Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
80 changes: 48 additions & 32 deletions Atomic-Blog-Generation-Pipeline/SOURCE-OF-TRUTH.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,55 +4,71 @@ When an article states anything about Atomic Notes itself, trust in this order.
sources disagree, the higher one wins and the lower is stale.

```
1. Current source code (Project-Atomic-Notes-New / Project-Atomic-Notes lib/, supabase/)
2. Newest build-progress doc (Context/Atomic_Notes_Build_Progress.md)
3. Current roadmap (Context/Atomic_Notes_Roadmap.md)
4. Current project context (Context/Atomic_Notes_Context.md)
5. Current website (Atomic-Community-Base)
6. Older documentation (may describe superseded architecture — do not resurrect)
1. Current source code: Atomic-Notes-App-V0.2 (lib/), and the private Server (ask the owner)
2. The App README and TRANSPARENCY.md (Atomic-Notes-App-V0.2), and the live website
3. docs/ai-handover/ in the workspace (CURRENT_STATE, ARCHITECTURE, DECISIONS)
4. Older documentation (may describe superseded architecture; do not resurrect)
```

If older content conflicts with the current implementation, the current implementation
wins. Never reintroduce a superseded system just because an old doc mentions it (e.g. the
old single-base64-blob storage, or a random-wrapped-DEK vault — both replaced).
wins. Never reintroduce a superseded system just because an old doc mentions it: the
Supabase backend, email + password auth with OTP, the 20-note allowance, last-write-wins
sync, the single-blob notebook storage, and the random-wrapped-key vault are all gone.

## Shipped vs planned (verify against code before every article)

Every claim must be labeled honestly. As of the latest build:
Every claim must be labeled honestly. As of version 2.03.5 (28 September 2026):

**SHIPPED**
- Local-first notes + checklists; instant local save; fully offline capable.
- Per-note cloud sync (opt-in), last-write-wins on server `updated_at`, tombstones.
- Opt-in end-to-end encryption: AES-256-GCM + Argon2id, 6-word recovery phrase, per-user
salt, server stores only a verifier (cannot read notes). Off by default (T2T plaintext
path) until the user enables the vault.
- Auth: email + password, in-app OTP email verification + password reset (via Resend SMTP).
- Atomic Energy + Atomic Coins: cap 120, +20 energy every 24h (server clock), 1 coin = 40
energy, 5-coin welcome gift. Sync is energy-gated: instant 10, standard 5/hour; refunded
on failed upload. Local note-taking is never gated.
- In-app Notification Center (pinned + targeted notifications).
- No ads, no analytics, no trackers, no crash SDK. Minimal Android permissions.
- Android app (Flutter), Android 9+, signed split-ABI APKs on GitHub Releases.
- Local-first notes + checklists saved to on-device Hive storage as you type; fully offline.
- Sync to the user's own Google Drive: one `.atomic` file per note in a `My-Atomic-Notes`
folder, Google `drive.file` scope only (the app sees only files it created).
- Server (Hono on Vercel, Mumbai region, MongoDB Atlas) stores metadata only: ids, kind,
pinned/deleted flags, timestamps, Drive file ids. Never note titles or text.
- Sync engine: request-id replay (no double charge, no duplicates), per-user lock, one
transaction per push, 8 Drive writes in flight with retry, pulls of 10 files per page,
network retries after 5/15/45 s, auto sync a few seconds after typing stops, on resume
and on reconnect.
- Conflicts keep both versions: each push carries a base version; a stale edit is refused
(`note_conflict`) and the phone saves it as "(conflict copy)". Stale deletes are refused.
- Opt-in end-to-end vault: 6-word phrase (1,024-word list, 60 bits), Argon2id (64 MiB,
3 passes, parallelism 1), salt = SHA-256("atomic-notes-vault-v1|<user id>"), AES-256-GCM
(12-byte nonce, 16-byte tag), server stores only a verifier. Off by default (T2T: plain
text in the user's Drive, passing through the server in transit).
- Sign-in: Google only.
- Atomic Energy + Atomic Coins: +20 energy per day at a fixed daily time, missed days paid,
cap 120; standard sync 5 (at most once an hour), instant 10, nothing-to-upload free,
refund when no note gets through; 1 coin = 40 energy; 5-coin welcome gift.
- Capacity tiers: Tachyon 30 notes (free), Antimatter 40 (10 coins), Monopole 50
(20 more), Strangelet 100 (30 more).
- Notification center with web-link buttons; three welcome messages for new accounts.
- Biometric lock, TOTP two-step verification, FLAG_SECURE (no screenshots), Android
secure storage. No ads, no analytics, no trackers, no crash SDK, no AI.

**PLANNED / NOT YET SHIPPED (never say these are live)**
- Coin purchases with real money (Lemon Squeezy / Razorpay). The Buy button is a
"coming soon" sheet; no payment backend exists yet.
- Official app-store listings (Play / App Store / Amazon).
- A true background sync scheduler (the hourly charge happens when a sync runs, not via a
background job).
- Coins sold in the app. Today supporters get coins early by hand (see the website's
support page). Do not name a payment platform in app copy or notifications.
- Email + password sign-in, a web version, iOS, background sync while the app is closed,
a full export feature, store listings.

