Thursday, September 10, 2026
No directory. Just math: how your Recovery Seed finds your notes
A question we get asked a lot, once people understand there is no account and no folder with their name on it: if the server genuinely cannot tell which encrypted fragments belong to which person, how does the app find your own notes when you open it on a new device? The answer is not a clever trick. It is the same idea that has quietly protected crypto wallets for over a decade — a formula instead of a filing system.
The two ways to find something in a pile
There are only two ways to locate a specific item in an undifferentiated pile of identical, locked containers. One is a directory — a list somewhere that says "container 4,281 belongs to this person." That is how almost every cloud service works, and it is exactly the thing that makes a stolen server, a subpoena, or a rogue employee dangerous: the directory itself is a map of who owns what, even before anyone breaks a single lock.
The other way is math. If you already know the exact address of your own container — not because it is written down anywhere, but because you can calculate it yourself, every time — you never need a directory at all. Nobody has to maintain a list of who owns what, because there is no list to maintain. There is just a formula, and the only people who can run it are the people who hold the input.
A directory is something that can be read, leaked, or subpoenaed. A formula that only you can run leaves nothing behind for any of those things to find.
Your Recovery Seed is the input
Your 12-word Recovery Seed is not just a backup password. It is the seed for that formula. Feed it in, on your own device, and it deterministically computes exactly where each of your notes lives — the same computation, producing the same answer, every single time, on any device you set up. Nobody at Prevon runs this computation on your behalf, because nobody at Prevon has the input to run it. The "directory" that finds your notes exists nowhere except as math you can perform yourself, and it evaporates the moment you close the app.
This is the exact mechanism behind a hardware crypto wallet recovering an entire portfolio from nothing but a seed phrase — no bank, no account, no company-held ledger of what you own, just a formula that reconstructs the answer from something only you hold. Prevon applies the same idea to notes instead of coins.
What this actually protects you from
This is a different, earlier layer of protection than encryption itself. Encryption protects what is inside a container once someone finds it. This protects the far more basic fact of which containers are yours in the first place. A server that was compromised entirely — every disk copied, every byte read — would hand an attacker a pile of identical, anonymous, encrypted fragments with no map connecting any of them to you specifically. Not "hard to connect." Nothing to connect, because that connection was never stored anywhere to begin with.
It is also why losing your Recovery Seed is unrecoverable by design, not by oversight. If Prevon could run that formula for you when you forgot it, Prevon would need to be holding a copy of it — and a copy that exists somewhere is exactly the directory this whole design exists to avoid.
