Note security & backups
Protect the seed, spend secret, view key, note randomness, encrypted journal, output preimages and backups.
The SDK keeps sensitive note material on the client. Protect these assets:
- Wallet seed and derived spend secret.
- View key used to decrypt encrypted Shield payloads.
- Note randomness and complete note preimages.
- Encrypted NoteStore journal and exported backups.
- Pending operation records and signed transactions before final reconciliation.
The encrypted journal contains note randomness and pending output preimages. Treat its backup with the same custody policy as the seed even though it is authenticated/encrypted. Do not log notes, proof requests, decrypted payloads or witness material.
Recovery responsibility
The SDK's EncryptedFileNoteStore is encrypted and append-only. exportBackup() and importBackup() provide encrypted journal backup/restore. The SDK verifies note commitments and spent-nullifier state during recovery.
Losing both seed and journal/backups can prevent recovery. Current random Private Swap output material is not emitted as plaintext in the event; if its preimage and backup are lost, it cannot be reconstructed from chain data alone. Do not assume public commitment visibility is enough to recover or spend a note.
If a process stops while proving before submission, the SDK may retain a reserved/unresolved input. It will not release the note based only on timeout. Reopen the store and call reconcilePending() before selecting notes again.
See Notes & NoteStore and Recovery & witnesses.