How to Audit a browser extension's permissions
How to Audit a browser extension's permissions — a practical, example-driven guide with honest tool comparisons and a clear place for WebSnips. Written for Lawyers.
Privacy & Security
How to self-host your knowledge base — a practical guide for individuals and teams who want full control over their knowledge management system by running it on their own infrastructure, eliminating third-party access to notes, documents, and captured research.
A self-hosted knowledge base runs on infrastructure the user controls: a home server, a VPS (virtual private server), or a cloud virtual machine the user owns. The user's notes, documents, and captured research live on that server, not on a third-party platform.
The privacy argument for self-hosting is simple: a third-party platform stores user data on servers the user doesn't control, under a privacy policy the user didn't write, subject to legal processes and business decisions the user can't influence. When Evernote changed its privacy policy in 2016 to allow certain employees to access user content, users had no recourse beyond deleting their accounts. When Notion updated its terms of service, the practical ability to negotiate the terms was nonexistent. When a note-taking service shuts down or is acquired, the user's data follows the acquiring company's policies.
Self-hosting eliminates these risks. The user's data lives where the user puts it. The security controls are the ones the user implements. There are no policy changes from a third-party business. There are no third-party obligations to respond to legal data requests (data requests go to the user's hosting provider, not a specialized note-taking service with a dedicated legal team and established disclosure practices).
The tradeoff: self-hosting requires technical setup and ongoing maintenance. It's not appropriate for every user. This guide explains what's involved, which tools support self-hosting, and how to assess whether self-hosting is the right choice for a specific knowledge base use case.
Technical requirements:
A server: Something to run the software on. Options range from a Raspberry Pi in a home network to a commercial VPS (DigitalOcean, Linode, Hetzner, Vultr) to a self-managed VM in a cloud provider (AWS EC2, Google Compute Engine). A cheap VPS (€5/month) is sufficient for a personal knowledge base; a small team might need more resources.
A domain name (optional but useful): A custom domain (e.g., wiki.yourname.com) makes the knowledge base accessible from any device without remembering an IP address. Domain registration is ~$12/year.
Basic Linux familiarity: Self-hosting typically involves command-line operations: installing packages, configuring environment files, starting services. Users comfortable with a terminal can set up most knowledge base tools in a few hours. Users without command-line experience will face a steeper learning curve — Docker-based setups reduce this barrier significantly.
Ongoing maintenance: Software updates, backups, security patches. This is the most underestimated requirement. A self-hosted knowledge base is a system the user is responsible for maintaining. The time cost is low (30 minutes per month for a well-configured system) but non-zero.
Security requirements:
A self-hosted knowledge base exposed to the internet is a server that can be targeted. Minimum security practices:
This isn't an advanced security configuration — it's a baseline that any self-hosted server should meet.
Obsidian + Syncthing (local-network sync, no server required)
For users who want cross-device sync without any cloud service or server exposed to the internet, Obsidian combined with Syncthing is an excellent option.
Setup: install Obsidian on all devices; install Syncthing on all devices; configure Syncthing to sync the Obsidian vault directory. Syncthing encrypts data in transit between devices. No account required; no central server.
This is not strictly "self-hosting" in the server sense, but it achieves the privacy goal (no third-party stores notes) with minimal technical overhead. Appropriate for individuals; less practical for teams.
Joplin Server (self-hosted sync)
Joplin's official server component allows the user to run their own Joplin sync server. Joplin notes sync to the user's server, with end-to-end encryption if configured. The Joplin Server is packaged as a Docker container.
Setup: a VPS or home server; Docker and Docker Compose installed; deploy the Joplin Server container; configure Joplin clients to sync to the self-hosted server with E2EE enabled.
