or PIN to unlock your records again.
When you copy passwords, they're temporarily stored in your device clipboard. For security, use the "Clear Clipboard" feature after pasting. On Android 10+, the system may show notifications when clipboard is accessed.
Yes, you can export your records data through the Export/Import feature in the menu. Exported data maintains encryption for security. This is useful for backups or transferring to another device.
You can import your data using any of the following supported backup file formats:
• SVT (.svt) – Secure backup format that supports encryption and password protection.
• ODS (.ods) – OpenDocument Spreadsheet format for importing compatible data exports.
• CSV (.csv) – Comma-Separated Values format for importing tabular data.
CSV Template: https://apidev.secboss.com/api/v2/import-templates/sample.csv
To import your data:
1. Open Settings.
2. Tap Export/Import Data.
3. Click import and select import type.
4. Select your backup file.
5. If the backup is password-protected, enter the required backup password or recovery key/phrase when prompted.
6. Review the import details and confirm to restore your data.
Note: The available import options may vary depending on the type of backup file you select. Ensure your backup file was created by a compatible version of the app to avoid import issues.
No. SecBoss updates are designed to preserve your locally stored data. Always ensure your records is backed up using the Export feature before major updates as an extra precaution.
If your Pro subscription expires and is not renewed, your account will automatically downgrade to the Free plan. Your stored records will remain intact, but Free plan limitations will apply, such as device sync limits and restricted access to Export/Import features. No stored records will be deleted unless you manually remove them.
If you lose both of your master password and recovery phrase or key, your data cannot be recovered - this is by design for maximum security. Always keep your recovery phrase in a secure location separate from your device.
Uninstalling SecBoss permanently removes all locally stored data on your device, including your accounts and records. After uninstalling, you will no longer be able to access your data using your email, password, or recovery phrase/key, since no data remains on the device.
To prevent data loss, make sure to back up your records using the Export feature before uninstalling.
Remote Data Wipe is a Pro feature that allows you to securely erase your SecBoss records data from linked devices through the Member Portal. This is useful if a device is lost, stolen, or compromised. Once triggered, the selected device's local records data will be permanently destroyed the next time it connects to the internet.
SecBoss supports encrypted record export options for backup and migration purposes.
Available export formats include:
• .SVT — Default encrypted SecBoss backup format available to all users.
• .ODS — Structured spreadsheet-compatible export format available for Pro users.
• .ZIP — Encrypted archive export format available for Pro users.
All exported data remains encrypted and protected for additional security.
Yes. SecBoss supports secure online and offline sharing of your note records.
Online Sharing allows encrypted sharing between authenticated SecBoss users over the internet.
Offline Sharing allows encrypted record transfers between nearby users without requiring an active internet connection.
All shared data remains encrypted end-to-end to help protect your information during transfer.
Yes. SecBoss includes a Secure Version History system that helps protect against accidental overwrites or unwanted changes.
You can:
• View previous versions of stored notes.
• Roll back to earlier versions when needed.
• Configure retention duration and version limits depending on your preferences or subscription plan.
All version history is stored locally on your device and remains encrypted and securely protected.
Yes. SecBoss includes a Recently Deleted Recovery system that temporarily stores deleted notes before permanent removal.
This allows you to:
• Restore accidentally deleted items.
• Recover records within a configurable retention period.
• Permanently erase items manually if desired.
Recovered items retain their original encryption and security protections.
Yes. The SecBoss Member Portal allows you to view and manage your registered and active devices.
You can:
• View linked devices and recent activity.
• Remove or revoke device access remotely.
• Monitor unauthorized or suspicious devices.
This helps you maintain better visibility and control over your account security.
Trusted Devices are verified devices that can be marked as secure within the Member Portal.
When a device is trusted:
• Certain verification steps may be reduced during re-registration or device recovery.
• Faster device restoration may be available after reinstalling SecBoss.
• Additional identity confirmation may still be required for sensitive actions.
