May 2026  ·  Deep Dive

What Is Nostr Vault?
The Personal Relay You Actually Control.

A plain-language walkthrough of everything Nostr Vault does — from running four relay types in a single app to sweeping on-chain Bitcoin straight from your nsec.

← Back to Home

Most people on Nostr post their notes to public relays they don't own. Those relays go down, get censored, start charging, or simply disappear — and so do the notes on them. Every like, every reply, every DM you've ever sent exists only as long as a stranger chooses to keep it online. That's not sovereignty. That's renting a shelf in someone else's storage unit and hoping they don't change the locks.

Nostr Vault is a personal Nostr relay. Its primary job is to run on your own hardware — your Mac, your iPhone — and act as a permanent home for every note you post, receive, or get tagged in, regardless of what happens to the public relays where those notes originally appeared. It watches the network, pulls notes that mention you, stores them locally, and keeps them safe. The notes survive because you keep them, not because some relay operator happens to.

Think of Nostr Vault less like a Twitter client and more like a personal mail server — one that also has a built-in email app for reading and writing. The relay and the backup system are the core; the client is a bonus that comes with the package.

Yes, Nostr Vault includes a full feed, compose view, zaps, and media viewer. You can use it as your daily Nostr client. But that's not what makes it different from every other Nostr app. What makes it different is that everything you do flows through a relay you control, and your notes exist on infrastructure you own.

Why a Personal Relay Matters

Nostr is a protocol, not a platform. The protocol guarantees that your identity (your key pair) is yours forever — no one can take it. But the protocol doesn't guarantee that your notes are preserved anywhere. Notes live on relays. Relays are servers. Servers go offline.

The standard advice is to post to multiple public relays so your notes are redundant. That helps, but it doesn't solve the underlying problem: you're still dependent on relays you don't control, and those relays don't actively watch the network to collect all events that involve you. If someone replies to your note on a relay you don't monitor, you might never see that reply. If a zap receipt lands on a relay that goes offline before you sync, it's gone.

A personal relay solves this differently. It's your server, running on hardware you own. It actively pulls events that tag you from the broader network. When you post a note, it gets stored locally first and blasted to the network second — so even if every public relay vanished tomorrow, your notes would still exist on your device. Other clients can connect to your relay directly and fetch your full history. Your relay is your source of truth.

Where It Came From

The Go code at the heart of Nostr Vault comes from bitvora/haven — HAVEN (High Availability Vault for Events on Nostr), the most sovereign personal relay in the Nostr ecosystem. That codebase is MIT-licensed, community-audited, and runs relay infrastructure for some of the most privacy-conscious people on Nostr.

The Mac and iOS wrapper is a fork that does something technically unusual: instead of shipping the Go relay as a separate process or a Docker container, it compiles the entire Go codebase into a static C library (libhaven.a) and links it directly into the Swift app binary. One process. No helper daemons. No orphaned background jobs. The relay and the UI are a single executable that you can cryptographically verify yourself.

The Four Relay Model

Most relays do one thing: accept events and serve them back. Nostr Vault runs four distinct relay types simultaneously, each with its own access rules, purpose, and endpoint. Together they give you complete control over who can read your notes, who can write to your relay, and where your messages get stored.

Private Relay

Your locked vault

Only the relay owner and explicitly whitelisted npubs can read or write here. Protected by NIP-42 Auth. Use it for draft notes, encrypted messages, or anything you never want a third party to see.

Chat Relay

Trust-gated DMs

Accepts only encrypted DMs and group chat events (NIP-04 and NIP-17 kinds). Anyone in your Web of Trust can reach you here, but strangers are locked out automatically by Auth.

Inbox Relay

Where the world tags you

Zaps, reactions, replies — any event that tags the relay owner or a whitelisted npub arrives here. The relay actively pulls tagged notes from other relays so your inbox is always complete, even when you're offline.

Outbox Relay

Your public broadcast tower

Your notes live here and are publicly readable by anyone. When you publish, your note is simultaneously "blasted" outward to your configured list of seed relays, ensuring maximum reach across the Nostr network.

This isn't just theoretical structure — every relay type runs on a separate endpoint under the same local server, so your Nostr client can connect to each one independently. The private relay at /private is completely unreachable to anyone who doesn't have your credentials, while the outbox at / can be publicly advertised in your Kind 10002 relay list.

