版本与升级(桌面端)Versions and upgrades (desktop)
- 备份设置页导出一份备份(或加密备份),确认能导入。
- 覆盖安装下载新版安装包直接安装;数据目录
%LocalAppData%\Novara\不受影响。安装器的「保留 / 删除数据」选择保持默认保留。 - 验证打开后检查数据完整、搜索可用、隐私锁密码照旧生效。
- Back upExport a backup from settings (or an encrypted one) and confirm it imports.
- Install overDownload the new installer and install directly; the data directory
%LocalAppData%\Novara\is unaffected. Keep the installer's "keep / delete data" choice on its default, keep. - VerifyAfter opening, check the data is intact, search works, and the privacy-lock password still applies.
- 旧导出的明文备份与
.novaenc在新版本中照常可导入。 - 回滚桌面端 = 重装旧版安装包,数据目录不动。
- Plaintext backups and
.novaencfiles from older versions import normally into the new one. - Rolling back the desktop = reinstall the older installer; the data directory is untouched.
这是什么What is Novara
一句话定义
One-sentence definition
Novara 是一款本地优先的个人数据管理工具(Windows 桌面应用):你的备忘、文件路径、待办与记录都存在一台电脑上的一个文件里,想加密就加密,想带出门就用下面两种方式——而这两种方式都不经过任何人的服务器。
Novara is a local-first personal data manager (a Windows desktop app): your memos, file paths, to-dos and records live in a single file on one computer, encrypted when you want them to be, portable when you need them to be — and neither of the two ways out below ever touches anyone else's server.
四个页面
The four pages
| 页面 | 管什么 |
|---|---|
| 备忘 | 分组管理账号 / 密码 / API Key / 银行卡 / WiFi 等条目,敏感字段掩码、TOTP 动态码、连通检测 |
| 文件路径 | 登记常用文件与文件夹,一键打开、有效性绿红标识 |
| 计划 | 待办(主/子勾选联动)与便签;便签可发送到桌面成为独立窗口 |
| 记录 | 富文本日记 + Markdown 文档,编辑 / 预览切换 |
| Page | What it manages |
|---|---|
| Memo | Grouped entries for accounts / passwords / API keys / bank cards / WiFi, with masked sensitive fields, TOTP codes and reachability checks |
| File paths | Register frequently used files and folders; one-click open with a green/red validity marker |
| Plans | To-dos (parent/child check linkage) and sticky notes; a note can be sent to the desktop as an independent window |
| Records | Rich-text journal + Markdown documents, with an edit / preview switch |
三种把数据带出去的方式
Three ways to take data out
- 本地库——一切的基础:单文件
data.novadb,开启隐私锁后 AES-256-GCM 加密。 - 安全快照(Snapshot)——导出一个加密、只读的单文件网页,扔到任意静态托管或双击即开。适合"看一眼"与分享。
- 互联同步——把你自己的一台机器变成密文中转站,手机浏览器可查看甚至编辑。适合持续使用第二块屏幕。
- Local vault — the foundation of everything: a single
data.novadbfile, AES-256-GCM encrypted once the privacy lock is on. - Secure snapshot — export an encrypted, read-only single-file web page; drop it on any static host or double-click it open. Built for "quick look" and sharing.
- Encrypted sync — turn one of your own machines into a ciphertext relay; your phone's browser can view and even edit. Built for continuously using a second screen.
两者都不需要官方参与:快照是静态文件,同步的服务器是你自己部署的。详解在安全篇与互联同步篇。
Neither path needs any official involvement: a snapshot is a static file, and the sync server is one you deploy yourself. Details in the security and sync guides.
还有什么
What else is inside
- 隐私锁:可选;密码 + Windows Hello,AES-256-GCM 加密,连错 5 次冷却 30 分钟。
- MCP 接口:让本机 AI 助手在你逐项授权下读写数据,敏感字段脱敏、调用全审计。
- 命令面板:Ctrl+K 搜索全部数据区,
>前缀直达命令。 - 桌面便签:计划页便签可发送到桌面,成为独立小窗口。
- 五语言与浅色 / 深色 / 跟随系统主题(切换后重启生效)。
- Privacy lock: optional; password + Windows Hello, AES-256-GCM encryption, 30-minute cooldown after 5 failed attempts.
- MCP interface: lets a local AI assistant read and write data under per-item permissions, with sensitive fields masked and every call audited.
- Command palette: Ctrl+K searches every data area; a
>prefix jumps straight to commands. - Desktop sticky note: a note from the Plans page can be sent to the desktop as an independent mini window.
- Five languages and light / dark / follow-system themes (a restart applies the change).
不做什么
What it does not do
- 不运营任何接收明文资料的官方云——没有"Novara 账号"这种东西。
- 不收集遥测,不要求联网才能用核心功能。
- 不替你保管锁密码:忘记密码没有任何后门,只能清空重建(见安全篇)。
- 不把你的数据交给第三方:联网能力只有你主动触发的 API 检测与你自己部署的同步。
- It runs no official cloud that accepts plaintext — there is no such thing as a "Novara account".
- No telemetry collection; core features never require an internet connection.
- It does not keep your lock password for you: a forgotten password has no backdoor — the only way back is a full reset (see the security guide).
- It does not hand your data to third parties: the only networking is the API checks you trigger yourself and the sync server you deploy yourself.
100% 离线不是口号而是默认态:不开同步、不做快照导出,Novara 就是一台电脑上的一个加密文件。
Fully offline is the default state, not a slogan: with sync off and no snapshot exported, Novara is just one encrypted file on one computer.
安装与第一次打开Install and first launch
下载与校验
Download and verify
安装包从 GitHub Releases 或本站镜像获取(下载页有两个来源与 SHA-256)。安装前建议核对校验值:
Get the installer from GitHub Releases or this site's mirror (the download page lists both sources and the SHA-256). Verifying the hash before installing is recommended:
certutil -hashfile Novara_Setup_9.2.0.exe SHA256桌面端面向 Windows x64,最低 Windows 10 2004(build 19041);.NET 运行时已内嵌,不需要另装。
The desktop app targets Windows x64, at minimum Windows 10 2004 (build 19041); the .NET runtime is embedded — nothing else to install.
安装
Install
双击安装包按向导完成。默认安装到 Program Files\Novara;安装目录下的 Sync\ 文件夹是随包自带的同步服务端(想用互联同步时会用到,见自建服务端篇)。
Double-click the installer and follow the wizard. It installs to Program Files\Novara by default; the Sync\ folder inside the install directory is the bundled sync server (you will use it if you turn on encrypted sync — see the self-hosting guide).
在已有数据的机器上覆盖安装(升级)时,安装器会让你二选一,这个选择值得看清楚:
When you install over an existing installation (an upgrade), the installer asks you to pick one of two options — and this choice is worth reading carefully:
| 选项 | 后果 |
|---|---|
| 保留数据(默认) | %LocalAppData%\Novara\ 原样不动,装完打开数据都在 |
| 删除数据 | 清空本地库——需要手动输入 RESET 确认,防止手滑 |
| Option | Consequence |
|---|---|
| Keep data (default) | %LocalAppData%\Novara\ is untouched; everything is there when you open the app |
| Delete data | Wipes the local vault — requires typing RESET manually to confirm, so a slip cannot do it |
全新安装不会出现这个选择,也没有任何数据可删。
A fresh install never shows this choice and has no data to delete.
数据都在哪
Where everything lives
| 内容 | 位置 |
|---|---|
| 主数据库 | %LocalAppData%\Novara\data.novadb |
| 锁凭据与密码哈希 | %LocalAppData%\Novara\security.dat |
| 滚动自动备份 | %LocalAppData%\Novara\backups\(最近 10 份) |
| 服务端数据(如启用) | %LocalAppData%\Novara\Server\data——与桌面库完全独立 |
| Content | Location |
|---|---|
| Main database | %LocalAppData%\Novara\data.novadb |
| Lock credentials & password hash | %LocalAppData%\Novara\security.dat |
| Rolling automatic backups | %LocalAppData%\Novara\backups\ (last 10 kept) |
| Server data (if enabled) | %LocalAppData%\Novara\Server\data — fully independent of the desktop vault |
设置页刻意不提供更改存储路径的入口:路径可预期是安全模型的一部分,杀软白名单与备份脚本也因此简单。
The settings page deliberately offers no way to change these paths: a predictable path is part of the security model, and it keeps antivirus whitelisting and backup scripts simple.
