Search you can trust with a diary
A notes app holds grocery lists, private worries, and the first draft of something you have not told anyone about. Finding a note should not mean handing all of that to a search service.
Beauty runs on iPhone, iPad, Mac, and the web, and every version shares the same local search engine. It finds words, phrases, file paths, and common variations like plurals. On compatible Apple devices, an optional "related results" layer can also surface relevant passages using Apple's on-device models. Neither path sends your queries or your notes to a Beauty server or a cloud AI service.
That privacy rule shaped everything else. The index lives next to your notes. Expensive work gets a fixed budget. And a good direct match shows up immediately, while the smarter search is still working.
The interactive figures in this article use a tiny made-up library and the real limits from our code. They illustrate the design; they are not timing benchmarks, and your device may be faster or slower.
An index, so we never reread every note
Rereading every note on every keystroke would make search slower with every note you add. Instead, Beauty keeps an inverted index: for every word, a list (called a posting list) of the notes that contain it.
For a multi-word query, the engine starts with the rarest word's matches and checks the other words only within those. Ranking keeps a small top-k heap of the best hits instead of sorting every match just to show one page. The index points to candidates; a final check against the actual note text makes sure every result reflects what is really there.
The matching rules are deliberately precise. Ordinary English words can match regular forms, so "skies" finds "sky," but only when that form actually appears in your notes. Quoted terms match exactly. The last word you are typing matches as a prefix until you add a space. Longer words tolerate a small typo when there is no exact match.
None of this needs a language model. It also respects what you asked for: search for a quoted function name and you get that exact name, not a creative guess. Match strength, title matches, and word rarity all feed into ranking; the weight given to a word form is not a confidence score.
Show something useful right away
Fast search is partly doing less work, and partly showing results sooner. Title and folder matches appear before Beauty has finished reading note bodies. Direct matches always come first; related results can arrive later without holding them up.
Indexing and searching also take turns with the rest of the app. Work runs in small time slices, six milliseconds by default and four in some places, then hands control back to the event loop so the app stays responsive. These are targets, not guarantees: a slow disk read or a busy system can still take longer.
Show something useful. Then keep going.
Search works in small slices and hands the app back between them, so typing never waits for a search to finish.
A drawing of the scheduling idea, not a trace. Six milliseconds is the default slice, four in some places; a slow disk or a busy system can still take longer. Related results are optional and never hold up direct ones.
When saving the index, Beauty writes in batches rather than paying the cost of a separate encrypted write for every tiny record. It writes the index root last, after the pages it points to, and recovery logic makes sure an interrupted update never shows up as the current index. The page cache and on-disk index each have their own size limits; those are not a promise about the whole app's memory use.
The interface gets the same care. Old results stay on screen while new ones load, but you cannot accidentally open a stale result as if it matched your new query. Beauty also waits a beat before showing "nothing found," so it does not flash on and off in the middle of a word. The goal is a search box that feels calm even while a lot is happening underneath.
Let the AI read a little, carefully
An index is perfect when you remember a word. Sometimes you only remember the idea. On supported Apple devices, related search uses Apple's Foundation Models on-device to expand your query and judge relevance. Word embeddings from Apple's Natural Language framework can suggest related terms. Beauty does not compute or store an embedding for every note.
Every suggestion still has to exist in your library. Proposed terms are checked against the index, and indexed lookups pick the candidate passages. We never push your whole notebook through a prompt. Anything already in the direct results is removed, and a small, fixed set of passages goes on to be judged one by one.
The limits are concrete: at most 16 index lookups, at most 64 candidates, and at most 12 passages selected for judging. Each passage is capped at 800 UTF-16 code units. Each ranking request carries a single passage, and requests run one at a time.
Twelve passages at 800 code units each caps the selected passage text at 9,600 code units. The query, titles, and instructions add a little on top, and code units are not the same as model tokens. Duplicates of direct hits, unreadable text, or invalid candidates can make the real set smaller.
This work only starts once you pause typing. If it does not finish, it can resume once; a failed attempt retries only after an idle interval. Either way it continues with the same selected passages rather than quietly grabbing twelve more. Judgments that finished before the deadline are kept, so good results do not vanish just because later ones ran out of time.
Cancellation gets the same care. A new query cancels the old work, and content hashes make sure a judgment about an old version of a note is never reused for the new one. Some system calls cannot be stopped instantly, so Beauty keeps counting them until they finish. Memory or heat pressure can cause the system to refuse or cancel AI work. The deadline limits how long the interface waits, not how fast the operating system must finish every call.
Find notes by what is in their pictures
Often the thing you remember is in an image. File names and image descriptions you wrote are searchable everywhere. On Apple devices, on-device Vision analysis can also add text found in the image and labels for objects and scenes.
Image analysis has its own queue and cache limits. It works from bounded snapshots and thumbnails instead of feeding every full-size camera photo to a model. Results are tied to the specific image, so replacing or deleting it throws the old analysis away. Your Markdown is never rewritten.
Richer, AI-generated image descriptions are a separate feature with stricter operating system, compiler, and model requirements, and not every installation has them. We keep that line clear so basic image search never depends on something your device may not support.
What is encrypted, and what is not
Everything search saves to disk stays on that device and is kept out of the synced library folder. These records are sealed with AES-256-GCM, and if encryption fails, Beauty does not fall back to writing the search cache unencrypted.
That does not mean Beauty encrypts every note. The Mac library is intentionally plain Markdown files. The private library on iPhone and iPad and the browser's local storage work differently. And encryption at rest has limits: anyone with access to your unlocked device or browser profile may be able to reach its keys and data.
Optional iCloud sync is its own boundary. It moves your library between your Apple devices, so "search stays on device" does not mean nothing ever touches the network once sync is on. Connecting an external AI client is also separate and opt-in, and that client has its own data practices. Local search needs neither.
Search stays inside. You decide the rest.
Toggle the optional connections. Search itself never needs either of them.
- Your queryParsed and answered here✕ never sentBeauty serversNever receive queries or notes
- Related passagesJudged by Apple’s on-device model✕ never sentCloud AI servicesNever used for search
- Index & image analysisSealed with AES-256-GCMstays localSynced library folderSearch caches are kept out of it
- Notes, folders, imagesPlain Markdown on Macyou turned this onYour iCloudOptional sync between your devices
- Notes you choose to shareOnly when you connect oneoffExternal AI clientOpt-in, with its own data practices
Crossing the boundary right now: Your iCloud. None of it is search.
Encryption at rest has limits: anyone using your unlocked device or browser profile may reach its data. The Mac library is intentionally plain Markdown files.
What you need for each feature
Word search works everywhere, with or without Apple Intelligence. Related results need Apple Intelligence-compatible hardware, iOS, iPadOS, or macOS 26 or later, Apple Intelligence turned on, the model downloaded, and a supported language. If any of that is missing, regular search keeps working.
Offline search assumes the app, your notes and images, and any optional system models are already on the device. Loading the website or downloading a model for the first time is a different story.
The principle behind all of it: do the smallest useful piece of work first, keep the evidence close to the text, and make the expensive work earn its place. Your notes never have to leave your desk to be found.
See the changelog for recent improvements, or read about offline writing with local files.