A zero-knowledge encrypted workspace for your documents, notes, and files.
π₯ Download Β |Β β¨ Features Β |Β π₯οΈ Self Host Β |Β ποΈ Build Β |Β π Structure Β |Β π¬ Discord Β |Β π Support
- Overview
- Download
- Key Features
- How the Encryption Works
- Tech Stack
- Folder Structure
- Self Hosting
- Building from Source
- Made with Love
Ciphra is a zero-knowledge encrypted desktop application for writing, organizing, and storing your most important information. Built with Tauri v2, every single byte of your data β documents, folder names, file names, images, and PDFs β is encrypted on your device before it ever leaves to the cloud.
No passwords. No email. No recovery codes sent to a server. Your 12-word BIP39 mnemonic phrase is the only key to your vault. Lose it, and nobody β not even the developers β can help you recover access. That is the point.
"If we can read it, it isn't really yours."
Choose the easiest installation method for your operating system. All manual download files are securely hosted on our Releases page.
Recommended (via Winget): The fastest way to install and keep Ciphra updated on Windows is through the Windows Package Manager. Open your terminal or command prompt and run:
winget install Ciphra.CiphraDirect Download: If you prefer a manual installation, download the installer of your choice from the Releases page:
Ciphra_x.x.x_x64-setup.exe(Standard NSIS Installer)Ciphra_x.x.x_x64_en-US.msi(Windows MSI Installer)
We provide multiple package formats to support your favorite distribution. Grab the latest version from the Releases page:
- Universal:
ciphra_x.x.x_amd64.AppImage(Portable, no installation required) - Debian / Ubuntu:
ciphra_x.x.x_amd64.deb - Fedora / RHEL / openSUSE:
ciphra-x.x.x-1.x86_64.rpm
π macOS: Not currently published due to Apple notarization requirements. However, you can easily build from source.
- BIP39 12-word mnemonic authentication β same standard used by crypto hardware wallets
- AES-256-GCM encryption for all data: documents, folder names, file names, images, and PDFs
- Private key lives only in RAM β never written to disk, never sent to any server
- Public key stored on Convex β used only to identify your account
- Refresh the app = session cleared. Your key is gone until you log in again.
- Optional 6-digit PIN that encrypts your RAM key and stores it locally
- Inactivity auto-lock β configurable: 1 min, 5 min, 30 min, or 1 hour
- App close = instant lock β no data left in memory
- PIN recovery via 12 words β verify your mnemonic to reset your PIN
- Logout wipes the PIN from storage with a confirmation warning
- Create unlimited folders with custom colors and names
- Star important folders for quick access in the Starred section
- Rename, recolor, lock individual folders
- Recycle bin with 30-day auto-deletion via Convex scheduled crons
- Grid and List view with sorting by name, date created, and date modified
- Encrypted folder names β Convex never sees what your folders are called
- Full-screen TipTap editor β no boxes, no borders, just your writing
- Safe Mode β document locked by default to prevent accidental edits, one click to enable editing
- Zoom control β adjust editor zoom from 70% to 150%
- Slash commands (
/) for quick formatting: headings, lists, tables, code blocks, dividers - Tables β fully resizable, Google Docs style. Add/remove rows and columns, merge and split cells
- Text alignment β left, center, right via dropdown
- Bold, italic, strikethrough, text color, highlight color
- Inline image insertion with automatic WebP compression (max 800px width)
- Code blocks with language selector and one-click copy button
- Find & Replace β Ctrl+F to find, toggle replace mode, replace one or all
- Focus Mode β hides all UI, full immersion writing. Press Escape to exit
- Auto-save β debounced 500ms after every keystroke, encrypted before saving
- Word count, character count, reading time in the status bar
- Export as PDF β opens print dialog with clean styling
- Export as Markdown β downloads a
