DevHoardDocs
TermsPrivacyHomeOpen app

architecture · vault

Vault Items

Updated Sun Aug 16 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Vault items

Your hoard is a personal Item list: typed memories with collections, tags, pin, trash, full-text search, JSON/MD export/import, and Obsidian-style [Title](#missing) links. Everything is scoped to your user id.

Public share (opt-in): owners can enable a /s/{slug} link for SNIPPET and PROMPT only. SECRET and other types are never shareable. Visitors can view; signed-in users can Clone to my hoard. Shares are noindex and can be disabled anytime.

Data lives in Neon Postgres, not in browser localStorage. Auth is an httpOnly session cookie. Only UI prefs (theme, nav collapse) use local storage. Review captures at /app/inbox. Personal stats live at /app/dashboard (not Owner metrics).

Item shape (short)

FieldNotes
typeSee item-types — includes IMAGE on Pro
titleDisplay name and wiki-link target
contentText body; SECRET is ciphertext at rest
languageShiki language for SNIPPET
urlRequired for LINK
source / reviewedAtCapture provenance + Hoard MCP Inbox
deletedAtSoft-delete (trash)

Blobs for IMAGE rows use a separate File table and presigned R2 PUT/GET — file bytes never pass through the Next.js request body.

Organization

  • Collections and tags (per-user unique names)
  • Pin via pinnedAt
  • Views in the app: Pinned only, Trash, Hoard MCP Inbox

No nested folders and no graph UI yet.

Search

Postgres FTS (tsvector + pg_trgm) over title and non-SECRET content, plus ⌘K in the app. SECRET bodies are not indexed.

Encryption honesty

SECRET items use AES-GCM with a server-held ITEM_ENCRYPTION_KEY. DevHoard can decrypt — this is convenience encryption, not E2EE or a password manager.

Related