Snoq is a free, native Windows notes app built around one idea: writing something private shouldn't require an account, a server, or trust in a company you've never met. This blog is where we'll write about the parts of that idea that don't fit on a landing page — the cryptography, the trade-offs, and what changes from one release to the next.
What we'll actually write about
Expect three kinds of posts here. First, release notes expanded into something more useful than a changelog entry — why a feature was built the way it was, not just that it shipped. Second, plain explanations of the encryption itself: Snoq encrypts notes with AES-256-CBC, a random 16-byte IV per note, and Encrypt-then-MAC using HMAC-SHA256, with keys derived from your password by Argon2id (64 MB memory, 3 iterations, 2 threads). We'll walk through what each of those choices buys you and where the edges are. Third, practical notes on using a local-only app well — backups, vault export, and working without a sync service, since Snoq deliberately doesn't have one.
What this blog won't do
We're not going to dress up a feature list as news, and we're not going to claim security properties we haven't implemented. If something is missing — and a few things are, like idle auto-lock and a mobile companion app — we'll say so here the same way we say so on the site. A published list of gaps is worth more than a page of adjectives.
Where to start
If you're evaluating Snoq, the encryption page is the fastest way to see the actual cryptographic construction, and the release notes track every shipped change in order. This blog sits alongside both: less structured, more room to explain the reasoning. Thanks for reading, and welcome.