.mdfile
- Upload images (JPG, PNG, GIF, WebP) and PDFs up to 15MB
- Files are encrypted before upload β Convex storage never sees raw bytes
- Image thumbnails β decrypted and rendered in the grid
- Full-screen viewer for images and PDFs β Escape to close
- Download decrypted file directly from the viewer
- Filter by: All, Images, PDFs, Documents
- Pagination with configurable items per page (5, 10, 20, 30, 50, 100, All)
- Right-click context menu on any file or document
- All deleted items go to recycle bin first
- 30-day countdown shown on each item (color-coded: green β amber β red)
- Restore any item back to its original location
- Permanent delete with confirmation modal
- Empty bin button to wipe everything at once
- Auto-purge via Convex daily cron job β no manual cleanup needed
- Appearance β Light/Dark mode toggle with live preview cards
- Security β App Lock toggle, PIN setup, timeout configuration, change PIN
- Storage β Visual storage usage bar with percentage and breakdown
- Data β Delete account Permanently
- Light and Dark mode with smooth transitions
- Premium glassmorphism design throughout
- Animated empty states with 3D floating effect
- Breadcrumb navigation β Home β Folder β Document
- Back button on all inner pages
- Custom 4px scrollbar that matches the theme
- Splash screen with animated progress bar
Your 12 Words (BIP39)
β
βΌ
mnemonicToSeed() β @scure/bip39
β
βΌ
PBKDF2 (100,000 iterations, SHA-256)
β
ββββΊ Private Key (AES-256-GCM) βββ stays in RAM only
β
ββββΊ Public Key (SHA-256 hash) βββ stored in Convex
used as account identifier
When you encrypt any data:
plaintext + Private Key β AES-256-GCM (random 12-byte IV) β base64 ciphertext
IV is prepended to ciphertext β single base64 string stored in Convex
When you decrypt:
base64 β split IV (first 12 bytes) + ciphertext β AES-256-GCM decrypt β plaintext
This happens 100% on your device. Convex only ever sees encrypted base64 strings.
What Convex stores:
- Encrypted folder names (
nameEncrypted) - Encrypted document titles (
titleEncrypted) - Encrypted document content (
contentEncrypted) - Encrypted file names (
nameEncrypted) - Encrypted file bytes (uploaded to Convex Storage)
- Your public key (used only to find your account on login)
What Convex never sees:
- Your 12 words
- Your private key
- Any plaintext content
- Any readable file data
| Layer | Technology |
|---|---|
| Desktop Shell | Tauri v2 (Rust) |
| Frontend | React 18 + TypeScript + Vite |
| Styling | Tailwind CSS v4 + shadcn/ui |
| Backend / Database | Convex (real-time, serverless) |
| Editor | TipTap v3 |
| Encryption | Web Crypto API (AES-256-GCM) |
| Mnemonic | @scure/bip39 (BIP39 standard) |
| State Management | Zustand v5 |
| Routing | React Router v7 |
| Icons | Lucide React |
| Notifications | Sonner |
| ZIP Export | JSZip + FileSaver |
A complete and exhaustive breakdown of the Ciphra project architecture, including all frontend features, serverless backend files, native desktop integration, and their specific purposes.
ciphra/
βββ .github/
β βββ assets/
β β βββ app.png # App screenshot for README
β β βββ icon.png # App logo
β βββ workflows/
β βββ release.yml # GitHub Actions β builds all platforms
β
βββ convex/ # Convex backend (serverless functions)
β βββ _generated/ # Auto-generated by Convex CLI
β β βββ api.d.ts # TypeScript definitions for API
β β βββ api.js # Compiled API endpoints
β β βββ dataModel.d.ts # Schema data types
β β βββ server.d.ts # Server types
β β βββ server.js # Compiled server code
β βββ auth.ts # User create / login / delete
β βββ crons.ts # Daily auto-delete scheduled job
β βββ documents.ts # Document CRUD + recycle bin
β βββ files.ts # File upload / storage / recycle bin
β βββ folders.ts # Folder CRUD + recycle bin
β βββ recycleBin.ts # Internal purge mutation
β βββ schema.ts # Database schema (all tables)
β βββ README.md # Convex backend documentation
β βββ tsconfig.json # TypeScript config for backend
β
βββ src-tauri/ # Tauri Rust backend
