
Most apps make a quiet decision for you the first time you open them: what you write goes to a server, and the copy on your machine is a cache. Context makes the opposite decision, and it makes it by default. Sync ships switched off. Nothing you write leaves your device until you decide it should.
That is easy to say and easy to misread. Here is what it means in practice, including the parts that cost you something.
On day one, nothing leaves
Open the web version and start writing. You are not asked for an account and you are not asked for a card. The notes you type, the tasks you date, the files and PDFs you keep beside them, and anything you put in the vault are created on your device and stay in encrypted storage there. The nightly backup runs on the same device. There is no “syncing…” indicator, because there is nowhere for it to sync to yet.
This is also why trying Context costs nothing but a tab. If it turns out not to be for you, you close it. There is no upload to go back and delete afterwards.
What you get while it is off
You can answer “where is my data” yourself. You don’t have to read a policy page and trust it; the answer is on the machine in front of you. That is a different kind of confidence from a promise.
The vault is a secret in one place. API keys and passwords are stored encrypted and stay masked in the list as well as in the detail view. Revealing a value is something you do, on purpose. While sync is off, those records exist in exactly one place and never travel.
Optional AI stays optional. AI help is off by default too. Switch it on and it reads only the notes relevant to the question you asked, names the note it used in the answer, and stays out of the vault. You pick the provider. Two switches, both off, both yours.
What you give up
Off by default is a trade. Pretending it is a free win would be the marketing voice we try to avoid.
One machine. Your workspace is on the device you wrote it on. There is no “open it on the library computer for ten minutes”. The web version is live and desktop, mobile and the browser extension are still in development, so today “another device” mostly means another browser on another computer, and with sync off that is an empty workspace.
A lost device is a lost workspace. Because the nightly snapshot lives on the same machine as the thing it is backing up, it will bring back a page you deleted by accident this afternoon but does nothing at all about a stolen laptop or a dead drive. A backup on the same disk isn’t a backup.
Working with other people is not the model. Nothing here is built around a shared document. If your notes need to be read by someone else while you write them, this is the wrong shape of tool, and no setting changes that.
What changes when you turn it on
Turning sync on is an explicit decision, and it stays visible after you make it. Settings show which workspace is being synced. Turn it off again and syncing stops while your local copy stays exactly where it is. An account is needed at that point; that is what the account is for: sync, backup syncing and the subscription.
Three things belong in the same paragraph, because they are true at the same time:
- Version 0.4 is not a stable release. The data format is still moving.
- There has been no independent security audit. The scope and the auditor agreement are drafted; there is no report, and we are not going to imply there is one.
- End-to-end encryption is not complete for every scenario.
If you are deciding whether to sync something sensitive, decide with those three sentences in front of you rather than around them. The full list lives on the security page and it changes when the product does.
Two habits, five minutes
Whatever you decide about sync, set these up first.
Look at the backup screen once. It shows when the last snapshot ran and how much space it takes, and it keeps a restore history. Knowing what it says today is what makes it useful in six months.
Export to Markdown once, and put the export somewhere else. Markdown export works today. We think of it as insurance more than a feature. An export sitting on the same laptop as the original doesn’t insure anything; it is a second copy of the same risk. Send it to an external drive, or to whatever cloud storage you already trust for exactly this kind of thing.
A reasonable default
Leave sync off if one machine is where your work actually happens, and you would rather have one copy you control than three copies you have to think about. That is the honest case for a lot of people, including students who write everything on one laptop.
Turn it on when the cost of retyping a workspace, or of losing one outright, becomes larger than the cost of having it in more than one place. That is a real threshold, and only you know where yours is.
Either way the decision is reversible, it is visible in settings, and it is not made for you the first time you open the app. That is most of what “off by default” is for.