Docker Compose setup:
version: '3'
services:
db:
image: postgres:14
volumes:
- ./data/postgres:/var/lib/postgresql/data
environment:
- POSTGRES_PASSWORD=changeme
- POSTGRES_USER=joplin
- POSTGRES_DB=joplin
app:
image: joplin/server:latest
depends_on:
- db
ports:
- "22300:22300"
environment:
- APP_PORT=22300
- APP_BASE_URL=https://joplin.yourdomain.com
- DB_CLIENT=pg
- POSTGRES_PASSWORD=changeme
- POSTGRES_DATABASE=joplin
- POSTGRES_USER=joplin
- POSTGRES_HOST=db
With a reverse proxy (nginx or Caddy) handling HTTPS and a Let's Encrypt certificate, Joplin Server is accessible at https://joplin.yourdomain.com. Joplin clients (desktop and mobile) connect to this URL instead of the default Joplin sync service.
Privacy posture: the user controls the server; no third-party has access to the note data. With E2EE enabled in Joplin, even the server operator (the user themselves, on their VPS) cannot read note content without the encryption password.
Outline (team knowledge base)
Outline is an open-source team knowledge base — a markdown-based wiki with real-time collaboration, document organization, search, and access controls. It's available as a SaaS service and as a self-hosted deployment.
The self-hosted version is a Docker-based deployment. Requirements: a VPS, Docker, PostgreSQL database, Redis, and an S3-compatible object storage for file attachments (MinIO can be self-hosted for this, or AWS S3 if some cloud dependency is acceptable).
Outline is well-suited for small teams who want Notion-like functionality with self-hosted privacy. The setup is more complex than Joplin Server but produces a full-featured team knowledge base.
Wiki.js
Wiki.js is a self-hosted wiki platform with a rich editing interface, structured navigation, granular access controls, and support for multiple authentication methods (local accounts, LDAP, OAuth). It's packaged as a Docker container.
Setup:
version: "3"
services:
db:
image: postgres:14-alpine
environment:
POSTGRES_DB: wiki
POSTGRES_PASSWORD: wikijsrocks
POSTGRES_USER: wikijs
volumes:
- db-data:/var/lib/postgresql/data
wiki:
image: ghcr.io/requarks/wiki:2
depends_on:
- db
environment:
DB_TYPE: postgres
DB_HOST: db
DB_PORT: 5432
DB_USER: wikijs
DB_PASS: wikijsrocks
DB_NAME: wiki
ports:
- "3000:3000"
volumes:
db-data:
With a reverse proxy, Wiki.js is accessible at a custom domain with HTTPS. It supports Markdown editing, Git-based storage (notes stored in a Git repository as markdown files), and rich search.
Gitea + Markdown wiki
Gitea is a self-hosted Git service — primarily for code version control — but its built-in wiki feature (a markdown-based wiki attached to any Git repository) is useful as a simple, low-overhead knowledge base.
If the user is already running a Gitea instance for code, the Gitea wiki provides a knowledge base with zero additional software. If starting fresh, Gitea is more setup than Joplin Server for a note-taking-only use case.
Target setup: Joplin Server on a €5/month VPS (Ubuntu 22.04); HTTPS with Caddy and Let's Encrypt; Joplin clients on macOS and iOS connecting to the self-hosted server.
Step 1: Provision the VPS
Purchase a VPS from a provider (Hetzner, Linode, DigitalOcean). Choose Ubuntu 22.04. Select the smallest instance (1 vCPU, 1 GB RAM — sufficient for a personal Joplin server). Note the VPS's public IP address.
Step 2: Point a domain to the VPS
Add an A record to a domain you control: joplin.yourdomain.com → [VPS IP address]. DNS propagation takes a few minutes to a few hours.
Step 3: Basic server setup
# Update packages
apt update && apt upgrade -y
# Install Docker
curl -fsSL https://get.docker.com | sh
# Install Caddy (as reverse proxy with automatic HTTPS)
apt install -y debian-keyring debian-archive-keyring apt-transport-https
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' | gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' | tee /etc/apt/sources.list.d/caddy-stable.list
apt update
apt install caddy
# Basic firewall
ufw allow OpenSSH
ufw allow 80
ufw allow 443
ufw enable
Step 4: Deploy Joplin Server
Create a docker-compose.yml file with the configuration from the previous section (filling in POSTGRES_PASSWORD with a strong password and APP_BASE_URL with the actual domain).
