nostrbasedocs
Start building
Guide
.md

Encrypt a personal record

const { data, error } = await db.private
  .from("todos")
  .insert({ id: "personal", title: "Private note", done: false })
  .select();

const notes = await db.private.from("todos").eq("done", false);
await db.private.from("todos").update({ done: true }).eq("id", "personal");
await db.private.from("todos").delete().eq("id", "personal");

The active Nostr signer must support NIP-44 encryption. The SDK encrypts the complete record body to the signer’s own public key, then signs and publishes the ciphertext as a kind 30078 event. Applesauce signers provide the encryption and signing methods.

Only ciphertext enters the event store, backups, and offline queue. Data field values never enter index tags. The author, app, table, record ID, event timestamps, and approximate payload size remain public. A private table uses a separate address from a public table with the same name and ID.

Queries decrypt the current author’s records and apply filters, search, projections, ordering, and pagination locally. An explicit .author() must match the active author. Private records require a signed-in user for reads as well as writes. Group sharing and key rotation are outside this personal table API.

// Read verified local ciphertext; decrypt only for this result.
await db.private.from("todos").local().select();

// Explicitly save a signed, encrypted write to the configured durable queue.
await db.private.from("todos").insert({ title: "Offline note", done: false }).queue();

// Receive decrypted record changes. Callbacks include the signed ciphertext event.
const subscription = await db.private.subscribe("todos", (change) => {
  console.log(change.eventType, change.new);
});
subscription.unsubscribe();

The offline queue uses memory by default. Configure an IndexedDB persistence adapter to retain queued ciphertext across restarts.

Subscriptions stop on sign-out, account change, or client close. Plaintext held by your own app remains your app’s responsibility. NIP-09 deletion requests hide the record in SDK reads; relays can retain ciphertext or ignore deletion requests. Encryption does not revoke copies already decrypted by an authorized key.

Search guides, API methods, and protocols.