第一次打开之后
After the first launch
- 首启导览:第一次打开会出现几页真实界面的导览卡,点完即止,不注册不联网。
- 开机自启:设置页可开;关掉后需要手动打开。
- 主题与语言:浅色 / 深色 / 跟随系统,中 / 繁 / 英 / 한 / 日五语言——切换后重启生效。
- 托盘:默认直接退出,可选驻留托盘(关闭窗口 = 缩到托盘)。
- 隐私锁:默认关闭;决定开启时先读《隐私锁与解锁》。
- First-run tour: the first launch shows a few tour cards built from real screens; click through and you are done — no sign-up, no network.
- Launch at startup: available in settings; once off, you open Novara manually.
- Theme & language: light / dark / follow system; five languages (Simplified Chinese, Traditional Chinese, English, 한국어, 日本語) — a restart applies the change.
- Tray: the app exits directly by default; optionally it can stay in the tray (closing the window minimizes to the tray).
- Privacy lock: off by default; read "The privacy lock" before turning it on.
装好就绪了。想动手体验,直接去《五分钟上手》。
Installation is done. To try things hands-on, jump straight to "First five minutes".
五分钟上手First five minutes
1 · 记下第一条备忘
1 · Create your first memo
- 新建分组备忘页空白处右键(或右下角按钮)新建一个分组,起个名字、选个图标。
- 新建条目分组内点「添加信息」,类型选「账户」或「API Key」,填字段后确认——内容实时自动落盘,没有保存按钮。
- 体验掩码给条目加一个 label 为「密码」的字段:列表里它显示为
••••••••,点击才显示明文。 - 试一下复制字段行右侧的复制按钮一键复制;置顶、星标在右键菜单里。
- New groupRight-click empty space on the Memo page (or use the bottom-right button) to create a group; give it a name and an icon.
- New entryInside the group click "Add entry", pick the "Account" or "API key" type, fill in the fields and confirm — content is saved to disk in real time; there is no save button.
- Try maskingAdd a field labelled "Password" to the entry: in the list it shows as
••••••••and only reveals the plaintext when clicked. - Try copyingThe button on the right of each field row copies it in one click; pin and star live in the right-click menu.
2 · 开启隐私锁
2 · Turn on the privacy lock
- 进入设置设置页 → 隐私访问锁 → 开启。
- 设置密码至少 6 位(建议更强)。开启的瞬间整库以 AES-256-GCM 重新加密写盘。
- 试一次锁定手动锁定(快捷键或设置内),锁屏出现;用密码解锁回来。装了 Windows Hello 的机器还能刷脸 / 指纹。
- Open settingsSettings page → Privacy access lock → Enable.
- Set a passwordAt least 6 characters (stronger is recommended). The moment you enable it, the whole vault is re-encrypted with AES-256-GCM and written to disk.
- Try lockingLock manually (shortcut or from settings); the lock screen appears; unlock with your password. On machines with Windows Hello you can also use face / fingerprint.
这个密码没有找回渠道——忘记 = 清空重建。开锁前先把它记进你信任的密码管理器。
This password has no recovery path — forgetting it means a full reset. Before locking anything, store it in a password manager you trust.
3 · 导出第一份安全快照
3 · Export your first secure snapshot
- 打开导出设置 → 互联卡片 → Snapshot 导出。
- 选口令勾选「复用隐私锁密码」,或设一个独立口令(两次一致)。导出物永远是密文——不存在明文快照这条路。
- 得到文件得到一个自包含的
index.html:查看器与密文都在里面。 - 验证把文件传到手机(或任意电脑)双击打开,输入口令——四分区数据只读呈现,刷新需重新输入口令。
- Open exportSettings → Connection card → Snapshot export.
- Pick a passphraseTick "Reuse the privacy-lock password", or set an independent passphrase (entered twice). The export is always ciphertext — there is no plaintext-snapshot path.
- Get the fileYou get a self-contained
index.html: viewer and ciphertext in one file. - VerifySend the file to your phone (or any computer), double-click it, enter the passphrase — all four data areas appear read-only; refreshing asks for the passphrase again.
到这里你已经用上了 Novara 的全部三种形态:本地库(权威)、隐私锁(加密)、快照(带出门)。
At this point you have used all three Novara forms: the local vault (authoritative), the privacy lock (encryption), and the snapshot (portable).
之后
Where to next
- 想在手机上随时看、还要能改 → 部署互联同步,从《互联同步是什么》开始。
- 想把数据在另一台电脑还原 → 看《备份与还原》。
- 让 AI 助手帮你记东西 → 看MCP 与 AI 助手指南。
- 日常顺手记东西 → 试试全局快速捕获热键与 Ctrl+K 命令面板。
- Want your phone to see the data any time and edit it too → deploy encrypted sync, starting with "What is encrypted sync".
- Want to restore the data on another computer → see "Backup and restore".
- Want an AI assistant to help you record things → see the MCP and AI assistants guide.
- For everyday capture → try the global quick-capture hotkey and the Ctrl+K command palette.
常见问题
FAQ
快照在浏览器里打不开,提示加密能力?
说明页面不是安全上下文:file:// 下换现代浏览器(Chrome / Edge / Firefox),或把文件放到 HTTPS 静态托管打开。
搜索搜不到刚存的密码?
正常:敏感字段(密码、卡号等)不参与搜索——见《搜索与命令面板》。按条目名称或备注找。
需要立刻部署同步服务端吗?
不需要。本地功能零依赖;什么时候需要跨设备,什么时候再部署(自建服务端篇从零开始讲)。
The snapshot will not open in the browser and mentions encryption?
That means the page is not a secure context: under file:// switch to a modern browser (Chrome / Edge / Firefox), or put the file on HTTPS static hosting.
Search cannot find the password I just saved?
That is by design: sensitive fields (passwords, card numbers, etc.) are excluded from search — see "Search and the command palette". Search by the entry name or its notes instead.
Do I need to deploy a sync server right away?
No. Local features have zero dependencies; deploy whenever you actually need cross-device access (the self-hosting guide starts from zero).
备忘Memo
分组与条目
Groups and entries
用分组整理:空白处或右下角按钮新建,可改名、选图标。分组内「添加信息」新建条目,类型决定字段的形状:
Organize with groups: create one from empty space or the bottom-right button; rename and pick an icon any time. Inside a group, "Add entry" creates an entry; the type decides the shape of its fields:
- 邮箱 / 账户 / 网站 / WiFi —— 地址与账号类信息
- API Key —— 密钥与其端点
- 银行卡 / 证件 —— 卡号、证件号自动进掩码档
- 自定义 —— 字段随意组合
- Email / Account / Website / WiFi — address and credential items
- API key — the key and its endpoint
- Bank card / ID — card and ID numbers are masked automatically
- Custom — combine fields freely
条目由若干字段行组成,每行右侧有复制按钮;折叠态副标题自动取该类型的关键信息(如银行卡取卡号——同样会掩码)。
An entry is a list of field rows, each with a copy button on the right; the collapsed subtitle automatically shows the key information for the type (a bank card shows its number — masked, of course).
敏感字段掩码
Sensitive field masking
label 为密码 / 邮箱密码 / CVV / API Key / 卡号 / 证件号(及若干无歧义英文别名)的字段,在列表与搜索结果里一律显示为固定 8 个圆点 ••••••••——不随原值长度变化,连长度都不泄露。点击才显示明文。
Fields labelled password / email password / CVV / API key / card number / ID number (plus a few unambiguous English aliases) always display as exactly eight dots •••••••• in lists and search results — the length never varies, so not even the length leaks. Click to reveal the plaintext.