# Create directory
mkdir -p /opt/joplin
cd /opt/joplin
# Create docker-compose.yml (fill in actual values)
nano docker-compose.yml
# Start services
docker compose up -d
Step 5: Configure Caddy reverse proxy
Edit /etc/caddy/Caddyfile:
joplin.yourdomain.com {
reverse_proxy localhost:22300
}
Reload Caddy: systemctl reload caddy. Caddy automatically obtains a Let's Encrypt certificate.
Step 6: Create a Joplin Server account
Visit https://joplin.yourdomain.com in a browser. Complete the initial admin setup to create a user account.
Step 7: Configure Joplin clients
On each device, open Joplin → Tools → Options → Synchronization. Set Sync Target to "Joplin Server". Enter the server URL, email, and password. Enable end-to-end encryption (Tools → Options → Encryption) and create an encryption password.
Notes now sync to the self-hosted server with E2EE.
A self-hosted knowledge base without backups is a knowledge base at risk. Server failures, hardware problems, and accidental deletion are real events.
Automated backup approach for Joplin Server on a VPS:
Create a script that dumps the PostgreSQL database and uploads it to an external location:
#!/bin/bash
# Run daily via cron
DATE=$(date +%Y-%m-%d)
BACKUP_DIR="/opt/joplin/backups"
mkdir -p $BACKUP_DIR
# Dump PostgreSQL database
docker exec joplin_db_1 pg_dump -U joplin joplin > "$BACKUP_DIR/joplin-$DATE.sql"
# Compress
gzip "$BACKUP_DIR/joplin-$DATE.sql"
# Upload to Backblaze B2 (using b2 CLI, configured separately)
b2 upload-file your-bucket "$BACKUP_DIR/joplin-$DATE.sql.gz" "backups/joplin-$DATE.sql.gz"
# Delete local backups older than 7 days
find $BACKUP_DIR -name "*.sql.gz" -mtime +7 -delete
Schedule with cron (crontab -e): 0 2 * * * /opt/joplin/backup.sh
This produces daily encrypted database backups stored off-server. Even if the VPS is destroyed, the knowledge base can be restored from backup.
Self-hosting is appropriate when:
Self-hosting is less appropriate when:
For users in the "want privacy but not self-hosting" category, end-to-end encrypted cloud services (Standard Notes, Notesnook, Joplin with an E2EE-enabled cloud sync target) provide meaningful privacy without server administration overhead.
Self-hosting a knowledge base is a meaningful privacy choice for users who want control over where their notes and research live. The technical requirements are real but manageable: a VPS, basic Linux comfort, Docker, and a backup strategy. The setup time for a personal Joplin Server deployment is a few hours; the ongoing maintenance is minimal if configured well. The privacy benefit is durable: no third-party policy changes, no provider access, no platform risk. For users who want the privacy property without the server management, E2EE cloud tools (Standard Notes, Notesnook) provide a middle path. For users who want full infrastructure control, self-hosting is the right call — and the tooling available in 2026 makes it more accessible than it has ever been.
More WebSnips articles that pair well with this topic.
How to Audit a browser extension's permissions — a practical, example-driven guide with honest tool comparisons and a clear place for WebSnips. Written for Lawyers.
How to avoid vendor lock-in with your notes — a practical guide for individuals and teams who want to keep their personal knowledge base portable, format-independent, and recoverable regardless of which application or service they use.
How to back up your notes safely — a practical guide for individuals and professionals who want reliable, secure backups of their personal knowledge base, covering backup strategies, encrypted backup tools, and recovery testing for note-taking applications.
How to capture sensitive research securely — a practical guide for researchers, journalists, legal professionals, and privacy-conscious individuals who need to gather and store sensitive information without creating avoidable exposure through insecure capture tools or storage practices.
How to choose a private web clipper — a practical guide for privacy-conscious researchers, journalists, and professionals who want to clip and save web content without exposing their browsing patterns, source materials, or clipped content to third-party services.
How to comply with GDPR in your knowledge base — a practical guide for teams and organizations who store personal data in their internal wikis, documentation systems, and knowledge management tools, covering data minimization, retention policies, access controls, and subject rights.