Users can manage or remove trusted devices anytime through the Member Portal.
SecBoss uses a zero-knowledge design, which means your notes are encrypted on your device and only you hold the keys.
• Your data is protected with AES-256 encryption — the same standard trusted by banks and governments.
• Your master password is strengthened using Argon2id, a modern, brute-force-resistant method for turning your password into an encryption key.
• Everything stays encrypted on your device, in transit, and on our servers. Your master password is never sent to us, so we can never read your notes or share them with anyone.
The trade-off is intentional: only your master password and recovery key can unlock your data. If you lose both, no one — not even us — can restore it.
PIN sign-in lets you unlock SecBoss on this device with a short numeric PIN instead of typing your master password every time. It is the alternative to fingerprint sign-in for phones that have no fingerprint sensor, or where you simply prefer a PIN. It never replaces your master password — your password always keeps working, and you will still need it for account recovery and for changing security settings.
Setting it up
1. Sign in normally with your master password.
2. Go to Settings and find the "Enable PIN Login" card.
3. Tap "Enable Sign In PIN".
4. Confirm your master password when prompted. This is required every time you create or update a PIN, so nobody who picks up an unlocked phone can quietly set one.
5. Enter a PIN of 6 to 12 digits, then re-enter it to confirm.
To change it later, tap "Update Sign In PIN" (your master password is required again). To turn it off, tap "Remove Sign In PIN" and enter your current PIN.
A PIN belongs to one account per device. If a PIN is already set up for a different account on this phone, the card offers "Switch to This Account" — accepting that removes the other account's PIN from this device.
Using it
• On the sign-in screen, tap "Sign In via PIN", enter your PIN, and tap Sign In.
• You will be greeted by name so you can confirm which account is about to be unlocked.
• Tap Cancel at any time to go back to password sign-in.
How it protects you
• Your PIN is never stored on your device or on our servers — not in plain form, and not even as a hash. It never leaves your phone.
• Instead, your PIN is run through a memory-hard key derivation function (Argon2id) with a random salt, and the resulting key is used to encrypt your account key with AES-256-GCM. Only that encrypted result is saved.
• Entering the correct PIN is what reproduces the key and decrypts your records. A wrong PIN fails cryptographic verification and produces nothing usable — there is no stored copy of the PIN to compare against, and no way to read your records without the right PIN or your master password.
• Wrong entries are limited. After 3 failed attempts the device locks out, and each further lockout lasts longer: 15 seconds, 30 seconds, 1 minute, 5 minutes, then 10 minutes. The counter is shared with password and fingerprint sign-in, so a PIN cannot be used to sidestep a lockout, and the countdown is shown on the screen.
• All the usual account checks still apply — a suspended or blocked account cannot be opened with a PIN.
• Because a short PIN is easier to guess or shoulder-surf than a long password, choose digits that are not your birthday, phone number, or screen-unlock PIN, and enter it out of sight of others.
Good to know
• PIN sign-in is per device. Enabling it on your phone does not enable it on your tablet or any other device — set it up separately on each one.
• Forgot your PIN? Sign in with your master password, then set a new PIN in Settings. There is no PIN reset by email, because we have nothing to reset.
• Uninstalling the app, deleting the account, or wiping your data on this device also removes the PIN enrollment. You will need to set it up again after signing back in.
SecBoss can automatically parse note descriptions to detect, extract, and organize structured information from your notes. When supported information is recognized, the app identifies relevant details and organizes them into the appropriate fields or sections, helping you save time when creating or updating records. Automatic parsing can be enabled when adding a field under Manage Templates, allowing the selected field to automatically detect and extract relevant information from note descriptions. This feature is designed to make unstructured note descriptions easier to manage while keeping your data organized.
Yes. SecBoss supports automatic formatting for long note descriptions to improve readability, structure, and organization. The feature helps organize lengthy content into a clearer and more structured format, making important information easier to read, review, and manage without requiring you to manually format the entire description.
SecBoss 2026. All Rights Reserved.