掩码规则是全程序唯一一份:列表页、搜索页、回收站、MCP 读取共用同一判断,不存在"列表里是点、搜索里是明文"的分叉。不认识的自定义 label 不会被掩码——宁可少掩,不误掩普通内容。
The masking rule is the single one in the whole program: list page, search page, trash and MCP reads all share the same decision. There is no fork where "the list shows dots but search shows plaintext". Unrecognized custom labels are not masked — under-masking beats falsely masking ordinary content.
API Key 检测连通性
API key reachability check
API Key 类型条目右键有检测入口,三个档位按需使用(消耗 token 的会先弹确认):
API key entries have a check entry in the right-click menu, in three tiers (anything that spends tokens asks for confirmation first):
| 入口 | 开销 | 告诉你什么 |
|---|---|---|
| 接口连通检测 | 0 token | 地址、密钥、协议配置是否正确 |
| 接口状态诊断 | 1~3 个请求 | 可达性 + 余额推断 + 元数据 + 延迟 |
| 中转站探针检测 | 十余个请求 | 8 项探针加权评分,四级判定 |
| Check | Cost | What it tells you |
|---|---|---|
| Endpoint connectivity | 0 tokens | Whether the address, key and protocol configuration are correct |
| Endpoint status diagnostics | 1–3 requests | Reachability + balance inference + metadata + latency |
| Relay probe | A dozen or so requests | 8 weighted probes with a four-level verdict |
检测只向条目自己配置的第三方端点发起请求,Novara 不经手、不代理这些流量。
Checks send requests only to the third-party endpoint configured on that entry; Novara never touches or proxies this traffic.
TOTP 动态码
TOTP one-time codes
邮箱 / 账户 / 网站 / WiFi 四类条目可以绑定两步验证密钥:卡片展开区实时跳动 6 位动态码,可一键复制当前码。密钥同样受掩码与加密保护,快照与手机端照样能算——纯本地 RFC 6238,不看时间以外的一切。
Email / account / website / WiFi entries can bind a two-factor secret: the expanded card shows a live 6-digit code, one click to copy the current one. The secret gets the same masking and encryption, and snapshots and the phone can still compute codes — pure local RFC 6238, touching nothing but time.
跨分组搜索
Search across groups
顶部搜索框跨分组检索;更全的入口是 Ctrl+K 命令面板(见《搜索与命令面板》)。敏感字段值不参与匹配——拿卡号片段当关键词是搜不出东西的,这是保护边界而不是索引故障。
The top search box searches across groups; the fuller entry point is the Ctrl+K command palette (see "Search and the command palette"). Sensitive field values never match — searching a fragment of a card number finds nothing, and that is a protection boundary, not an indexing bug.
文件路径File paths
收藏路径
Pinning paths
添加文件或文件夹路径作为条目。它存的是路径而不是文件本身——不复制、不占用空间,只是登记一条"去这里的快捷方式"。
Add a file or folder path as an entry. It stores the path, not the file — nothing is copied, no space is used; it is a registered "shortcut to go there".
常见用法:在做的项目文件夹、每周要交的报表、公司制度的 PDF、NAS 上的共享目录——任何"每次都要翻三层目录才找到"的位置,都值得登记进来。
Typical uses: the project folder you are working in, the report you submit weekly, the company policy PDF, a NAS share — anywhere you would otherwise dig through three levels of directories is worth registering.
「打开」的行为
What "Open" does
点「打开」会启动文件管理器并选中该文件(文件夹则直接进入)。不是"打开文件内容",而是"把那个文件在资源管理器里亮给你"——方便接着拖拽、发邮件或压缩。
Clicking "Open" starts the file manager with that file selected (folders open directly). It does not "open the file's contents" — it highlights the file in Explorer, ready to drag, attach or compress.
右键还可以复制路径,把完整路径文本交给别的程序用。
Right-click also offers copy path, handing the full path text to other programs.
有效性检测
Validity check
| 状态 | 含义 |
|---|---|
| 绿边框 | 路径当前存在 |
| 红边框 | 路径已失效(被移动、删除或设备不可达) |
| State | Meaning |
|---|---|
| Green border | The path currently exists |
| Red border | The path is broken (moved, deleted, or the device is unreachable) |
检测时机:程序启动时、新建条目后、以及每 30 分钟自动重检。也就是说状态基本总是新鲜的,不需要手动刷新。
Check timing: at app start, after creating an entry, and an automatic re-check every 30 minutes. The status is essentially always fresh — no manual refresh needed.
状态只是提示,不会自动删除失效条目:移动硬盘没插上时红一下是正常的,插回来它会自己变绿。真要清理,右键删除——进垃圾桶,可恢复。
The status is only a hint and never auto-deletes a broken entry: a red flash while an external drive is unplugged is normal; plug it back and it turns green on its own. To really clean up, right-click delete — it goes to the trash, recoverable.
右键操作
Right-click actions
复制路径、打开、置顶、星标、编辑、删除——与其他页面同一套通用操作(见《通用操作》)。置顶的路径会排在这一页最前面,适合正在推进的项目。
Copy path, open, pin, star, edit, delete — the same common actions as every page (see "Common actions"). Pinned paths sort to the top of this page, ideal for active projects.
什么时候用路径而不是备忘
Path or memo?
- 内容是一个位置(文件夹、文件、网络共享)→ 路径备份:能一键打开、有绿红状态。
- 内容是一段信息(网址、账号、说明)→ 备忘:有掩码、有字段结构。
- 路径条目只存路径文本,不含文件内容——删除它不影响文件本身。
- The content is a location (folder, file, network share) → a path entry: one-click open plus the green/red state.
- The content is a piece of information (URL, account, note) → a memo: masking and field structure.
- A path entry stores only path text, never file contents — deleting it never touches the file itself.
路径条目也能进工作区:把项目文件夹和相关的备忘、待办聚合在同一个工作区里。
Path entries can join a workspace too: group a project folder with its related memos and to-dos under one workspace.
常见问题
FAQ
「打开」没有反应?
确认路径仍然有效(绿边框)。路径指向的网络位置不可达或移动盘未挂载时,打开会失败——先看边框颜色。
路径失效会被自动清理吗?
不会。失效只是状态提示,条目保留,等你确认位置是临时不可达还是真的没了。
能收藏网络位置吗?
可以。UNC 路径(\\服务器\共享)与映射盘符都能登记,有效性检测按同样的节奏工作。
"Open" does nothing?
Check that the path is still valid (green border). When a network location is unreachable or a removable drive is unmounted, opening fails — check the border color first.
Are broken paths cleaned up automatically?
No. A broken state is only a status hint; the entry stays until you decide whether the location is temporarily unreachable or truly gone.
Can I pin network locations?
Yes. UNC paths (\\server\share) and mapped drive letters both work, and the validity check runs on the same rhythm.
计划与便签Plans and sticky notes
待办:主/子勾选联动
To-dos: parent/child check linkage
- 子待办全部勾选 → 主待办自动勾选,卡片自动折叠(可重新展开)。
- 取消任意子待办 → 主待办同步取消,卡片展开。
- 主待办也可以独立存在——没有子待办时它就是一张普通卡片。
- All sub-tasks checked → the parent checks itself and the card auto-collapses (you can re-expand it).
- Any sub-task unchecked → the parent unchecks in sync and the card expands.
- A parent can exist on its own — with no sub-tasks it is just a regular card.
列表支持拖拽排序,按当天的心情安排顺序;置顶与星标照常可用。
The list supports drag to reorder, so arrange the day as you like; pin and star work as everywhere.
计划页标签右侧的箭头可以按「混合 / 待办 / 便签」筛选,列表立刻只显示对应卡片;筛选视图下拖拽被禁用,避免排序错乱。
The arrow next to the Plans page tabs filters by "mixed / to-dos / notes"; the list instantly shows only matching cards. Dragging is disabled in a filtered view to keep ordering consistent.
便签
Sticky notes
便签记录一段文字,内容超长可展开查看。内容与待办一样实时自动保存。
A note holds a stretch of text; overly long content can be expanded in place. Notes auto-save in real time just like to-dos.