β βββ capabilities/ # Tauri permission definitions
β β βββ default.json # Default system permissions
β βββ gen/ # Auto-generated by Tauri
β β βββ schemas/ # IPC and configuration schemas
β β βββ acl-manifests.json
β β βββ capabilities.json
β β βββ desktop-schema.json
β β βββ windows-schema.json
β βββ src/
β β βββ lib.rs # Rust library and plugin setup
β β βββ main.rs # Tauri application entry point
β βββ .gitignore # Ignored files for Rust backend
β βββ 2 # Tauri v2 flag/lock
β βββ build.rs # Rust build script
β βββ Cargo.lock # Rust dependency lockfile
β βββ Cargo.toml # Rust dependencies and versioning
β βββ tauri.conf.json # App config, window size, identifier
β
βββ src/ # React Frontend
β βββ components/
β β βββ common/
β β β βββ ConfirmModal.tsx # Generic confirmation dialog
β β β βββ EmptyState.tsx # Animated empty state with 3D icon
β β β βββ FullScreenViewer.tsx # Decrypted image/PDF viewer
β β β βββ SearchEmptyState.tsx # UI for no search results
β β β βββ UpdateProgressToast.tsx # Progress bar for app updates
β β β βββ VerifyPinModal.tsx # PIN verification modal
β β βββ layout/
β β β βββ Breadcrumb.tsx # Breadcrumb navigation
β β β βββ LogoutModal.tsx # Secure logout confirmation
β β β βββ TopNav.tsx # Sticky top navbar
β β βββ ui/ # shadcn/ui auto-generated components
β β βββ alert-dialog.tsx # Alert dialog primitive
β β βββ badge.tsx # Badge primitive
β β βββ button.tsx # Button primitive
β β βββ card.tsx # Card container primitive
β β βββ checkbox.tsx # Checkbox primitive
β β βββ context-menu.tsx # Right-click menu primitive
β β βββ dialog.tsx # Modal dialog primitive
β β βββ dropdown-menu.tsx # Dropdown primitive
β β βββ input.tsx # Text input primitive
β β βββ popover.tsx # Popover primitive
β β βββ scroll-area.tsx # Custom scrollbar container
β β βββ separator.tsx # Divider primitive
β β βββ sonner.tsx # Toast notification system
β β βββ tabs.tsx # Tab navigation primitive
β β βββ tooltip.tsx # Tooltip primitive
β β
β βββ features/ # Core App Modules
β β βββ auth/ # Authentication Flow
β β β βββ components/
β β β β βββ MnemonicInputGrid.tsx # Reusable 12-word input grid
β β β β βββ MnemonicRevealStep.tsx # Step 2 β show/copy/download 12 words
β β β β βββ UsernameStep.tsx # Step 1 β username availability check
β β β βββ hooks/
β β β β βββ useLogin.ts # Login logic + lockout handling
β β β βββ LoginPage.tsx # 12-word grid login page
β β β βββ SignupPage.tsx # Multi-step signup orchestrator
β β βββ editor/ # Rich Text Document Editor
β β β βββ components/
β β β β βββ AlignDropdown.tsx # Text alignment dropdown
β β β β βββ CodeBlockComponent.tsx # Custom code block with copy
β β β β βββ EditorStatusBar.tsx # Word count + save status
β β β β βββ EditorToolbar.tsx # Formatting toolbar + title + nav
β β β β βββ ExportMenu.tsx # PDF + Markdown export
β β β β βββ FindReplace.tsx # Find & Replace panel
β β β β βββ FontSizeDropdown.tsx # Text sizing controls
β β β β βββ LinkModal.tsx # Insert hyperlink modal
β β β β βββ ResizableImage.tsx # Inline image resizing
β β β β βββ SlashCommand.tsx # '/' command palette
β β β β βββ TableControls.tsx # Floating table toolbar
β β β β βββ TextStyleDropdown.tsx # Headings and font styles
β β β β βββ TipTapEditor.tsx # TipTap instance + extensions
β β β β βββ ToolbarHelpers.tsx # Helper functions for editor
β β β βββ hooks/
β β β β βββ useAutoSave.ts # Debounced encrypted auto-save
β β β β βββ useFocusMode.ts # Focus mode toggle + Escape key
β β β βββ styles/
β β β β βββ EditorPage.css # Editor-specific styles
β β β βββ EditorPage.tsx # Full-screen document editor page
β β βββ folder/ # Folder & Vault View
β β β βββ components/
β β β β βββ CreateDocModal.tsx # New document modal
β β β β βββ FileCard.tsx # Grid card for file/doc
β β β β βββ FileContextMenu.tsx # Right-click menu for items
β β β β βββ FileFilter.tsx # All/Images/PDFs/Documents filter
β β β β βββ FileGrid.tsx # Unified grid with pagination
β β β β βββ FileListItem.tsx # List row for file/doc
β β β β βββ FolderActionBar.tsx # Filter + sort + view + actions
