Apple Notes NoteStore.sqlite: macOS Notes Forensics
NoteStore.sqlite holds Apple Notes on macOS: note text as compressed protobuf, folders, accounts, attachments, locked notes and Recently Deleted items.
- Location
- ~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite
- Proves
- What a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the database
- Timestamps
- Mac absolute time (seconds since 2001-01-01 UTC)
- Access
- Owning user; the group container is TCC-protected, so the collector needs Full Disk Access
- Retention
- Until deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free list
- Collection
- UAC, mac_apt, ditto, Disk image
Tools
Compare all tools- apple_cloud_notes_parserCLI · open source
- mac_aptCLI · open source
- sqlite3CLI · built into macOS
What it is
Apple Notes stores every note, folder and attachment reference in a Core Data SQLite database, NoteStore.sqlite, shared by the app and its extensions through a group container. The same schema is used on iOS, so tools and research apply to both. Notes synced through iCloud, notes kept "On My Mac" and notes in legacy IMAP accounts all appear, flagged by account.
People use Notes for passwords, to-do lists, meeting notes, drafts and pasted material. In insider and fraud cases it is often the most candid source on the machine.
Where it lives
| Source | Path | Notes |
|---|---|---|
| Database | ~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite (+ -wal, -shm) | Current format since about 10.11 El Capitan |
| Attachments | ~/Library/Group Containers/group.com.apple.notes/Accounts/<account>/Media/<UUID>/ | Images, PDFs, scans, audio |
| Previews | .../Accounts/<account>/Previews/, FallbackImages/, FallbackPDFs/ | Rendered thumbnails of attachments and drawings |
| Legacy stores | ~/Library/Containers/com.apple.Notes/Data/Library/Notes/NotesV*.storedata | Pre-El Capitan data, kept on upgraded Macs |
What it proves
- The content of each note at the time of acquisition, including checklists, tables and links.
- When a note was created and last modified, its folder, and whether it is pinned, shared or locked.
- Which account it belongs to (iCloud, On My Mac, IMAP), which tells you whether it also exists on other devices and in iCloud.
- Deleted notes: items in Recently Deleted remain full rows; hard-deleted ones may survive in the WAL, free pages or Spotlight.
Locked notes are encrypted with a key derived from a separate Notes password or, since the iOS 16 / macOS 13 generation, optionally the device passcode or login password. Without it you see dates and metadata (and sometimes the title), but not the body.
Key fields
Most rows sit in the polymorphic ZICCLOUDSYNCINGOBJECT table; column suffixes (1, 2, 3) shift between releases.
| Table / column | Meaning |
|---|---|
ZICCLOUDSYNCINGOBJECT.ZTITLE1 | Note title (first line) |
ZSNIPPET | Short preview text |
ZCREATIONDATE*, ZMODIFICATIONDATE1 | Created, last modified |
ZFOLDER, ZACCOUNT* | Folder and account links |
ZISPASSWORDPROTECTED | Locked note |
ZMARKEDFORDELETION | Deletion pending sync |
ZNOTEDATA → ZICNOTEDATA.ZDATA | Gzip-compressed protobuf with the note body |
ZIDENTIFIER, ZTYPEUTI (attachments) | Attachment UUID and type, joining to the Media folder |
The note body is not plain text in SQLite: ZDATA is gzip-compressed and holds a protobuf document with text and attribute runs. Keyword searches on the raw database miss it unless you decode first.
Timestamps
All dates are Mac absolute time. Convert with datetime(col + 978307200, 'unixepoch'). For iCloud notes, modification times reflect edits on any device on the account, so a note "modified" at 03:00 may have been edited on an iPhone.
Retention
- Recently Deleted keeps notes for about 30 days before removal.
- After removal, rows are deleted from SQLite. Check the
-walfile, freelist pages and older copies in APFS snapshots and Time Machine. - iCloud notes can be recovered from other devices or an iCloud account export when legally available.
Collection
sudo ditto "/Users/<user>/Library/Group Containers/group.com.apple.notes" ./case/notes_<user>
Copy the whole container, not only NoteStore.sqlite, so the WAL and the attachments stay consistent. Quit Notes first on a live system if possible. UAC collects NoteStore.sqlite*; mac_apt NOTES reads the current and legacy stores.
Parsing
# Full decode to HTML/CSV, including embedded objects and locked-note metadata
ruby notes_cloud_ripper.rb --mac ./case/notes_<user> --output-dir ./out
# Quick list of titles and dates
sqlite3 -readonly NoteStore.sqlite "
SELECT ZTITLE1, datetime(ZMODIFICATIONDATE1 + 978307200, 'unixepoch') AS modified_utc
FROM ZICCLOUDSYNCINGOBJECT WHERE ZTITLE1 IS NOT NULL ORDER BY ZMODIFICATIONDATE1 DESC;"
apple_cloud_notes_parser (Three Planets Software) decodes the protobuf, tables and embedded objects, and can decrypt locked notes that use a separate Notes password when you have it and the authority to use it (-w password list). Its documentation states that notes locked with the device passcode are not yet supported. mac_apt NOTES gives a quicker overview.
Investigator tips
- Check both the Notes body and the attachment
Mediafolders: scanned documents and pasted screenshots often matter more than text. - Compare modification times with KnowledgeC and Biome app focus records to show the note was edited on this Mac.
- Notes shared with other iCloud users carry participant information; treat it as a communication record like Messages.
- A locked note still exposes when it was created and modified, which can be enough to contradict an account of events.