All writing
Last updated Sep 1, 20268 min read

Self-hosting your second brain, and why data ownership stopped being paranoid

Self-hostingSupabaseData ownership

In short

A self-hosted second brain means your notes live in a database you control rather than a vendor's cloud. In practice this usually means Postgres — with pgvector for semantic search — running on a host you own, on infrastructure you can point at. The tradeoffs are honest: you take on backups, upgrades, and availability, and you give up the polish of a well-funded product team. What you get is a real export path, the ability to query your own data with SQL, no per-seat pricing on your own thoughts, and immunity to a product decision made in a meeting you were not in. For a knowledge base you expect to keep for a decade, that last point does most of the work.

Every note-taking tool makes a bet about where your notes should live, and the bet is usually invisible until it costs you something.

Notion bets on their cloud. Everything is a block in their database, the collaboration is genuinely excellent, and the export is a zip of HTML or markdown that loses most of the structure that made it useful. Obsidian bets on local files, which is a strong position — plain markdown on your disk, yours forever — and then you spend a weekend on sync and another on plugins to get search that works across devices. Evernote bet on their cloud too, and then spent several years teaching a large number of people what it feels like when a company you have trusted with a decade of notes changes its pricing and its priorities.

There is a fourth option that has quietly become reasonable: run a database you control, and build on top of it.

What "self-hosted" means here

It is a loaded term, so let me be specific about the version I mean.

Not: a server in your closet. Not: you become a sysadmin. Not: you compile things.

What I mean is that the database is yours — a Postgres instance under your account, on a provider you chose, that you can connect to with any Postgres client, back up with pg_dump, and point at a different application tomorrow. The app that renders your notes is replaceable. The data underneath it is not going anywhere without your say-so.

Supabase is the path of least resistance here, though the argument holds for any managed Postgres. You get Postgres with row-level security, auth, and pgvector for embeddings, on a free tier that comfortably fits a personal knowledge base. It is your project, in your account, with your connection string.

The distinction that matters is not "who runs the server." It is who can revoke your access.

Why Postgres specifically

Once your notes are in a real relational database, some things become easy that are otherwise impossible.

You can query it. Your notes are rows. Which tags do I use most and never revisit? Which projects have tasks that have been open more than sixty days? How much did I write each month last year? These are four-line SQL queries. In a closed product they are feature requests, and the answer is usually no.

Semantic search comes nearly free. pgvector adds a vector column type and the index types to search it. Your embeddings live in the same database as the text they came from, in the same transaction. No second datastore, no sync job between your notes and your search index, no class of bug where the two disagree.

Relationships are actual relationships. A note linked to a task linked to a project is three rows and two foreign keys. The knowledge graph is not a feature someone built — it is a query over data that was already shaped correctly.

The backup story is boring, which is the highest compliment. pg_dump produces a file. That file restores into any Postgres anywhere. This is thirty-year-old technology and it will outlive every note-taking startup currently operating.

The honest costs

Anyone who tells you self-hosting is free is selling something.

You own the operations. Nobody is paging themselves at 2am because your notes are down. If you skip backups, you have no backups. The mitigating fact is that managed Postgres has made this dramatically less demanding than it was — automated backups are a checkbox, upgrades are mostly a button — but it is not zero, and pretending otherwise is how people lose data.

You give up a product team. A well-funded company shipping a note-taking app full-time will out-polish you on mobile, on offline sync, on the hundred small interactions you never think about until they are missing. Real-time collaborative editing in particular is genuinely hard, and if you need several people typing in the same document simultaneously, this is the wrong tradeoff and Notion is a good product.

There is a setup cost. It is a project, an environment variable, and a schema migration rather than a signup form. Twenty minutes if things go well. Some people will bounce off that, entirely reasonably.

When ownership actually pays

The argument for owning your data usually gets made in the abstract — sovereignty, lock-in, principle — and abstract arguments are easy to nod at and ignore. The concrete versions:

Pricing changes. A tool you have used for four years introduces a seat minimum, or moves the feature you depend on into a higher tier. If your data is in their cloud, your options are pay or lose the workflow. If your data is in your Postgres, your option is to keep using it.

