Private notes in an encrypted collection
A journal or a folder of medical results is the kind of note you may want to keep away from an AI agent and out of your sync provider's file history. An encrypted collection stores those records as ciphertext on disk, and Intabula decrypts them in memory only while you have the collection unlocked.
Setting it up
Click New collection in the sidebar, name the folder (journal, for example) and tick Encrypt this collection. Enter a password of at least 8 characters twice and tick the box confirming there is no recovery. The collection is encrypted before its first record is written. An existing collection can be encrypted later with Encrypt this collection… in its settings, which rewrites its records as ciphertext. Folders inside an encrypted collection are encrypted with it.
What is locked at rest
Each record file holds AES-256-GCM ciphertext in place of its fields and body. The encryption key is wrapped by a key derived from your password, and the password itself isn't stored. The search index keeps a stub row per encrypted record with no fields or text in it.
Filenames, the number of records, file sizes and modification times stay visible on disk. If a record's name is itself private, give it a neutral one.
What the agent can see
The agent is told the collection exists and how many records it holds, and it can see record names. Every tool that reads or changes records refuses an encrypted collection, whether or not you have it unlocked, and search results leave its records out. The refusal is enforced in the app's code for every provider. A bot can't be set up on an encrypted collection or given read access to one.
Unlocking
Open the collection and enter the password; it stays unlocked for the session. It locks again when you quit Intabula, after 15 minutes without use, or when you click Lock now in the collection's settings.
There is no recovery
Intabula has no account or server holding a copy of your key. If you forget the password, the records stay unreadable. Change password… in the collection's settings rewraps the key and leaves the record files as they are.
On iPhone
The encrypted files sync with the rest of the vault. The iOS app shows the collection with a lock and its record count, and it can't unlock it or add records to it, so you read and write those notes on your Mac. The agent in the iOS app can't read them either.
More in the docs: Encrypted collections