Blossom: A Built-in Media Server

Text-only Nostr isn't enough for most people. Nostr Vault ships a full Blossom media server (BUD-02 compliant) alongside the relay. When you post a photo or a video, it gets uploaded to your own Blossom instance first, then mirrored to one or more public Blossom hosts you configure. The URL that goes into your note points to an external mirror — so even if your local relay is offline, your media stays visible.

Upload authentication uses Nostr's BUD-02 spec: a signed kind 24242 event with operation-type tags, a SHA-256 hash of the file, and an expiration time. Only you (and whitelisted npubs) can upload. Anyone can view. Media files are stored on-device and can be exported, backed up, or migrated at any time.

The media viewer inside the app supports images, GIFs (with animated playback), videos, and audio files. MIME types are detected via both file extension and magic bytes, so extensionless Blossom hashes display correctly without guessing.

Web of Trust: Spam Protection That Doesn't Rely on Centralized Lists

Nostr is permissionless by design, which means without some kind of filter, your relay would fill up with spam and unsolicited content immediately. Nostr Vault uses a Web of Trust (WoT) system derived from your follow graph to decide who can reach you.

The idea is simple: if you follow someone, or if someone you follow follows them, they're in your WoT. The chat and inbox relays enforce this automatically — someone three hops outside your graph can't drop a DM into your inbox. You configure the depth (how many hops counts as "trusted") and the refresh interval (daily, weekly, etc.) from the Settings panel. The WoT graph is cached locally so startup is fast even when the network is slow.

For finer control, you can supplement WoT with explicit whitelist and blacklist management. Whitelisted npubs get full relay access regardless of WoT status. Blacklisted npubs are rejected at the connection level before they can even send a message. Blocks are per-account and sync to the Nostr Kind 10000 mute list, so your blocks stay consistent across other Nostr clients too.

Lightning Zaps and NWC

Nostr Vault integrates Lightning payments through Nostr Wallet Connect (NWC). Connect your existing Lightning wallet — Alby, Mutiny, or any NWC-compatible wallet — and you can send zaps directly from the feed, note detail, or profile view.

Zapping is not a background operation you fire and forget. There's a live animated notification banner that tracks each payment in real-time: Zapping… transitions to Zapped! (or Zap failed) with a pulsing lightning bolt animation. Zap history is tracked per-account and displayed in dedicated Likes & Zaps tabs with stacked avatar previews and satoshi totals.

When you reply or react to someone else's note, Nostr Vault automatically fetches their Kind 10002 relay configuration and delivers your response to their inbox relays directly. Your zap or reply doesn't just go to a generic public relay and hope for the best — it goes where the recipient actually reads.

Your nsec is your key to the Lightning network. And, now, your key to the Bitcoin blockchain.

On-chain Bitcoin: Your nsec Is Your Wallet

This is the feature that makes Nostr Vault unlike any other Nostr client. Your Nostr private key (nsec) is a secp256k1 key pair — the same cryptographic primitive that Bitcoin uses. Nostr Vault takes that insight seriously.

Inside the embedded Go relay, there is a native BIP-341 Taproot (P2TR) address derivation routine. Using btcsuite/btcd, it derives a key-path-only Taproot address directly from your Nostr public key. You get a real Bitcoin address you can receive funds to — no separate wallet app, no hardware device, no seed phrase import.

When you're ready to move the coins, the Bitcoin Sweep flow:

  1. Fetches your UTXOs from a self-hosted Mempool instance you configure.
  2. Displays your spendable balance in sats and the live BTC/USD fiat equivalent.
  3. Constructs a raw Taproot transaction using key-path spending (tapTweakHash).
  4. Signs it with Schnorr signatures using your nsec (the same key you use to sign Nostr events).
  5. Broadcasts the transaction directly to the network.

No external process. No browser extension. No third-party signing service. The entire transaction lifecycle happens inside the app, in the same Go code that runs your relay. The sweep also renders on-chain Taproot zap receipts alongside standard Lightning zap receipts in the UI, so the two payment rails feel equally first-class.

This is not a replacement for a dedicated Bitcoin wallet with proper UTXO management and coin control. It's a sweep tool for moving funds you've accumulated at your nsec-derived address into a wallet of your choice. The Bitcoin address is deterministic from your nsec, which means it's always recoverable and always yours.

Keys, Encryption, and the Keychain

Your private key is the most sensitive piece of data on your device. Nostr Vault never stores your nsec in plaintext. It uses NIP-49 encryption (ncryptsec) to wrap your key with a password you choose, using scrypt as the key derivation function.