桌面便签是独立窗口:在便签卡片上点「发送到桌面」,它会以独立小窗常驻桌面(由独立进程承载,主程序最小化也不受影响)。
A desktop note is an independent window: click "Send to desktop" on a note card and it lives on the desktop as its own mini window (backed by a separate process, unaffected when the main app is minimized).
桌面便签适合"今天必须记得的三件事"这类内容——始终在视野里,不用打开主程序。
Desktop notes suit things like "three things I must remember today" — always in view, no need to open the main app.
提醒
Reminders
待办与便签都能设置提醒:右键 → 设置提醒,弹窗里只选日期和时间。确认后卡片边框会随剩余时间从绿渐变到红,一眼看出哪件事快到点了。
To-dos and notes can both set reminders: right-click → Set reminder, then pick a date and time in the dialog. Once confirmed, the card border fades from green to red as the deadline approaches — you can see at a glance what is due.
到点时:弹出提醒卡片(内容 + 知道了按钮)并发出系统 Toast 通知,只弹一次。取消提醒走二次确认,边框复原。
When it fires: a reminder card pops (content + a "Got it" button) and a system toast is sent, once. Cancelling goes through a double confirmation and the border returns to normal.
删除与恢复
Delete and restore
删除的待办/便签进入垃圾桶,可恢复回原位置;彻底删除才真正移除(见《垃圾桶与恢复》)。同步开启时,删除同样会同步到手机端。
Deleted to-dos/notes go to the trash and can be restored to their original spot; only "delete permanently" truly removes them (see "Trash and restore"). With sync on, deletions reach the phone too.
右键菜单一览
Right-click menu reference
| 动作 | 效果 |
|---|---|
| 编辑 | 打开卡片编辑弹窗(标题、内容、子待办、图标) |
| 置顶 / 星标 | 排序与标记,与其他页面一致 |
| 设置提醒 / 取消提醒 | 按卡片当前有无提醒显示对应项 |
| 发送到桌面(便签) | 把这条便签变成独立桌面窗口 |
| 删除 | 软删除,进垃圾桶 |
| Action | Effect |
|---|---|
| Edit | Opens the card edit dialog (title, content, sub-tasks, icon) |
| Pin / star | Sorting and marking, same as other pages |
| Set reminder / cancel reminder | Shows whichever matches whether the card currently has one |
| Send to desktop (notes) | Turns this note into an independent desktop window |
| Delete | Soft delete, goes to the trash |
常见问题
FAQ
子待办全部勾完,主待办没反应?
会自动勾选并折叠。若主待办看起来未勾选,多半是之前手动取消过它——重新勾一次即可,之后联动照常。
桌面便签的内容和主程序里的便签是同一条吗?
是。「发送到桌面」只是把它显示成独立窗口,数据仍在计划页里,删除也走垃圾桶。
提醒到点时程序没开会怎样?
提醒由系统计划任务承载,到点会拉起 Novara 弹出提醒——不是必须一直开着程序才能收到。
All sub-tasks are checked but the parent did not react?
It checks and collapses automatically. If the parent looks unchecked, it was probably manually unchecked earlier — tick it once more and linkage resumes.
Is the desktop note the same item as the note in the app?
Yes. "Send to desktop" only displays it as an independent window; the data still lives on the Plans page and deleting it goes through the trash.
What if the app is not running when a reminder fires?
Reminders are carried by a scheduled task in the system — Novara is launched to show the reminder. The app does not need to stay open.
日记与 MarkdownRecords and Markdown
富文本日记
Rich-text journal
点「新建日记」打开编辑器,支持加粗 / 斜体 / 下划线 / 文字颜色,可以插入图片。两种格式都由内嵌的网页编辑器承载,写起来和熟悉的文档编辑器一致。
Click "New journal entry" to open the editor: bold / italic / underline / text color, and images can be inserted. Both formats run on the embedded web editor, so it feels like the document editor you already know.
编辑器下方的胶囊工具栏有两态,这是最常被问到的行为:
The pill toolbar below the editor has two states — the behavior people ask about most:
| 操作 | 效果 |
|---|---|
| 选中文字后点 B / I / U | 即时改变当前选中的文字 |
| 不选中直接点 B / I / U | 设置接下来输入的文字保持该格式 |
| Action | Effect |
|---|---|
| Select text, then click B / I / U | Changes the current selection immediately |
| Click B / I / U with nothing selected | Makes what you type next carry the format |
Markdown 文档
Markdown documents
新建文档得到一条 Markdown 记录:纯文本编辑 + 实时预览切换(Write ↔ Preview),写的时候就能看到 # 渲染成的标题。列表徽标显示「文档」以区别于「日记」。
A new document is a Markdown record: plain-text editing with a live preview switch (Write ↔ Preview), so you see # become a heading as you type. The list badge shows "Document" to distinguish it from "Journal".
| 规则 | 说明 |
|---|---|
| 导入格式 | .md / .markdown,文件名成为标题 |
| 编码 | 严格 UTF-8 |
| 大小上限 | 2 MiB |
| 图片 | 本地图片路径按文本保留,不解析不内联 |
| Rule | Detail |
|---|---|
| Import formats | .md / .markdown; the file name becomes the title |
| Encoding | Strict UTF-8 |
| Size limit | 2 MiB |
| Images | Local image paths are kept as text — not resolved, not inlined |
文档编辑的是标题 + 正文;保存修改时间,列表排序随之更新。
A document edits title + body; saving updates the modified time and the list re-sorts accordingly.
导出也是明确的:日记可「导出 MD(含图片 / 无图片)」(有损转换);文档只「导出 Markdown(原文)」(无损)。日记与文档不做双向转换——两个方向都有损,格式跳变会带来一连串复杂度。
Export is explicit too: a journal can "export MD (with / without images)" (a lossy conversion); a document only "exports Markdown (as-is)" (lossless). Journals and documents are never converted into each other — both directions lose information, and a format jump drags a chain of complexity behind it.
列表排序与筛选
List ordering and filtering
列表按「置顶优先 + 修改时间倒序」排列,支持拖拽调整顺序;标签箭头可按混合 / 日记 / 文档筛选。所有记录共享时间线回顾,旧日记按时间回看很方便。
The list orders by "pinned first, then modified time descending", with drag to reorder; the tab arrow filters mixed / journal / document. All records share the timeline review, handy for looking back at older journals.
删除
Deletion
删除记录进入垃圾桶,不会立刻物理擦除;同步开启时删除以墓碑形式同步到手机端,正常列表会过滤掉它们。
Deleted records go to the trash and are not physically erased right away; with sync on, deletions travel to the phone as tombstones and normal lists filter them out.
常见问题
FAQ
Markdown 导入失败了?
按三个方向查:扩展名是不是 .md / .markdown;文件是不是严格 UTF-8 编码;是否超过 2 MiB。三者都满足才能导入。
导入的文档里图片怎么没显示?
本地图片路径按文本保留,不解析不内联——导入的是文档文字本身。图片信息在路径文本里,可自行取用。
能把日记转成文档吗?
不做双向转换:HTML 到 Markdown 有损、Markdown 到 HTML 也有损,格式跳变会带来编辑器、徽标、搜索一串连锁问题。需要的话用「导出 MD」拿到 Markdown 原文。
Markdown import failed?
Check three things: is the extension .md / .markdown; is the file strictly UTF-8; is it within 2 MiB. All three must hold.
Why do images in the imported document not show?
Local image paths are kept as text, not resolved or inlined — what was imported is the document's text. The image information is in the path text, ready to use.
Can I convert a journal into a document?
No conversion in either direction: HTML → Markdown is lossy, and so is Markdown → HTML; a format jump drags the editor, badges and search into a chain of problems. If you need it, use "export MD" to get the Markdown source.
垃圾桶与恢复Trash and restore
软删除
Soft delete
备忘、路径、待办/便签、记录——四个页面统一使用软删除:删除的条目进入垃圾桶并保留在数据库中,随时可以反悔。误删的代价被压到最低。
Memo, paths, to-dos/notes, records — all four pages use soft delete: deleted entries move to the trash and stay in the database, reversible at any time. The cost of a mistake is kept as low as possible.