β β β β βββ ImageThumbnail.tsx # Decrypt + render image thumbnail
β β β β βββ StarredItemsSection.tsx # Starred items in folder
β β β β βββ UploadFileModal.tsx # Encrypted file upload
β β β βββ FolderPage.tsx # Folder contents page
β β βββ home/ # Main Dashboard
β β β βββ components/
β β β β βββ CreateFolderModal.tsx # New folder creation
β β β β βββ FolderCard.tsx # Grid card for folders
β β β β βββ FolderContextMenu.tsx # Right-click menu for folders
β β β β βββ FolderGrid.tsx # Unified folder grid
β β β β βββ FolderListItem.tsx # List row for folders
β β β β βββ StarredSection.tsx # Pinned/Starred folders
β β β βββ HomePage.tsx # Root page β all folders grid
β β βββ lock/ # Security & App Lock
β β β βββ components/
β β β β βββ AppLockSettings.tsx # Enable/disable/change PIN settings
β β β β βββ PinInput.tsx # 6-digit PIN input logic
β β β β βββ PinResetModal.tsx # Reset PIN via 12 words
β β β βββ LockScreen.tsx # PIN entry screen overlay
β β βββ recycle/ # Recycle Bin
β β β βββ components/
β β β β βββ ConfirmDeleteModal.tsx # Permanent delete confirmation
β β β β βββ RecycleItemCard.tsx # Grid card for deleted items
β β β β βββ RecycleItemList.tsx # List row for deleted items
β β β βββ RecycleBinPage.tsx # Recycle bin with grid/list view
β β βββ settings/ # App Settings & Preferences
β β β βββ components/
β β β β βββ AboutSettings.tsx # App info, social links, and updates
β β β β βββ DataSettings.tsx # Account deletion and data export
β β β β βββ SettingsSidebar.tsx # Collapsible sidebar navigation
β β β β βββ StorageSettings.tsx # Storage bar + space breakdown
β β β βββ SettingsPage.tsx # Settings layout wrapper
β β βββ splash/
β β βββ SplashScreen.tsx # Splash with animated progress bar
β β
β βββ hooks/
β β βββ useInactivity.ts # Inactivity timer for app lock
β β
β βββ lib/ # Core Logic & Algorithms
β β βββ crypto/
β β β βββ aes.ts # AES-256-GCM encrypt / decrypt
β β β βββ bip39.ts # Mnemonic generate / validate / seed
β β β βββ fileCrypto.ts # File-specific encryption handling
β β β βββ keys.ts # Key derivation (PBKDF2 β AES key pair)
β β βββ storage/
β β β βββ pinStorage.ts # PIN-encrypted localStorage key storage
β β β βββ ram.ts # In-memory private key store
β β βββ utils.ts # Tailwind class merge utilities
β β
β βββ router/
β β βββ AppRouter.tsx # Routes + PrivateRoute guard
β β
β βββ store/ # Global State (Zustand)
β β βββ lockStore.ts # App lock state + timeout setting
β β βββ sessionStore.ts # User session (userId, username, publicKey)
β β βββ themeStore.ts # Light/dark mode state
β β
β βββ App.css # Global styles
β βββ App.tsx # Root β Convex provider, theme, lock
β βββ main.tsx # React entry point
β βββ vite-env.d.ts # Vite environment types
β
βββ .env # Local environment variables
βββ .env.local # Convex local deployment URL
βββ .env.production # Convex production deployment URL
βββ .gitignore # Git ignore rules
βββ components.json # shadcn/ui configuration
βββ convex.json # Convex project configuration
βββ index.html # Main HTML entry point
βββ LICENSE # Open source license
βββ package-lock.json # NPM dependency lockfile
βββ package.json # NPM dependencies & scripts
βββ README.md # Project documentation
βββ tsconfig.json # TypeScript base configuration
βββ tsconfig.node.json # Node environment TypeScript config
βββ updater.json # Tauri auto-updater endpoint configuration
βββ vite.config.ts # Vite bundler configuration
You will need:
- Node.js v20+
- Rust stable toolchain
- A free Convex account
git clone https://github.com/miangee21/ciphra.git
cd ciphra
npm installIn Terminal 1, start the Convex dev server:
npx convex dev- You will be prompted to log in to Convex (browser opens)
- Select Create a new project, name it
ciphraor anything you like - Convex automatically creates
.env.localin your project root with your dev deployment URL
In Terminal 2, start the Tauri dev build:
npx tauri devThe app window will open. Create an account, add folders, create documents β everything is fully functional in development mode.
