Local-first

The library is a folder you own

Piper keeps your sources, notes, and highlights in a database on your machine. Not a cache of something that lives elsewhere — the actual thing.

Storage

Your vault is a real directory

On desktop, a vault binds to a folder you pick. You can open it in Finder or Explorer, back it up the way you back up everything else, and see your material sitting there as files.

Accounts

There is nothing to sign up for

No account, no email, and no server holds your vault. Piper works on a plane, in a basement, and on the day the company's website goes down. Nothing you read is reported anywhere.

Authority

The local database is the truth

Piper reads and writes SQLite on your own disk, and treats it as the authoritative copy. Everything you do lands locally first and stays correct whether or not anything else ever connects.

Exit

There is always a way out

Your notes are mirrored to disk as readable HTML as you write them. Open the folder without Piper running and the vault is still legible, which is the point of storing it that way.

Imports

Saved pages cannot phone home

Web articles are sanitized on the way in and rendered by Piper's own reading layer. An imported page cannot navigate the app or pull remote resources back down while you read it.

Not built

Sync you turn on, not sync you inherit

Planned as something enabled per vault rather than assumed. Until it lands, Piper moves your data nowhere at all.

Your library outlives the app.

Four boundaries

Sync does not exist. Your vault lives on one machine. Moving between a laptop and a desktop means moving the folder yourself, the same as any other folder.

Nothing is encrypted at rest. The SQLite database and the HTML files Piper mirrors your notes into both sit unencrypted on your disk, readable by anything that can read your files. Full-disk encryption is the mitigation; Piper adds no second layer and does not pretend to.

The note format is Piper's, not plain Markdown.Notes are stored in Piper's own HTML-based format so that links, columns, and margin comments survive round-trips. Piper does not read or write an existing Markdown vault in place, and there is no Markdown export command yet.

Downloads and update checks use the network. Piper contacts its public release service to check for and download app updates. Hosting providers receive ordinary request information such as an IP address and user agent, but Piper sends no Vault, source, note, highlight, or reading data with those requests.

Learn faster with Piper

macOSRequirements pending verification
Windows x64Requirements pending verification

Signed desktop downloads are not available yet.

Download and update checks contact Piper's public release service. They send ordinary network request information, never your Vault or what you read and write.