手机端与快照里的正常列表会过滤这些条目——"手机上看不到回收站内容"是设计,不是同步漏了。
Normal lists on the phone and in snapshots filter these entries — "the phone does not show trash contents" is by design, not a missed sync.
一个例外要知道:备忘的分组删除直接生效,不走墓碑通道(分组本身没有删除标记字段),分组内的条目仍各自按软删除处理。
One exception to know: deleting a memo group takes effect immediately and does not go through the tombstone path (the group itself has no deleted-flag field); entries inside the group are still each handled as soft deletes.
恢复
Restore
垃圾桶内选中条目点恢复,它会回到原来的位置:原分组、原排序位置、原有的置顶与星标都在。恢复不需要任何确认——它本身就是个可逆动作。
Select an entry in the trash and click restore: it returns to exactly where it was — original group, original sort position, pin and star intact. Restore never asks for confirmation — it is itself a reversible action.
恢复的条目如果处于同步环境中,下一轮同步会把"它回来了"传到所有设备。
In a sync environment, the next round of sync tells every device "it is back".
彻底删除
Permanent deletion
垃圾桶内的「彻底删除」需要二次确认,确认后条目才真正移除。涉及敏感数据想立即清除时用这一步。
"Delete permanently" in the trash requires double confirmation; only then is the entry truly removed. Use it when sensitive data must be gone right away.
同步开启时,删除以墓碑形式参与同步:所有设备都会知道"它被删了",不会在下一轮同步里复活;Web 端正常列表同样过滤墓碑。
With sync on, deletion joins sync as a tombstone: every device learns "it was deleted" and it will not resurrect in the next round; the web side filters tombstones from normal lists the same way.
两个小提醒
Two small reminders
- 全局搜索不搜垃圾桶——在垃圾桶里就用垃圾桶自己的浏览与定位。
- "彻底删除"不可同步撤销:它是终点站,删除前想三秒。快照是导出时刻的静态副本,彻底删除后重新导出才会反映变化。
- Global search does not search the trash — inside the trash, use the trash's own browsing and locating.
- "Delete permanently" cannot be undone through sync: it is a terminal state, so think for three seconds first. A snapshot is a static copy from its export moment; after a permanent deletion, re-export to reflect the change.
删除从哪里发生
Where deletion happens
删除动作与四个页面里的右键菜单保持一致:备忘条目、路径条目、待办/便签卡片、记录列表的右键都有「删除」。垃圾桶页内则提供恢复与彻底删除两个出口。
Deletion matches the right-click menus of the four pages: memo entries, path entries, to-do/note cards and the records list all carry "delete". The trash page itself offers the two exits: restore and delete permanently.
同步环境下,删除是全设备一致的:本机删掉,手机端正常列表也会消失;反之亦然——手机端(编辑凭据)删除的条目会以墓碑形式回到电脑的垃圾桶。
In a sync environment deletion is consistent across devices: delete here and it disappears from the phone's normal list; the other direction too — an entry deleted on the phone (with edit credentials) arrives back on the computer's trash as a tombstone.
与云端版本历史的关系
Relation to server version history
彻底删除不影响服务器上已有的历史版本:旧版本仍按版本保留策略(默认 10 版)随时间淘汰,直到被新版本顶出。这是版本机制的正常行为——密文服务器分毫不差地保管历史,直到策略说可以放手。
Permanent deletion does not touch existing history versions on the server: old versions keep aging out under the retention policy (10 versions by default) until newer ones push them out. That is normal version mechanics — the ciphertext server keeps history exactly until the policy says to let go.
删除后想尽快让所有端一致:桌面端点一次「立即同步」,确认没有待推的改动即可。
To converge all devices quickly after a deletion: click "Sync now" once on the desktop and confirm nothing is left to push.
搜索与命令面板Search and the command palette
命令面板
The command palette
任意界面按 Ctrl+K 唤起:上半是全局搜索框,输入 > 前缀进入命令模式。全程键盘导航,手不用离开键盘。
Press Ctrl+K anywhere: the top half is the global search box; typing a > prefix enters command mode. Full keyboard navigation — your hands never leave the keyboard.
| 命令模式能做的事 | 说明 |
|---|---|
| 新建五类条目 | 备忘 / 待办 / 便签 / 日记 / 文档,直达对应页面并打开编辑 |
| 打开设置 | 跳到设置页 |
| 进入垃圾桶 | 查看与恢复已删除条目 |
| 立即锁定 | 等价于手动隐私锁——起身离开前最顺手的一步 |
| What command mode can do | Detail |
|---|---|
| Create any of the five entry types | Memo / to-do / note / journal / document — jumps to the page and opens the editor |
| Open settings | Jumps to the settings page |
| Enter the trash | View and restore deleted entries |
| Lock now | Equivalent to the manual privacy lock — the handiest step before standing up |
搜索范围
What search covers
- 跨四个数据区:备忘、路径、计划(待办/便签)、记录。
- 备忘跨分组检索——不记得条目存在哪个分组也没关系。
- 结果直接跳回原页面并保持可操作:继续编辑、置顶、星标、删除都在原地。
- 搜索面向正常列表,不含垃圾桶——找已删除的条目去垃圾桶页。
- 顶部搜索框与 Ctrl+K 共用同一套匹配规则与掩码边界。
- Across the four data areas: memo, paths, plans (to-dos/notes), records.
- Memo searches across groups — no need to remember which group an entry lives in.
- Results jump back to the original page still operable: keep editing, pin, star, delete right there.
- Search targets normal lists and excludes the trash — deleted entries live in the trash page.
- The top search box and Ctrl+K share one matching rule set and the same masking boundary.
敏感字段不参与搜索
Sensitive fields never match
搜索结果里不会返回敏感字段的内容——这是设计,不是 bug。
Search results never return sensitive field content — that is design, not a bug.
密码、卡号、CVV、API Key 等字段的值不进入搜索索引,结果摘要位置显示掩码。拿"6222"这种卡号片段当关键词是搜不出对应条目的——防止有人在你解锁着的电脑上顺手搜出敏感信息。
Values of password, card number, CVV and API key fields never enter the search index; the result summary shows the mask. Searching "6222", a card-number fragment, will not surface the entry — so no one can fish sensitive information out of your unlocked computer.
按名称、账号、邮箱地址、备注这些明文字段找条目即可,它们都在搜索范围内。
Find entries by name, account, email address or notes — all plaintext fields that are within scope.
用得更顺的几个习惯
Habits that make it smoother
- 先按
>再想命令——新建一条待办只要「> 新建待办」加回车,比点三次菜单快。 - 记不清条目名字时,搜它的备注或分组名,命中的往往是同组上下文。
- 从搜索结果跳过去之后,右键菜单还在原地等你——继续编辑或置顶不需要重新找条目。
- Press
>before you think of the command — a new to-do is just "> new to-do" plus Enter, faster than three menu clicks. - When you cannot recall an entry's name, search its notes or group name — the context of the same group usually surfaces it.
- After jumping from a result, the right-click menu is still there — keep editing or pinning without hunting for the entry again.
范围速查
Coverage at a glance
| 内容 | 能搜到吗 |
|---|---|
| 备忘条目(名称 / 账号 / 备注) | 能 |
| 路径条目、待办、便签、日记与文档 | 能 |
| 敏感字段值(密码、卡号、CVV、API Key) | 不能——按设计 |
| 垃圾桶内的条目 | 不能——去垃圾桶页找 |
| 隐私锁锁定状态 | 整库卸载,无从搜索——解锁后可用 |
| Content | Findable? |
|---|---|
| Memo entries (name / account / notes) | Yes |
| Path entries, to-dos, notes, journals and documents | Yes |
| Sensitive field values (password, card number, CVV, API key) | No — by design |
| Entries inside the trash | No — look in the trash page |
| While the privacy lock is engaged | The whole vault is unmounted; nothing to search — unlock first |
同步开启后,手机端与快照的搜索遵循同一套掩码规则——本机搜不到的,手机上同样搜不到,边界不分设备。
With sync on, search on the phone and in snapshots follows the same masking rules — what cannot be found on the computer cannot be found on the phone; the boundary does not depend on the device.
