Skip to content

Privacy, storage, and sync

PlebChat is local-first, not local-only. Different actions send different data to relays, Blossom servers, AI providers, and web-research services.

Stored on this device

PlebChat uses the browser's IndexedDB storage for work associated with the active Nostr identity.

New content starts on this device only. This applies to:

  • chats;
  • folders, files, and workspaces (these never sync);
  • books, PDFs, and reading state;
  • feeds and bookmarks;
  • debates.

Use an item's menu and select Sync with relays when you want that item on your other devices. Folders and files have no sync yet — export what matters.

Clearing site data, private browsing, or device loss can remove local work. Enable sync or export important work.

On iPhone, a Home Screen install is a separate store from the Safari tab. Sign in and sync to restore work.

Encrypted relay sync

Account settings, provider credentials, personality prompts, skills, favorites, and reading preferences sync automatically after sign-in. Relay and Blossom server lists stay on each device because they are needed to start sync.

Enabled content also syncs automatically after each local save. PlebChat encrypts private sync records to your own Nostr key before publication. Relays receive ciphertext, signatures, timestamps, and lookup tags. They do not receive the plaintext from PlebChat.

Encryption protects content but not all metadata. A relay or network observer may infer that a key connected, when events changed, and roughly how large they are.

Sync work stays in a durable queue during connection failures. The app shows failed records and conflicts. It never resolves edits from two devices by silently selecting the newest clock.

Stop syncing

Select Stop syncing in the item menu to keep the local copy and stop future sync. PlebChat publishes encrypted tombstones and sends NIP-09 deletion requests for relay copies.

Relay deletion is best-effort. A relay can ignore the request, and another party can keep a copy. Treat data sent to a relay as data that can remain there.

Blossom file backup

Some imported book files can back up to a Blossom server. A Blossom server stores blobs addressed by their content hash. Treat server choice and upload visibility separately from encrypted Nostr metadata.

Public sharing

Publishing a shelf item, annotation, article, debate, or shared folder is intentionally different from private sync. Public events are signed so others can verify the author and read the content. A shared folder also uploads file bytes to Blossom. Those bytes are public by hash.

Assume public data can be copied permanently. Deleting it or switching an item back to private cannot retract copies held by relays or readers.

AI and research services

When you ask an AI model for help, the selected provider receives the request content needed to answer it. The built-in provider routes that request through the PlebChat paygate. A provider you configure receives it directly.

Web search and page reading send queries or URLs to Firecrawl when enabled. An RSS proxy can see the feed URLs routed through it.

PlebChat's local-first design does not make these external calls private from the services you chose.

Incognito

Incognito applies only to Chat. It keeps the active conversation, sources, and draft in memory. It never saves or syncs that conversation. It disappears on refresh, close, or leaving Incognito.

Incognito does not pause account sync or other enabled content. It also does not stop the selected AI or research provider from receiving requests you send.