v1.1.0 — Encrypted backup & restore, plaintext export, and the Flowvault Blog
Flowvault v1.1.0 is a portability-and-docs release. You can now snapshot an
entire vault — every slot, every decoy password, every tab — into a single
zero-knowledge .fvault file, restore it to any Flowvault instance (hosted
or self-hosted), or export the currently-open notebook as a plaintext
Markdown zip for migration to Obsidian, git, or Standard Notes. We also
launched the Flowvault Blog with seven long-form posts that explain every
feature from first principles, and tightened the user-facing copy around
the trusted-handover flow.
Highlights
- Encrypted backup (
.fvault) — one-click download of the opaque
ciphertext the server already holds, plus its KDF salt and volume
layout, bundled into a single JSON envelope. Still zero-knowledge on
disk: no password, no plaintext, decoy slots indistinguishable from
random bytes. Round-trips every password in the vault. - Plaintext Markdown export (
.zip) — behind an explicit confirmation,
the currently unlocked slot's tabs are written to.mdfiles. Decoy
notebooks behind other passwords are never included, preserving
deniability even if you export under coercion. - Restore page (
/restore) — drop a.fvaultfile onto any fresh URL
slug. No password prompt during restore (there's no decryption
happening); Flowvault just re-seats the ciphertext. Existing slugs are
rejected — you pick a new one. - Flowvault Blog (
/blog) — seven deep-dive posts with full SEO
wiring (per-post canonical, OpenGraph article, Twitter card,
BlogPosting + BreadcrumbList JSON-LD, sitemap entries). - Trusted-handover copy refresh — the inheritance feature is now
called Trusted handover across all visible UI. The mechanism is
unchanged; the wording is just less alarming.
What's new
SEO & docs
- New FAQ section: "Backup, restore & migration (
.fvault, Markdown
export, self-hosting)" with ten Q&As. - Home page: new feature card + two new comparison-table rows
("Encrypted backup / restore", "Plaintext export (Markdown)"). - Root metadata + home/FAQ/security keywords extended for the new
feature surface. - Sitemap now emits
/blog,/blog/<slug>for every post, and
/restore. - Navbar: added Blog link.
UX / copy
- All user-visible "dead-man's switch" wording replaced with "trusted
handover" (modal title, toolbar button, error messages, released-gate
text, FAQ, blog, README, OpenGraph image). The Firestore field name
and internal identifiers are unchanged — no data migration needed. - "Released" phrasing softened to "handed over" where it appears in
user-facing copy. - Homepage closing section and footer now cross-link to
/blog. - FAQ footer section links to every post by topic.
Fixes
- Internal error message from
sites.tswhen writing to a released
vault now reads "handed over to its beneficiary" instead of the
previous phrasing. - Minor a11y fix on the restore form (removed an unsupported
aria-disabledon a<section>with implicitrole="region").
Upgrade notes
- No breaking changes. Existing vaults open unchanged under their
existing passwords. Existing trusted-handover configurations keep
working (only the wording changed). - Backups are opt-in. If you never open the Export menu, nothing
about your vault leaves the server. Backups are generated and
downloaded purely client-side. - Restoring requires a fresh slug. We intentionally refuse to
overwrite a live vault at an existing URL; pick an unused slug on
/restore. - Self-hosters: the
.fvaultformat is stable atversion: 1.
Backups created against the hosted instance rest