Memo App
Security Comparison
Protecting notes also means controlling who can access them and planning for deleted data, lost passwords, and device changes. Compare six apps and services by the everyday controls and recovery conditions you will use.
Choose by the job: check collaborator rights for a household list, device and note locks for personal notes, and organizational access and recovery rules for work. E2EE and collaboration can coexist, but neither can recall every copy made by an authorized recipient.
Reviewed September 9, 2026. The author develops Simple Memo. This is a comparison of documented features and procedures, not an audit or security certification of the other products.
Compare six services by access and recovery
Scroll the table horizontally, including with the keyboard, to read conditions and sources.
| App or service | Use | Conditions to check | Official sources |
|---|---|---|---|
| Appleメモ / Apple Notes | Individual notes can be locked; collaboration requires removing that note’s lock setting. | Check ADP for iCloud Notes; shared-note ADP E2EE requires all participants to enable it. Resetting a custom Notes password does not unlock older notes. | Locks and recovery · Sharing · ADP |
| Google Keep | Useful for a shared list or note whose collaborators can edit its content. | For a read-only handoff, distinguish inviting a collaborator from sending a copy through another app. Archiving is not deleting. | Sharing · Archive and delete |
| Notion | Supports collaboration with page, guest, and workspace permissions. | The broadest applicable access wins. Moving a parent page to Private does not remove permissions already granted to its subpages. | Sharing and inheritance |
| OneNote | Can separate password-protected sections within a notebook. | Microsoft cannot unlock a section if its password is lost. Locked sections are excluded from search; check their state before concluding notes are missing. | Section protection · Finding notes |
| CryptPad | Supports E2EE document collaboration with view/edit permissions and owner-managed access lists. | Check recipients: sharing exposes edit history too. Share a new copy if old content should stay private. Ownerless documents cannot have ownership managed later, and administrators cannot reset account passwords. | Sharing and owners · Security assumptions · Lost password |
| Simple Memo | Captures short personal notes into a configured inbox or connected destination; it has no collaborative editor. | Local Outbox and sent history are encrypted, but email delivery is not E2EE. Check the recipient and the inbox or connected destination’s access and storage. | Technical policy |
Check account, device, and note locks separately
Review who can sign in
Use supported multi-factor authentication or passkeys, and review recovery addresses, phone numbers, signed-in devices, and connected applications. Face ID at app launch does not by itself control account access from another device.
Distinguish a screen lock from encryption
A device passcode, an app lock, and encryption of a specific note have different scopes. Check automatic relocking and whether titles or notifications remain visible. OneNote allows configuring how long a protected section remains unlocked. See OneNote’s protection settings.
See the separate 10-app encryption comparison for cipher and E2EE scope. A key length does not resolve accidental sharing or recovery.
What to check before sharing
- Choose between collaboration and sending a copy.Collaboration keeps participants on the live document. A PDF or emailed copy is a separate file that revoking the original share may not recall.
- Check recipients and rights.Grant editing only when it is needed. Keep collaboration lets recipients edit, so distinguish it from handing over a read-only copy.
- Inspect parent pages, subpages, and public links.Workspace and inherited permissions can matter alongside individual settings. Making a parent page private does not establish that every subpage is private.
- Test with harmless sample content.Check public links while signed out, and restricted content from an authorized recipient’s view. Confirm both visibility and editing rights. Opening the page in your own administrator session is not enough.
Prepare for deletion, lost keys, and device changes
Distinguish deletion from archiving
Keep allows recovery within seven days after deletion. iCloud Notes can recover notes in Recently Deleted within 30 days. These are not promises to recover permanently deleted content. First check the account, storage location, archive, and locked sections. See Keep’s instructions and iCloud Notes recovery.
An export is not a guaranteed full restore
Notion provides plan-dependent page history and exports, but reuploading an export does not instantly recreate the workspace. Use a small sample to check attachments, hierarchy, and links in the format you need. See Notion’s backup explanation and export instructions.
Open a sample on the new device before erasing the old one
Finish syncing and open the text and attachment on the new device. Keep required encryption passwords and recovery methods available, and protect exported copies at their destination. Do not erase a device that holds your only usable key or data copy.
Can strong privacy and collaboration coexist?
CryptPad is an option for E2EE document collaboration.Review view/edit rights, ownership, and access lists. Shared edit history can expose past content; use a new copy when that history should stay private. Its web application and endpoints still need to be trusted; shared links and copies made by authorized recipients still matter. Read CryptPad’s security assumptions, its FAQ on shared history, and sharing and access guidance.
Notion permissions, Apple Notes sharing, and OneNote section protection are different controls. For organizational use, match the required collaboration, participant devices, administrator recovery, and external-sharing rules. E2EE does not make collaboration impossible, and no single product can be called the safest for every workflow.
Check destinations for personal capture too
Simple Memo captures text into a personal inbox or configured connected destination. Start with one non-sensitive note and check its recipient and content in the inbox. If Obsidian integration is enabled, also check the configured vault and note.
The local Outbox and sent history are encrypted, but email content passes through the sending API and delivery provider and is stored as received email. Review mailbox access, forwarding, and vault sync or sharing separately. See delivery checks and the data-flow guide.
Frequently asked questions
Can I compare note app security by encryption alone?
No. Check recipients and permissions, account access, device and note locks, recovery, and exported copies too. A cipher name does not establish protection against accidental sharing or data loss.
Can E2EE support real-time collaboration?
CryptPad supports E2EE document collaboration. Review view/edit rights, ownership, links, and access lists. E2EE cannot recall every copy made by an authorized recipient.
Can I keep an Apple note locked while collaborating?
A note with a lock setting cannot be used for collaboration. Remove that lock setting through the note’s menu before sharing; temporarily opening it with Face ID is different. Check iCloud Advanced Data Protection and sharing conditions separately.
Why can someone edit a Notion page after I gave them view access?
They may receive broader rights through another route. Notion applies the broadest applicable access, so check workspace, parent-page, group, and other permissions.
Will a password reset restore my encrypted notes?
It depends on the product and key management. Resetting a custom Apple Notes password does not unlock older notes. Microsoft cannot remove a lost OneNote section password. Check the product’s recovery options in advance.
What should I check before replacing my device?
Finish syncing, open the text and attachments on the new device, and keep required keys and recovery methods available. Inspect exported content and its protection. Do not erase an old device that holds the only data or key copy.