搜索与列表页共用同一条数据与同一套掩码判断——不会出现"列表里是掩码、搜索里是明文"这种对不上的情况。
Search and the list pages share the same data and the same masking decision — "masked in the list but plaintext in search" cannot happen.
通用操作Common actions
自动保存(没有保存按钮)
Auto-save (there is no save button)
内容实时自动保存,不需要寻找隐藏的保存按钮,也不存在"忘了保存"这种事故。编辑落盘、退出落盘、锁定前同样先落盘——写完就存,接着干别的。
Content saves automatically in real time. There is no hidden save button to look for and no "forgot to save" accident: edits hit disk as you type, on exit, and before locking — write, then move on.
这也意味着"恢复到上一次手动保存"这种概念不存在:你看到的就是已保存的。
It also means "revert to the last manual save" does not exist as a concept: what you see is what is saved.
右键菜单
The right-click menu
任意卡片右键 = 功能菜单:编辑、复制、删除、置顶、星标,以及各页面自己的特有操作(如 API 检测、设置提醒、发送到桌面、导出)。同一套菜单结构贯穿四个页面,学会一次到处能用。
Right-click any card for the action menu: edit, copy, delete, pin, star, plus each page's own specials (API check, set reminder, send to desktop, export). One menu structure across all four pages — learn it once, use it everywhere.
置顶与星标
Pin and star
- 置顶:排在列表最前面,适合正在用的项目。
- 星标:金色角标,跨列表标记重要的东西。
- 两者可叠加;列表排序始终「置顶优先 + 修改时间倒序」,置顶之内按修改时间排。
- Pin: sorts to the very front of the list, for what you are working on now.
- Star: a gold corner mark that flags important things across lists.
- Both stack; list order is always "pinned first, then modified time descending", and within pinned, by modified time.
弹窗与关闭
Dialogs and closing
弹窗按 Esc 或点击弹窗外空白处关闭;涉及删除、覆盖、清空的操作都会二次确认——确认弹窗会写清后果,不会只给一个"确定"按钮。
Dialogs close with Esc or a click outside; anything involving deletion, overwriting or clearing asks for double confirmation — the confirm dialog states the consequence plainly instead of offering a lone "OK".
主题与语言
Themes and language
浅色 / 深色 / 跟随系统三档主题,中 / 繁 / 英 / 한 / 日五语言,都在设置页切换;切换后重启生效(刻意不做热切换,保证界面状态一致)。
Light / dark / follow-system themes and five languages (Simplified Chinese, Traditional Chinese, English, 한국어, 日本語) all switch in settings; a restart applies the change (deliberately not hot-switched, to keep UI state consistent).
快速捕获与工作区
Quick capture and workspaces
- 全局热键:人在任何应用里,按下热键就能随手记一条备忘 / 待办 / 便签,直接落进对应数据区——不用切窗口、不用找 Novara 在哪。
- 工作区:跨五类数据的虚拟分组——把一个项目相关的备忘、路径、待办、记录聚合在一个名字下,原始数据原地不动。
- 网络指示器:标题栏常显「● 仅本地」;只有 API 检测或同步动作发生时出现对应提示。程序有没有在联网,任何时候都看得到。
- Global hotkey: from inside any application, the hotkey captures a memo / to-do / note straight into its data area — no window switching, no hunting for Novara.
- Workspaces: virtual groups across the five data types — gather a project's memos, paths, to-dos and records under one name while the originals stay put.
- Network indicator: the title bar always shows "● local only"; a matching hint appears only when an API check or a sync action runs. Whether the app is touching the network is visible at all times.
常见问题
FAQ
怎么确认内容已经保存了?
不用确认——保存是实时的,你看到的就是已落盘的内容。锁定、退出前程序也会先把编辑中的内容写完。
置顶和星标能同时用吗?
能。两者独立:置顶管排序,星标管标记,互不影响。
Esc 关不掉某个弹窗?
需要明确选择的弹窗(删除确认、覆盖确认、密码验证)不响应 Esc——必须点明确的按钮,防止误触把危险操作放过去。
How do I know my content is saved?
You do not need to — saving is real-time; what you see is what is on disk. The app also finishes writing before locking or exiting.
Can pin and star be used together?
Yes. They are independent: pin controls ordering, star controls marking; neither affects the other.
Esc will not close a certain dialog?
Dialogs that demand an explicit choice (delete confirmation, overwrite confirmation, password verification) ignore Esc — you must click a real button, so a stray keypress cannot wave a dangerous action through.
隐私锁与解锁The privacy lock
开启
Enabling it
设置页 → 隐私访问锁 → 开启,设定密码(至少 6 位,上限 64)。开启是即时生效的:整库立即以 AES-256-GCM 重新加密写盘,此后每次启动先过锁屏。
Settings page → Privacy access lock → Enable, and set a password (at least 6 characters, up to 64). Enabling takes effect immediately: the entire vault is re-encrypted with AES-256-GCM and written to disk on the spot, and from then on every launch starts at the lock screen.
密码不存明文:本地只存加盐哈希(PBKDF2-SHA256,300 万次迭代)。解密密钥由密码派生,密码不对谁也解不开。
The password is never stored as plaintext: only a salted hash is kept locally (PBKDF2-SHA256, 3 million iterations). The decryption key is derived from the password — with the wrong password, nobody opens it.
两种解锁方式
Two ways to unlock
| 方式 | 说明 |
|---|---|
| 密码 | 永远可用的主通道与兜底 |
| Windows Hello | 增强通道:刷脸 / 指纹验证通过后由系统保险箱代为取回密码。密码派生密钥的加密模型不变——Hello 只负责"把密码取回来" |
| Method | Detail |
|---|---|
| Password | The primary channel, always available and always the fallback |
| Windows Hello | The enhanced channel: after face / fingerprint verification, the system vault retrieves the password on the app's behalf. The encryption model (key derived from the password) is unchanged — Hello only "fetches the password back" |
Hello 验证失败或取消会静默退回密码输入,不计失败次数;系统没启用 Hello 时锁屏不显示该按钮。改密后 Hello 凭据自动同步更新。
If Hello verification fails or is cancelled, the app silently falls back to password entry without counting a failed attempt; the Hello button does not appear on systems without it. After a password change, the Hello credential is updated automatically.
锁定是硬锁
Locking is a hard lock
三个通道触发的是同一种锁定:手动锁定(快捷键)、空闲超时(5/10/30 分钟 / 1 小时 / 从不)、Windows 锁屏联动——按下 Win+L 锁电脑,Novara 跟着上锁。
All three triggers produce the same lock: manual locking (shortcut), idle timeout (5 / 10 / 30 minutes / 1 hour / never), and Windows lock-screen linkage — press Win+L to lock the PC and Novara locks with it.
硬锁的语义:会话密钥清除、数据库实例卸出内存、同步立即暂停(锁定期禁网是硬规则,不会因为"远端有新版本"绕过);解锁 = 重新验证密码、重新派生密钥、重新加载库。它不是只挡住界面的软锁——锁屏背后没有留任何可读状态。
What "hard" means: session keys are wiped, the database instance is unloaded from memory, and sync pauses immediately (no network while locked is a hard rule — it is not bypassed because "the server has a newer version"). Unlocking = re-verify the password, re-derive the key, reload the vault. It is not a soft lock that merely covers the UI — nothing readable is left behind the lock screen.
离开座位养成 Win+L 的习惯,空闲自动锁兜底,两层都开了才叫稳妥。
Build the Win+L habit when leaving your desk and let the idle auto-lock back you up — with both layers on you are properly covered.
连错 5 次
Five wrong attempts
连续输错 5 次密码 → 锁定 30 分钟。截止时间持久化在本地,重启程序也照样计时——重启不能"清零重来"。
Five consecutive wrong passwords → locked for 30 minutes. The deadline is persisted locally and keeps counting across app restarts — restarting does not "reset the counter".
冷却期内不接受尝试,防止程序化爆破。Windows Hello 失败不计入这 5 次——它本来就没碰密码。
No attempts are accepted during the cooldown, which blocks automated brute-forcing. Windows Hello failures do not count toward the five — they never touch the password.
