Privacy and locking
Varlig keeps your notebook on your Mac, and on your iPhone and iPad if you sync it, and gives you clear controls over who can read it. This page explains where your notes live, how to protect the private ones, and exactly when Varlig uses the internet. To keep a copy of your notes, see Import, export and backups. On iPhone and iPad, see Protected notes and app lock.
Where your notes live
Your notes are stored in a library on your Mac, in ~/Library/Application Support/Varlig/. Attachments such as images and PDFs are copied into the library, so a note keeps working even if you move or delete the original file. Everything saves as you type.
You don’t need an account to use Varlig, and your notes aren’t sent to a server of ours: Varlig has none. With iCloud sync on, your library also goes to your own private iCloud storage, and from there to your iPhone and iPad and your other Macs, and nowhere else.
Notes without a password are stored unencrypted, like most documents on your Mac. Anyone who can sign in to your Mac user account could read them. For sensitive notes, add a password as described below, and consider turning on FileVault in macOS to encrypt your whole disk.
Protect a note with a password
Give a private note, such as bank details or a journal entry, its own password:
- Open the note and choose Note › Note Password….
- Enter a password of at least 8 characters, and confirm it.
- To open the note with your fingerprint later, turn on Allow Touch ID or Mac password on this Mac.
- Choose Encrypt.
Varlig encrypts the note’s text and its attachments, and lists the note in the sidebar’s Locked section. While the note is locked, its title shows as “Locked note” and search can’t see inside it.
To read a locked note, select it and choose Unlock Note, then enter the password or use Touch ID. Note › Note Password… is also where you change or remove a note’s password.
A few honest details:
- When you protect a note, Varlig removes its earlier saved versions from your library.
- Copies you exported or backed up before adding the password stay as they were. Delete them if they shouldn’t be readable.
- A protected note syncs encrypted, and iCloud only ever holds its encrypted text. The same password opens it on your iPhone and iPad, where Face ID can open it once you’ve entered the password there. Touch ID and Face ID keys stay on the device that made them.
When protected notes lock again
Protected notes you’ve opened lock again automatically, so you don’t have to remember:
- When you switch to another app, while Lock protected notes when Varlig is inactive is on in Settings › Privacy. It’s on to begin with.
- When your Mac has been idle for the time set in Lock after Mac is idle, also in Settings › Privacy. The default is 5 minutes.
- Whenever you choose Note › Lock Encrypted Notes.
Protected tags
Rather than remembering to protect each note, you can name the tags whose notes must always be
protected. In Settings › Privacy › Protected tags, list them — for example private, finance/taxes — and click Apply.
Varlig then lists any notes with those tags, or their subtags, that aren’t protected yet, and Protect N Notes… encrypts them all with one password. Until a note is protected it’s already kept out of Spotlight, widgets, the Share menu, Shortcuts, URL automation and connected tools.
A new note that gets a protected tag prompts you to protect it. The sheet can remember the password until protected notes lock, so a run of new notes doesn’t ask each time.
Lock the whole app
Choose Note › Lock Varlig to hide your entire library behind a lock screen, for example before you hand your Mac to someone. To get back in, choose Unlock with Mac Authentication and use Touch ID or your Mac password.
To ask for authentication every time Varlig opens, turn on Require Mac authentication at launch in Settings › Privacy. Lock all of Varlig after inactivity, in the same pane, hides the whole library after the idle time instead of only locking protected notes.
Locking the app hides your notes from view, but it doesn’t encrypt them. For notes that must stay private, add a note password as well.
Spotlight is up to you
Varlig keeps your notes out of Spotlight unless you choose otherwise. To find notes from Spotlight, turn on Include unencrypted notes in Spotlight in Settings › Privacy.
Password-protected notes, and notes in the Trash, are never added to Spotlight. Turning the setting off again removes your notes from Spotlight.
Each device has its own switch. On iPhone and iPad it’s Show Notes in Spotlight in Settings › Privacy, off to begin with; see Spotlight.
