Data & security

Data ownership is a precondition, not a feature: a single-file database you can move or export, with no account and no telemetry.

Data directory

How you run itLocation
Desktop (Windows)%LOCALAPPDATA%\Hetu
From sourceHETU_DATA_DIR, otherwise hetu.db in the working directory
Databasehetu.db (plus -wal / -shm)
Logslogs/, Serilog daily rolling, 7 days retained
Vector extensionsqlite-vec/vec0.dll (vec0.so elsewhere), loaded when the connection opens

Backup and migration

  • Settings → Data & backup: export all notes as a Markdown archive, back up or restore the database file.
  • To move machines, quit the app and copy the whole data directory (including the WAL file).
Copying the database file while the app runs can lose uncommitted WAL content. Prefer quitting first, or use the built-in backup.

Environment variables and config keys

NamePurpose
HETU_DATA_DIRData directory (database and logs); injected by the desktop shell
HETU_PARENT_PIDShell process id; the backend exits when its parent disappears
HETU_API_DEV_PORTIn dev mode, reuse an existing backend on this port
DatabaseProvider (appsettings)Sqlite (default) / Postgresql
ConnectionStrings:DefaultConnectionConnection string; SQLite defaults to Data Source=hetu.db
Embedding:DimensionsVector dimensions (default 1536) — must match the embedding model
WorktreeConfig (stored setting)Worktree root directory
WorktreeCleanupConfigCleanup interval, idle threshold, delete branch
CloseToTrayWhether closing the window minimizes to the tray

Switching to PostgreSQL

export DatabaseProvider=Postgresql
export ConnectionStrings__DefaultConnection="Host=localhost;Database=hetu;Username=postgres;******"

dotnet ef database update \
  --project src/Hetu.Infrastructure.PostgresMigrations \
  --startup-project src/Hetu.Api

PostgreSQL 16+ with the pgvector extension is required. Both databases support the same features, but data does not transfer: rebuild notes and indexes in the new database.

Vector storage

DatabaseApproachDimensions
SQLitesqlite-vec vec0 virtual table keyed by rowid, alongside metadata tablesFrom Embedding:Dimensions, default 1536
PostgreSQLpgvector column with an indexSame setting

Security boundaries

ItemImplementation
API keysEncrypted with ASP.NET DataProtection (DPAPI-backed on Windows); never written to logs or API responses in plaintext
SSH credentialsEncrypted the same way
Outbound requestsOnly to providers you configure and to search / MCP services you explicitly enable; no telemetry
Markdown renderingSanitized with DOMPurify so note content cannot inject scripts
Command executionGoverned by permission modes (plan / readonly / ask / auto / bypass); risky operations require confirmation by default
Share linksExpose a single rendered note, can be revoked, and record view counts
SQL injectionAll access goes through EF Core parameterized queries