- Go to your Convex Dashboard
- Open your project β click the Production tab
- Under Settings, copy these values:
- Production Deploy Key β looks like
prod:f... - Convex URL β looks like
https://f***.convex.cloud
- Production Deploy Key β looks like
- Create
.env.productionin your project root:
VITE_CONVEX_URL="https://f*********************.convex.cloud"Tauri requires all distributed builds to be cryptographically signed. Generate your key pair:
npx tauri signer generateYou will be prompted to set a password β choose a strong one and save it somewhere safe.
Create .env in your project root:
TAURI_SIGNING_PRIVATE_KEY="your_private_key_here"
TAURI_SIGNING_PRIVATE_KEY_PASSWORD="your_password_here"Important: Add
.envto your.gitignore. Never commit your signing private key to version control.
| File | Purpose | Created by |
|---|---|---|
.env.local |
Dev Convex deployment URL | Convex CLI (auto-generated in Step 2) |
.env.production |
Production Convex URL | You (Step 4) |
.env |
Tauri signing keys | You (Step 5) |
- Node.js v20+
- Rust stable toolchain β run
rustup update stable - Linux only: install system libraries first:
# Ubuntu / Debian
sudo apt install libwebkit2gtk-4.1-dev libssl-dev libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev
# Fedora
sudo dnf install webkit2gtk4.1-devel openssl-devel gtk3-devel libappindicator-gtk3-devel librsvg2-develOpen PowerShell in the project root. Run these commands in order:
# 1. Deploy Convex schema and functions to production
$env:CONVEX_DEPLOY_KEY="prod:f**********************************"
npx convex deploy
# 2. Set signing key environment variables
$env:TAURI_SIGNING_PRIVATE_KEY="your_private_key_here"
$env:TAURI_SIGNING_PRIVATE_KEY_PASSWORD="your_password_here"
# 3. Build the app
npx tauri buildOutput files (inside src-tauri/target/release/bundle/):
| File | Description |
|---|---|
msi/Ciphra_x.x.x_x64_en-US.msi |
Windows Installer package |
nsis/Ciphra_x.x.x_x64-setup.exe |
NSIS installer executable |
The Convex production deployment only needs to be done once. If you already ran npx convex deploy on Windows, skip that step here.
Open a terminal in the project root:
# 1. Set signing key environment variables
export TAURI_SIGNING_PRIVATE_KEY="your_private_key_here"
export TAURI_SIGNING_PRIVATE_KEY_PASSWORD="your_password_here"
# 2. Build the app
npx tauri buildIf you encounter AppImage build errors, use this alternative command:
NO_STRIP=1 APPIMAGE_EXTRACT_AND_RUN=1 npm run tauri buildOutput files (inside src-tauri/target/release/bundle/):
| File | Description |
|---|---|
appimage/ciphra_x.x.x_amd64.AppImage |
Universal Linux portable app |
deb/ciphra_x.x.x_amd64.deb |
Debian / Ubuntu package |
rpm/ciphra-x.x.x-1.x86_64.rpm |
Fedora / openSUSE / RHEL package |
Made with β€οΈ by Hassan