Can AI Read Encrypted Notes?
August 23, 2026 · 5 min read
If your notes are encrypted with AES-256-GCM, how can AI search them or answer questions about them? It's a fair question — and the honest answer is more nuanced than most products admit. Here's exactly how xNotePadAI handles it.
The Short Answer
AI cannot read ciphertext. It cannot process encrypted content. If your notes were truly opaque to everything, AI features would be impossible. The question is: where does decryption happen, who controls it, and what data leaves your device.
How It Actually Works
1. You write a note — plain text in your browser
2. You enable AI — an explicit opt-in choice
3. Content is chunked and sent to our server — for embedding and search
4. Separately, encryption protects your local copy — AES-256-GCM with your password
5. Server stores encrypted sync blobs — cannot decrypt without your password
The crucial distinction: AI features and encryption serve different purposes. Encryption protects your data at rest and in transit. AI features require readable content to function. You choose which to enable.
What's Truly Zero-Knowledge
Zero-knowledge (always)
Encrypted sync blobs, passwords, encryption keys — server literally cannot read these
Readable when AI enabled (opt-in)
AI chunks, vector embeddings, D1 note copies — used for search and AI answers
The Confidential Escape Hatch
Even with AI enabled, you can mark any section as confidential:
<!-- CONFIDENTIAL -->
Bank account: 12345678
Password: hunter2
<!-- /CONFIDENTIAL --> Content between these markers is stripped before any byte leaves your device. No AI agent, no MCP tool, no sync, no sharing can ever see it. It exists only in your browser's localStorage.
Comparison: What Others Do
| App | Can the company read your notes? | AI access |
|---|---|---|
| Notion | Yes — server-side, unencrypted | Silent, always-on |
| Evernote | Yes — server-side | Silent |
| Apple Notes | Opt-in (ADP) | Apple Intelligence (on-device) |
| xNotePadAI | No — zero-knowledge sync | Explicit opt-in, with confidential exclusion |
The Honest Position
We won't pretend AI can work on content it cannot read. What we do instead: make AI opt-in, give you per-section confidential controls, ensure the server cannot read encrypted sync data, and let you revoke AI access at any time. The architecture is designed so you're always in control of the boundary between privacy and utility.