改密与关锁
Changing the password and turning the lock off
- 改密需要验证原密码;改密是一次事务:先整库重加密、再更新凭据文件,任一步失败两边保持一致,不会出现"库是新密码、凭据是旧密码"的中间态。
- 关闭隐私锁会自动解密整库并清除 Windows Hello 凭据——数据回到明文单文件状态。
- 导入外部备份后,程序会建议重新设置 Hello(避免"Hello 解开了旧密码的库"这种歧义)。
- Changing the password requires the current one; the change is a single transaction: re-encrypt the whole vault first, then update the credential file. If either step fails, both sides stay consistent — there is no intermediate state where "the vault uses the new password but the credentials the old one".
- Turning the privacy lock off decrypts the whole vault and clears the Windows Hello credential — the data returns to a single plaintext file.
- After importing an external backup, the app suggests setting up Hello again (avoiding the ambiguity of "Hello unlocking a vault locked with the old password").
忘记密码会怎样If you forget the password
事实
The facts
- 没有恢复后门:项目方没有、服务端也没有解锁能力——加密库里连"验证答案"都不存在,密码不对就是打不开。
- 没有远程通道:清空、解锁、找回都需要在本机操作——不存在远程清空或远程解锁这种功能。
- 连错 5 次锁定 30 分钟(截止时间本地持久化),这个限制挡住的恰恰是"忘了密码的人反复试"。
- 唯一的路:清空全部数据、重建空库,再从备份恢复。没有备份的增量数据找不回来。
- No recovery backdoor: neither the project nor the server can unlock anything — the encrypted vault does not even contain "security answers"; a wrong password simply does not open it.
- No remote channel: wiping, unlocking and recovery all happen on your machine — there is no remote wipe or remote unlock feature.
- Five wrong attempts lock the app for 30 minutes (the deadline is persisted locally); this limit exists precisely to stop "someone who forgot the password from trying over and over".
- The only way forward: wipe all data, rebuild an empty vault, then restore from a backup. Data added since the last backup cannot be recovered.
怎么避免走到那一步
How to avoid ever getting there
- 把锁密码记进你信任的密码管理器——这是唯一真正有效的预防,其他都是缓解。
- 定期导出备份(明文或
.novaenc),并真的在新位置试导入一次——没验证过的备份不算备份。 - 开启 Windows Hello 便于日常解锁,但它不能替代牢记密码:取回的仍是密码本体,重装系统后未必还在。
.novakey是同步空间密钥的备份,不是锁密码的备份——两者别混。- 改密需要验证原密码——把它当作一次"确认自己还记得"的机会,顺手做一次备份。
- Keep the lock password in a password manager you trust — the only prevention that truly works; everything else is mitigation.
- Export backups regularly (plaintext or
.novaenc), and actually test-import once in a new place — an unverified backup is not a backup. - Windows Hello makes daily unlocking convenient but does not replace remembering the password: what Hello retrieves is the password itself, and the credential may not survive a system reinstall.
.novakeybacks up the sync space key, not the lock password — do not confuse the two.- Changing the password requires the current one — treat it as a "confirm I still remember it" drill and run a backup while you are there.
如果已经忘了
If it is already forgotten
- 清空重建在锁屏入口选择清空数据(需要确认),得到一个全新的空库。
- 恢复备份设置 → 数据归档与还原 → 导入最近的备份文件,重启后数据回来。
- 重设密码重新开启隐私锁,这次把密码记牢。
- Wipe and rebuildChoose to wipe the data at the lock screen (confirmation required); you get a brand-new empty vault.
- Restore a backupSettings → Data archive & restore → import the latest backup file; after a restart your data is back.
- Set a new passwordRe-enable the privacy lock — and this time commit the password to memory.
这句话就是本页存在的意义:备份的价值在忘记密码的那一天兑现。
That sentence is the reason this page exists: a backup's value is redeemed on the day the password is forgotten.
常见问题
FAQ
开启 Windows Hello 后忘了密码,有事吗?
日常没事:Hello 验证通过后程序从系统保险箱取回密码自动解锁。但重装系统、更换硬件后凭据可能不在了——密码本体还是要记牢。
服务端能帮解锁吗?互联同步的密钥还在吗?
都不能也没有:服务端从不持有锁密码;清空重建只影响本地库。同步空间密钥来自已配对设备的保管,与本机锁密码是两回事(但本机清空后需要重新配对才能恢复同步)。
能不能设置"安全问题"找回?
不能。安全问题的答案本质是弱密码,等于给爆破留一扇门——Novara 选择不做。
I use Windows Hello and forgot the password — is that a problem?
Not day to day: after Hello verification the app fetches the password from the system vault and unlocks automatically. But a system reinstall or hardware change may take the credential with it — still memorize the password itself.
Can the sync server help unlock? Are the sync keys still there?
No and no: the server never holds the lock password, and wiping rebuilds only the local vault. The sync space key is held by your paired devices — a different thing from this machine's lock password (though after a wipe you must re-pair to rejoin sync).
Can I set up "security questions" for recovery?
No. The answers are effectively weak passwords — a door left open for brute-forcing. Novara deliberately does not do this.
备份与还原Backup and restore
两种备份
Two kinds of backup
| 形态 | 特点 | 适合 |
|---|---|---|
| 明文备份 | 可读、可直接打开检查;导出时红字警告"文件含敏感信息";校验头用 SHA-256 防损坏 | 同机迁移、想用文本工具核对内容 |
加密备份 .novaenc | 独立密码(不存储、强度指示不拦截)+ AES-256-GCM + 独立随机盐;与安全快照同一容器格式 | 跨电脑传输、云盘存放——文件本身不带密钥 |
| Form | Traits | Best for |
|---|---|---|
| Plaintext backup | Readable and directly openable for inspection; the export warns in red that "the file contains sensitive information"; a SHA-256 checksum header guards against corruption | Same-machine migration, checking contents with text tools |
Encrypted backup .novaenc | Independent password (never stored; the strength meter never blocks) + AES-256-GCM + an independent random salt; same container format as secure snapshots | Moving between computers, cloud storage — the file itself carries no key |
两种都保留校验头,旧版本 Novara 导出的文件在 9.0 中照常可导入。开着隐私锁时,导入/导出都会先要求验证锁密码。
Both keep the checksum header, and files exported by older Novara versions import normally into 9.0. With the privacy lock on, import/export first asks for the lock password.
自动备份
Automatic backups
%LocalAppData%\Novara\backups\ 滚动保留最近 10 份。它是兜底,不是策略——重要数据请主动导出并放到另一块盘。
%LocalAppData%\Novara\backups\ keeps a rolling window of the last 10. It is a safety net, not a strategy — for anything important, export deliberately and put it on another drive.
自动备份与手动导出互不替代:前者防灾(程序崩溃、误操作后还能找回来),后者迁移(你主动持有、可带走、可导入另一台机器)。
Automatic and manual backups do not replace each other: the former is disaster recovery (you can still get data back after a crash or a slip), the latter is migration (you hold it, can carry it, can import it on another machine).
还原流程
The restore flow
- 选文件设置 → 数据归档与还原 → 导入。开着隐私锁时会先要求验证锁密码。
- 确认覆盖导入会覆盖当前全部数据——确认弹窗写明这一点。
- 自动快照覆盖执行前,Novara 自动把当前数据库先存一份快照——后悔药由程序替你备。
- 重启导入完成后需要重启程序,清除旧数据的内存状态。
- Pick the fileSettings → Data archive & restore → import. With the privacy lock on, the lock password is asked for first.
- Confirm the overwriteImporting overwrites all current data — the confirmation dialog says exactly that.
- Automatic snapshotBefore overwriting, Novara automatically snapshots the current database — the app keeps the regret pill for you.
- RestartAfter the import, the app needs a restart to clear old in-memory state.