The password itself lives in the macOS or iOS system Keychain, not in app storage or iCloud sync. When you open the app, the Keychain supplies the password to decrypt the ncryptsec, the key is used for signing, and then it's discarded — it never sits in memory longer than necessary and never touches the filesystem in readable form.

For multi-account setups, each identity is stored separately. You can fast-switch between accounts from anywhere in the app using a long-press on the Profile tab on iOS, or the account selector in the Mac sidebar. Each account has its own block list, its own relay configuration, and its own cached WoT graph.

The Built-in Client: A Bonus, Not the Point

Because Nostr Vault already has your keys and your relay, it can also function as your primary Nostr client — and it does. But it's worth being honest about the hierarchy here: the relay comes first. The client exists so you don't need a separate app to use your relay. If you already have a Nostr client you love, connect it to your Nostr Vault relay and keep using it. Your relay will still back up everything you post there.

For those who do use the built-in client, it's fully-featured: Following and Global feed modes, real-time note streaming, threaded replies with visual connectors, reposts with expanded parent notes, and live engagement stats fetched via NIP-45 COUNT queries (which give accurate counts instead of the capped results you get from standard subscription limits).

Composing a note supports live @mention tagging from your follow list, emoji picker integration, and automatic NIP-89 client tagging. When you reply or react to someone, Nostr Vault looks up their Kind 10002 relay list and delivers your response to their actual inbox relays rather than hoping they happen to read from wherever you publish.

The UI adapts to each platform. On Mac, the relay lives in the menu bar; the main interface is a popout window with a sidebar, a dedicated Search tab, and multi-source search across users, notes, links, and hashtags. On iPhone it's a floating "Liquid Glass" tab bar with spring animations. On iPad it's a full NavigationSplitView sidebar layout. Every platform gets a native experience, not a web view wrapper.

Mac as Your Always-On Home Base

The most powerful configuration is a Mac running Nostr Vault 24/7 behind a domain name. With a reverse proxy (Nginx, Caddy, or Apache) pointing relay.yourdomain.com at the local port, your relay becomes publicly reachable. Other people can follow you on your own relay. Other clients can sync directly to your outbox. Your notes exist on infrastructure you own.

The iOS app integrates with this setup through Mac Relay Sync: when you open Nostr Vault on your phone, it connects to your always-on Mac relay and pulls any notes you missed while your phone was offline or asleep. Pull-to-refresh in the feed triggers a manual sync. This means your phone's feed is always anchored to a relay you trust rather than patched together from whatever public relays happen to be online.

If you don't have a Mac or a domain, the iOS app still runs a local relay that acts as a private Blastr: it broadcasts your notes outward to your configured relay list, keeping your notes alive across the network even when you're not publishing from a dedicated server.

Backup and Recovery

Sovereignty means nothing if you lose your data. Nostr Vault uses a portable JSONL format for note backups — one event per line, human-readable, importable into any HAVEN-compatible relay. You can export manually from the Dashboard at any time, or configure periodic cloud backups to any S3-compatible storage provider.

Restoring is equally straightforward: import a .jsonl file or a .zip archive through the Settings panel or the Setup Wizard. Checksum and integrity verification run automatically before any data is written, so a corrupted backup fails loudly rather than silently overwriting good data.

Blossom media is backed up separately. The Setup Wizard includes a dedicated media restore step that can pull your media library from a remote Blossom server over the network, so even a fresh install on a new machine can recover your full media history without manual file transfers.

Open Source, Verifiable, and Yours

Nostr Vault is fully open source. The Go backend is MIT-licensed and can be audited, compiled, and verified independently of the Swift wrapper. The build script for the Go static library is wired into Xcode's build phases, and the full build and verification instructions are documented in the repository. You don't have to trust the binary — you can build it yourself.

The iOS version is available on TestFlight. The Mac version is available as a signed download from the GitHub releases page. Both targets share the same Go relay binary and the same Swift service layer — the codebase is genuinely unified, not two separate apps that happen to look similar.

If you've been waiting for a reason to run your own relay — one that doesn't require a Linux VPS, a Docker compose file, or an afternoon fighting with nginx configs — this is it. Install it. Run it. Keep your notes.

Ready to own your relay?

Native on Mac, iPad, and iPhone. Bitcoin-aware. Encrypted by default. Verifiable from source.

Join iOS TestFlight Download for Mac View Source