Publishing puts notes outside Varlig
Publishing a snapshot writes the notes you choose into a folder of plain HTML pages. Those pages are readable by anyone who has the folder: there is no password on them, no account and no login, and nothing records who opened them.
Two things follow from that, and neither can be undone afterwards:
- Choose what goes in with care. Protected notes, notes carrying a protected tag and locked notes are never published — publishing has no “include protected notes” choice at all — but every other note you select is written out as readable text, along with its attachments.
- Removing the folder isn’t a retraction. It stops someone opening it from that location, and nothing more. A copy that has already been downloaded, mailed on or backed up stays where it is.
Publishing itself is a local operation: Varlig writes the folder where you point it and sends nothing anywhere. Whatever you then use to carry the folder — a shared drive, a web server, a mail attachment — is what decides who can reach it.
What uses the internet
Most of Varlig works entirely offline, including writing, search, text recognition in images and PDFs, Mermaid diagrams, formulas, and calculations with units or currencies once rates are downloaded. Apart from iCloud sync and sharing a note with people, which send your notes only where you choose, none of the features below upload a note. Some do send one thing you wrote in it — a web address you paste or clip, or the place name in a calculation — and the table says which:
| Feature | What it fetches | How to control it |
|---|---|---|
| Exchange rates | Daily rates from the European Central Bank and crypto rates from Coinbase, when a calculation first needs them, then at most hourly | Turn off Refresh currency and crypto rates hourly in Settings › Calculations. Refresh Now updates on demand. |
| Rate history and inflation data | Exchange-rate history from the European Central Bank and US inflation figures from the Bureau of Labor Statistics, soon after Varlig opens | The same Refresh currency and crypto rates hourly switch |
| Pasting a web link | The page’s title | Turn off Auto-fill titles when pasting web links in Settings › General |
| Link cards | The page’s title and image, when you choose Show Preview | Only when you ask for a preview. A saved card displays offline. |
| File › Clip Web Page… | The page you enter | Only when you use the command |
| Places and time zones | The place named in a calculation, sent to Apple’s geocoder | Look up places and time zones in Settings › Calculations › Live data. On to begin with. |
| Weather | The place’s coordinates, sent to Apple WeatherKit | Look up weather conditions, in the same group. On to begin with, and needs place lookup. |
| iCloud sync | Your notes and attachments, to your own private iCloud storage and your other devices. Protected notes stay encrypted. | Sync notes with iCloud in Settings › Sync & Backup. Off until you turn it on. |
| Sharing a note with people | The note you share, through iCloud, to the people you invite | Only when you choose File › Share with People… |
The two live-data lookups start on because a line that names a place has asked for one, and they run only for such a line. Turn one off and those lines show no answer.
Varlig keeps the last exchange rates it downloaded. If it has never had rates for a currency, a conversion shows an error rather than a guess.
Settings › Sync & Backup holds the iCloud switch, automatic backups and a Storage view showing what your library uses. Sync goes only to the iCloud account your Mac is signed in to; see iCloud sync and shared notes.
If you turn on Allow local MCP connections in Settings › Advanced, an AI assistant you connect can read the notes you allow, and it may send them to its own service. It’s off to begin with. See Settings.
Crash and hang reports
When Varlig crashes, stops responding, or uses unusual amounts of processor time or disk, macOS gives it a report. Varlig keeps the last 20 reports, and 10 days of performance figures, on your Mac, outside your library: they aren’t synced or backed up, and nothing sends them anywhere by itself. Each one holds the Varlig and macOS versions, your Mac’s model, and what happened and where in Varlig’s code — never note text, titles or file names.
Settings › Advanced › Crash and Hang Reports says how many are kept. Send Report… shows everything the report holds, down to the file itself, before you choose Email… or Share…, and Delete Reports… removes them. iPhone and iPad keep their own, in Settings › About Varlig. See Send a crash or hang report and the privacy policy.