换电脑迁移:导出(明文或加密)→ 拷贝文件 → 新机导入 → 重启。加密备份的密码是你导出时自设的那个,不是锁密码——除非你当时勾了复用。
Moving to a new computer: export (plaintext or encrypted) → copy the file → import on the new machine → restart. The encrypted backup's password is the one you set at export time, not the lock password — unless you ticked reuse.
加密备份的密码不存储在任何地方。忘了它,文件就永久解不开——和隐私锁密码同一个道理,记进密码管理器。
The encrypted backup's password is not stored anywhere. Forget it and the file can never be opened — same story as the lock password; put it in a password manager.
一个细节
One detail
导入备份后若使用了 Windows Hello,建议重新设置一次(导入的库对应导出时的密码)。系统会提示,别忽略。
After importing a backup, if you use Windows Hello, set it up again (the imported vault matches the password at export time). The app will prompt you — do not ignore it.
什么时候该备份
When to back up
- 第一次开锁并把真实数据放进来之后——立刻做第一次手动导出。
- 每次大批量整理(导入 CSV、迁移、批量删除)之后。
- 改密之后:新密码 + 新备份一起验证一次,保证"能导入"这件事始终成立。
- 固定节奏(比如每月一次)比"想起来才做"可靠得多。
- Right after the first unlock with real data inside — make the first manual export immediately.
- After every large reorganization (CSV import, migration, bulk deletion).
- After changing the lock password: verify the new password and a fresh backup together, so "it can be imported" always stays true.
- A fixed rhythm (say monthly) beats "when I remember" by a wide margin.
衡量标准很简单:任意时刻,最近一份备份都能在另一台电脑上成功导入。做到这一点,忘记密码、盘坏、误删都只是虚惊。
The bar is simple: at any moment, the latest backup should import successfully on another computer. Meet that, and a forgotten password, a dead drive or a slip of deletion are all false alarms.
数据存在哪里Where data lives
桌面端
Desktop side
| 内容 | 位置 |
|---|---|
| 主数据库 | %LocalAppData%\Novara\data.novadb |
| 锁凭据与密码哈希 | %LocalAppData%\Novara\security.dat |
| 滚动自动备份 | %LocalAppData%\Novara\backups\(最近 10 份) |
| Content | Location |
|---|---|
| Main database | %LocalAppData%\Novara\data.novadb |
| Lock credentials & password hash | %LocalAppData%\Novara\security.dat |
| Rolling automatic backups | %LocalAppData%\Novara\backups\ (last 10 kept) |
开启隐私锁后 data.novadb 整体是密文;无论加密与否,这些文件都在你的用户目录下,跟着 Windows 账户走,别的程序读不读得到由 Windows 权限管。
With the privacy lock on, data.novadb is ciphertext as a whole; encrypted or not, these files live under your user profile, tied to the Windows account, with other programs' access governed by Windows permissions.
服务端(如果你启用了互联同步)的数据在完全独立的目录——Windows 直跑在 %LOCALAPPDATA%\Novara\Server\data,Docker 默认在容器挂载的 /data。删桌面端不影响服务端,反之亦然。
The server's data (if you enabled encrypted sync) lives in a fully independent directory — %LOCALAPPDATA%\Novara\Server\data for the Windows direct-run path, the container-mounted /data by default under Docker. Removing the desktop app does not touch the server, and vice versa.
卸载会丢数据吗
Does uninstalling lose data?
| 选项 | 后果 |
|---|---|
| 保留数据(默认) | %LocalAppData%\Novara\ 原样保留;重装后数据自动恢复,隐私锁密码也照旧 |
| 删除数据 | 清空数据目录——需要输入 RESET 确认,防手滑 |
| Option | Consequence |
|---|---|
| Keep data (default) | %LocalAppData%\Novara\ stays exactly as it is; reinstalling restores everything automatically, privacy-lock password included |
| Delete data | Clears the data directory — requires typing RESET to confirm, so a slip cannot do it |
卸载删的是程序;用户数据是否清除由你决定,且默认不清。重装同版本或升级安装,数据都在原地等着。
Uninstalling removes the program; whether user data is cleared is your call, and the default is to keep it. Reinstall the same version or upgrade, and the data is waiting in place.
删除数据前若还有顾虑,先去设置页导出一份备份——两分钟的事,买一份后悔药。
If any doubt remains before deleting data, export a backup from settings first — two minutes that buy a regret pill.
能不能改路径
Can the paths be changed?
设置页刻意不提供"更改存储路径"入口:路径可预期是安全模型的一部分(杀软白名单、备份脚本、还原流程都建立在固定路径上)。
The settings page deliberately offers no "change storage path" entry: predictable paths are part of the security model (antivirus whitelisting, backup scripts and restore flows all stand on fixed paths).
想迁移到另一台电脑,用《备份与还原》;想在多台设备间保持一致,用《互联同步是什么》。
To move to another computer, use "Backup and restore"; to keep several devices consistent, use "What is encrypted sync".
导出物放在哪
Where exports go
备份文件与快照的保存位置由你导出时选择——程序不指定、不偷偷复制。几个建议:
Where backup files and snapshots are saved is chosen at export time — the app neither picks for you nor quietly copies anything. A few suggestions:
- 备份放到另一块物理盘或云盘;和数据库同盘的备份挡不住盘坏。
- 加密备份与快照本身就是密文,放云盘是安全的;明文备份建议加密压缩后再上云。
- 快照导出后是独立的
index.html,复制、改名、上传都不影响解密能力。
- Put backups on another physical drive or a cloud drive; a backup on the same disk as the database does not survive disk failure.
- Encrypted backups and snapshots are already ciphertext — cloud storage is safe; compress and encrypt a plaintext backup before uploading it.
- An exported snapshot is a standalone
index.html; copying, renaming or uploading it never affects its ability to decrypt.
服务端数据目录的位置见自建服务端篇各路径页面——它同样只是一个目录,备份就是复制。
For the server data directory location, see each path's page in the self-hosting guide — it is likewise just a directory, and backing it up means copying it.
常见问题(安装 · 数据 · 备份)FAQ (install · data · backup)
需要注册账号吗?需要联网吗?
都不需要。Novara 没有账号体系,核心功能完全离线;联网只发生在你主动使用的能力上(API Key 连通检测、互联同步)。
数据存在哪里?卸载会丢吗?
主库在 %LocalAppData%\Novara\data.novadb。卸载时选「保留数据」则完整保留、重装后自动恢复;选「删除数据」才会清除(需要输入 RESET 确认)。
换电脑怎么迁移?
用设置页的备份/导出,把文件拷到新电脑导入;或使用加密备份 .novaenc。
备份和 Snapshot 有什么区别?
备份(明文或 .novaenc)用于还原——整库搬回 Novara;Snapshot 是只读的加密单文件网页,用于查看与分享,不能导入。
能把 Snapshot 发给别人吗?
可以:文件加口令分两个渠道发。对方只能看、不能改,也拿不到比快照更多的数据。
自动备份在哪?
%LocalAppData%\Novara\backups\,滚动保留最近 10 份。它不替代你主动导出的备份。
Do I need an account? Do I need to be online?
Neither. Novara has no account system and core features are fully offline; networking happens only in features you actively use (API key checks, encrypted sync).
Where is the data? Does uninstalling lose it?
The main vault is at %LocalAppData%\Novara\data.novadb. Uninstalling with "keep data" preserves everything and a reinstall restores it automatically; only "delete data" clears it (typing RESET required).
How do I migrate to a new computer?
Use backup/export in settings, copy the file over and import; or use an encrypted .novaenc backup.
Backup or snapshot — what is the difference?
A backup (plaintext or .novaenc) is for restoring — bringing the whole vault back into Novara; a snapshot is a read-only encrypted single-file web page for viewing and sharing, and cannot be imported.
Can I send a snapshot to someone?
Yes: send the file and the passphrase through two different channels. They can view but not change, and get nothing beyond the snapshot.
Where are automatic backups?
%LocalAppData%\Novara\backups\, a rolling window of the last 10. They do not replace backups you export deliberately.
继续阅读Keep reading
- Take data out the door and share it → the secure snapshot guide
- See it on the phone any time, and edit → the encrypted sync guide
- Run your own sync server → the sync deployment guide