## Verified constants (do not drift)

- Note allowance: 20 per account (server-enforced).
- Energy cap 120; daily grant +20 / 24h (rolling, server UTC).
- 1 Atomic Coin = 40 energy. Sync cost: standard 5, instant 10.
- Encryption: AES-256-GCM, Argon2id (64 MB / 3 iterations), 6-word phrase, 1024-word list.
- Stack: Flutter (Dart) app; Supabase (Postgres + Auth + RLS + Realtime + Edge later).
- Version 2.03.5 (build 8), released 2026-09-28. Certificate SHA-256
cc24ae5ce1dca50fcd5e5c4c252d69e4965c55a975bd0e4739e8938fad9bebeb.
- Free note allowance: 30 per account (server-enforced).
- Energy cap 120; daily grant +20 at a fixed daily time; missed days paid up to the cap.
- 1 Atomic Coin = 40 energy. Sync cost: standard 5, instant 10, nothing to upload 0.
- Measured (27 Sep 2026, production, server time): 9-note push 3.2 s, 22-note push 6.8 s,
Google Drive about 1.5 s per file write, cold start 0.5 to 0.9 s.
- Stack: Flutter (Dart) app with bloc + Hive CE; Server Hono (TypeScript) on Vercel +
MongoDB Atlas + Google Drive API; website Next.js 15.
- Design: ink #15171B, paper #F4F5F1, signal #3A2FF0; Bebas Neue / Hanken Grotesk / JetBrains Mono.

## Security-claim rules

- Do not overstate encryption. It is opt-in; plaintext (T2T) notes are readable by the
operator by design until the vault is on. Say so plainly.
- Do not overstate encryption. It is opt-in. T2T notes are plain text in the user's Drive
and pass through the server in transit until the vault is on. Say so plainly.
- A lost recovery phrase means unrecoverable vault notes, by design. Never imply recovery.
- Do not invent audits, certifications, penetration tests, or CVE numbers.

Expand Down
2 changes: 1 addition & 1 deletion Atomic-Blog-Generation-Pipeline/STYLE-RULES.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,5 +65,5 @@ answers with "Great question" or "It depends".

## Atomic Notes positioning to reinforce (truthfully)
local-first, offline-first, privacy-first, data ownership, no ads/trackers/AI-on-your-notes,
opt-in encryption, Flutter + Supabase engineering, building in the open. Do not turn these
opt-in encryption, sync into the user's own Google Drive, Flutter + TypeScript engineering, source-available code. Do not turn these
into slogans; back each with a concrete mechanism from the code.
2 changes: 1 addition & 1 deletion Atomic-Blog-Generation-Pipeline/config/authors.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"name": "Ashutosh Sharma",
"role": "Founder & Solo Developer, Atomic Notes",
"brand": "DevBehindYou",
"bio": "Solo developer building Atomic Notes, a local-first, privacy-first notes app. Writes about local-first software, encryption, Flutter, and Supabase from first-hand build experience.",
"bio": "Solo developer building Atomic Notes, a local-first, privacy-first notes app. Writes about local-first software, encryption, sync and Flutter from first-hand build experience.",
"url": "https://devbehindyou.vercel.app",
"avatar": "/authors/ashutosh-sharma.png"
}
Expand Down
2 changes: 1 addition & 1 deletion Atomic-Blog-Generation-Pipeline/config/categories.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
{ "slug": "security", "name": "Security", "description": "Encryption, auth, and data protection." },
{ "slug": "local-first", "name": "Local First", "description": "Offline-first, device-first architecture." },
{ "slug": "open-source", "name": "Open Source", "description": "Building in the open." },
{ "slug": "engineering", "name": "Engineering", "description": "Flutter, Supabase, sync, and internals." },
{ "slug": "engineering", "name": "Engineering", "description": "Flutter, the sync server, Google Drive sync, and internals." },
{ "slug": "atomic-energy", "name": "Atomic Energy", "description": "The renewable-resource sync economy." },
{ "slug": "community", "name": "Community", "description": "Updates for and from the community." },
{ "slug": "announcements", "name": "Announcements", "description": "Milestones and news." }
Expand Down
2 changes: 1 addition & 1 deletion Atomic-Blog-Generation-Pipeline/prompts/research.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ You are researching one Atomic Notes blog topic. Load `SOURCE-OF-TRUTH.md` and

## Do
- Run at least 5 searches across distinct angles:
1. The technical concept (local-first, E2E encryption, CRDT/sync, Flutter, Supabase, etc.)
1. The technical concept (local-first, E2E encryption, CRDT/sync, Flutter, Google Drive sync, etc.)
from primary/authoritative sources.
2. Current stats or context (2024-2026 only), cross-checked against ≥2 independent sources.
3. Practitioner sentiment (dev communities) — the gap between marketing and real experience.
Expand Down
Loading