What Remarkable Does With Your Data
Remarkable's cloud store syncs handwritten notes, PDFs, and exported files across devices. The company states that all data is encrypted in transit using TLS 1.2 and stored on Amazon Web Services (AWS) with server‑side encryption. While encryption protects against eavesdropping, it does not guarantee that the data is inaccessible to anyone with AWS account privileges or to the company's own administrators.
More from this site
Keep reading the latest coverage
Encryption Details and Key Management
Remarkable uses AES‑256 for data at rest, a standard that meets industry security benchmarks. However, the public documentation does not disclose whether keys are managed by the user, the device, or the company. If keys are centrally stored, a breach of the key vault could expose all user content. Users who demand stricter controls might consider local backups or third‑party encryption before uploading sensitive material.
Access Controls and Authentication
Access to the cloud store is gated by a single account login. Two‑factor authentication (2FA) is available via email or SMS, but the platform does not yet support authenticator apps or hardware tokens. The absence of multi‑factor methods beyond basic 2FA increases vulnerability to account takeover, especially if users rely on weak passwords.
Data Residency and Compliance
Remarkable stores data in the United States. For organizations subject to GDPR, HIPAA, or other data‑protection regulations, this poses a compliance question. The company does not provide explicit assurances about data residency or the ability to export data in a compliant format, which may limit its suitability for regulated industries.
User‑Controlled Backups and Export Options
Users can export notes as PDFs, images, or plain text, and can sync to cloud services like Google Drive or Dropbox. This flexibility allows manual encryption or storage on personal devices. However, the default sync feature lacks granular permission settings; all notes in an account are automatically shared with the cloud, leaving no way to exclude particular files from sync without manual export.
Security Incidents and Transparency
To date, there are no publicly reported data breaches involving Remarkable's cloud storage. The company publishes a privacy policy and a data handling statement, but it does not maintain a public incident‑reporting page or a bug‑bounty program. Transparency is limited, making it harder for users to assess the company's response to potential security events.
Conclusion
Remarkable's cloud store implements industry‑standard encryption and basic authentication, which provides a solid baseline for casual users. However, the lack of advanced multi‑factor options, unclear key management, and limited compliance information mean that users handling highly sensitive or regulated data should exercise caution and consider supplemental local backups or third‑party encryption tools.