Product direction changes. The tool pivots to enterprise, or to AI, or to whatever the market is rewarding this year, and the thing you loved gets deprioritized. This happens constantly and it is nobody's fault — it is just what companies do. It is only a catastrophe if you cannot leave.

Shutdown. Rarer than the internet suggests, but not rare enough. Usually there is a merciful window and an export button. Sometimes the export is bad.

You want to build something. This is the underrated one. Once you have SQL access to your own notes, you can write the small tool you have always wanted — a weekly digest, a script that flags notes nobody has opened in a year, a custom view for one specific project. Not a plugin API someone designed for you. Actual queries against actual data.

The pattern in all four: ownership is worth nothing right up until the moment it is worth everything, and you cannot buy it retroactively.

What this does not solve

Being fair to the alternatives.

Self-hosting does not make your data more private from yourself, and it does not automatically make it secure. A misconfigured Postgres with row-level security disabled and a public connection string is considerably worse than Notion's cloud. You have to actually turn the locks.

It does not solve sync. It relocates it. Your data being in Postgres means every client hits the same database, which is a simpler model than file sync, but it does mean you are online or you are working from cache.

And it does not make the app good. A well-designed product on a closed backend beats a badly-designed one on an open backend every single day of the week. Ownership is a floor, not a ceiling. It guarantees you can leave. It does not guarantee you will want to stay.

The ten-year test

Here is the question I find clarifying: where do you want your notes to be in ten years?

Not next quarter. Ten years. A second brain is a compounding asset — its value comes almost entirely from accumulation, from the note you wrote in 2019 turning out to answer a question you have in 2029. That only works if the notes survive continuously, and surviving ten years means surviving pricing changes, acquisitions, pivots, and at least one product decision you strongly disagree with.

A zip of markdown in a folder passes that test. A Postgres dump passes it. A proprietary cloud with a lossy export button probably does not, and you will not find out which until the day you need it to.

That is the whole argument, and it is not really about technology. It is about which failure you would rather be exposed to: the inconvenience of running a database, or the possibility that a decade of your thinking becomes read-only in someone else's product.

For most notes, most of the time, either is fine. For the ones you would be upset to lose, the choice makes itself.

Frequently asked questions

What does self-hosted mean for a second brain?

Self-hosted means the database is yours — a Postgres instance under your account, on a provider you chose, that you can connect to with any Postgres client, back up with pg_dump, and point at a different application tomorrow. The app that renders your notes is replaceable. The data underneath it is not going anywhere without your say-so.

Why Postgres for a note-taking app?

Once your notes are in Postgres, some things become easy: you can query your notes with SQL (which tags do I use most?), semantic search comes nearly free via pgvector, relationships between notes/tasks/projects are actual foreign keys, and the backup story is boring in the best way — pg_dump produces a file that restores into any Postgres anywhere.

What are the costs of self-hosting a second brain?

You own the operations (backups, upgrades), you give up a product team (mobile, offline sync, collaborative editing), and there's a setup cost (typically 20 minutes with managed Postgres). Managed Postgres has made this dramatically less demanding than it was, but it's not zero.

When does data ownership actually matter?

When pricing changes (a tool introduces a seat minimum), when product direction changes (the feature you depend on gets deprioritized), when shutdown happens (rare but not rare enough), or when you want to build something custom on your own data. Ownership is worth nothing right up until the moment it's worth everything, and you can't buy it retroactively.

Is self-hosting more private than using Notion?

Self-hosting doesn't automatically make your data more private or secure. A misconfigured Postgres with row-level security disabled and a public connection string is considerably worse than Notion's cloud. You have to actually configure the security controls. The benefit is that you have the option to lock it down — the data is in your hands.

Keep reading

Stop re-deriving what you already knew.

EngineerOS indexes every note and task as you write, then answers questions with citations back to the source.