Zero knowledge. Zero onboarding.
Notes, contacts, and files, encrypted on your device before they sync. No email, no password, no signup form: open Tearleads and start working.

Zero knowledge
Document and file contents are encrypted on your device before they sync. The service stores ciphertext and wrapped keys and holds no plaintext content keys. The app derives who can receive keys from signed access records it verifies, not from server-provided lists.
- Content
- Encrypted before it syncs
- Service stores
- Encrypted content and wrapped keys
- Access
- From verified signed records
The service still sees organization and group names, membership, and structure such as identifiers, sizes, access relationships, and timing.
What the service can seeZero onboarding
The first time you open Tearleads, it creates your identity keys on your device and, once you're online, registers their public keys with the service. Those keys sign you in instead of a password, so there is no account form to fill in and you can start working right away.
- Sign-up
- No email, no password
- Identity
- Created on your device
- Recovery
- 24-word recovery phrase
Back up your recovery phrase in Identity Manager when you're ready, and keep it private: anyone who has it can restore your identity. A paid web plan asks for a billing email at checkout.
How it worksWhat's in Tearleads
Everything lives in one folder tree in Explorer.
Notes
Plain-text notes with attached files and image previews.
Contacts
Names, nicknames, and profile photos. Add a Tearleads user ID to link a contact to that person's identity.
Files
Import images, PDFs, audio, and video into nested folders, download them again, and recover removed items from Trash.
Records
Structured records such as driver's licenses and passports, each with its own fields and images.
Offline
Edits save on your device first and sync when you reconnect. Sharing and other online actions need a connection.
Backups
Export a password-protected backup file and restore from it.

How it works
Open Tearleads
Use the web app in your browser, or install the desktop app for macOS or Linux. There is nothing to sign up for.
Work on your device
Your notes, contacts, and files are stored encrypted on your device and stay editable offline. Export a password-protected backup whenever you like.
Sync and share
Your personal organization gets a 7-day free sync trial when the app registers your identity. After that, paid plans keep end-to-end encrypted sync across your devices, and Team plans add folder sharing with users and groups in your organization.
What's protected, and where it stops
Each protection is listed with its limit.
Content
Protection Document and file contents are encrypted on your device before they sync. The service stores ciphertext and wrapped keys, not plaintext content keys.
Limit The service can see organization and group names, membership, folder and file structure, identifiers, public keys, access relationships, who signed each change and when, sizes, IP addresses, and traffic patterns such as request timing. See the full list.
Sharing
Protection The app works out who can receive a folder's keys from signed access records and group policies that it verifies. Editing a membership row on the server is not enough to grant access.
Limit Trust starts at first contact: a server that substitutes someone's key on the first lookup can still establish a false identity.
Removing access
Protection Removing group members rotates the group key and the affected folder keys in one atomic update.
Limit It can't take back content or keys someone already received. New members can read a folder's retained history, and nested folders have further limits.
Your device
Protection Local data is stored encrypted, under keys protected by a host wrapping key and an optional PIN.
Limit Protection depends on where the platform keeps that wrapping key. The desktop and mobile apps store it as key bytes alongside the app's data, so without a PIN a copy of that data can be decrypted, and with a PIN it can be attacked by guessing PINs offline. In a browser, a copy of the browser's stored data may allow the same. An unlocked or compromised device exposes content, and anyone with your recovery phrase can recover your identity.
Public-key operations in the Tearleads client and API keying protocol use only post-quantum algorithms: ML-KEM-1024 for key delivery and ML-DSA-87 for signatures (NIST FIPS 203 and 204). TLS connections and deployment tooling are outside that statement. Synced document and file contents are encrypted with AES-256-GCM.
Pricing
Free on your device. Paid plans add sync for one organization and are priced by member capacity, not per member.
| Plan | Price | Includes |
|---|---|---|
| Free Forever | $0 | Your device only, no sync |
| Solo | $5 / month | Encrypted sync for 1 member |
| Team (up to 5) | $10 / month | Encrypted sync and sharing for up to 5 members |
| Team (up to 10) | $20 / month | Encrypted sync and sharing for up to 10 members |
Your personal organization starts a 7-day free sync trial when the app first registers your identity. For any other organization, an admin can start one in Org Manager → Billing.
Download
Install Tearleads on macOS or Linux, or use it in your browser.
- Download for macOS
macOS
- Apple silicon
- .dmg
- Signed and notarized
- Download for Linux
Linux
- x64 (Intel, AMD)
- .tar.gz
- Tested on Ubuntu 24.04
Web
- app.tearleads.com
Nothing to install.
Open web app
Check each download against its SHA-256 checksum before you install. The Linux install guide shows the command.
Zero knowledge. Zero onboarding.
Free on your device. Open Tearleads in your browser, or install it on macOS or Linux.