Two safety nets, both on by default.
Deleting a page (⇧⌘D) shows an Undo button for a few seconds —
one click and the page is back where it was. Beyond that, nothing is destroyed:
the page moves to File ▸ Recently
Deleted…, where it can be restored with one click for 30 days. After
that it's quietly purged. Delete Forever is there when you mean it (and asks
first). Trashed pages vanish from search, links, exports, and the page list immediately —
they're gone from the wiki, just not gone from the world.
A clear-out is rarely one page. Each row has a check: choose a few, or shift-click for a run, and the buttons at the foot count what you chose — Restore 12 or Delete 12 Forever. Empty clears the whole bin. Both destructive ones ask first and say how many, and the window stays open afterwards so you can keep going rather than reopening it each time.
Restoring says what really happened, which matters when a page came from a followed folder: if its file is gone from disk, the page comes back as a page of its own and you are told how many did that, rather than being told everything was fine.
A connected assistant cannot see them either. Everything above is true of anything reading your wiki from outside: a page in here is not listed, not searched, and never the answer to a question about the page that replaced it. Restore it and it comes back to both at once. See AI Agents.
While you edit, MojoPad quietly snapshots the page — at most one snapshot every ten minutes. History thins as it ages instead of cutting off: everything from the last two days is kept, then one snapshot per day for a month, one per week for a year, one per month beyond that — so "how did this note read last spring?" still has an answer without the document swelling. Open them from Edit ▸ Page Versions… or by right-clicking a page in the sidebar ▸ Page Versions…. Each snapshot is listed by how long ago it was taken; click one and it renders in a preview beside the list — headings, lists, and formatting as they were, not just raw text. Click Restore this version to bring it back. Restoring is itself reversible: the current state is snapshotted first, so you can step back and forth. (Encrypted pages are never versioned — no plaintext left behind.) This is the answer to "I rewrote this paragraph yesterday and it was better before."
MojoPad quietly zips a complete copy of your document every time you open it,
and once an hour while it stays open and keeps changing — long sessions get
checkpoints too. Want one on demand — say, right before a big reorganization?
File ▸ Back Up Now. File ▸ Show Backups in Finder takes you to them.
File ▸ Save a Copy As… is the other half of this: it writes a complete second copy
of the whole document wherever you choose — the package, not just the pages — and leaves
you working in the original. The thing to do before a risky bulk edit, or when an existing
wiki is the right starting point for a new one. To
restore one: unzip it, and the result is a normal .mojopad document — open
it, or pull pages from it with File ▸ Merge Document….
Out of the box, backups live in MojoPad's own folder, and they never overwrite each other across documents. They are in addition to whatever Time Machine or your sync service does — belt, suspenders.
Eight copies of each document are kept. That is generous and invisible at a few megabytes a document — and quite different if your wiki is a gigabyte and a half, where eight copies ask for twelve gigabytes of a disk you may not have, or of an external drive you cannot always carry with you.
So set it: Settings ▸ Files & Backups ▸ Copies to keep of each document. Anything from one to fifty. If you work mostly in small documents, leave it alone.
Two things worth knowing about how the clearing out works:
Help ▸ Save Diagnostic Report lists what is actually on your disk — every copy with its size, the total, and a line calling out any document holding more copies than your setting, which is how you spot the ones that will never be cleared.
Backups and passwords. A backup is a complete copy of the document as it was when the copy was made — so backups taken before you set a password are unprotected copies of a document that is now protected. When you set a password, MojoPad takes a fresh backup under it and then tells you how many unprotected ones exist and how much space they take, and asks whether to remove them. It never removes them on its own, for a reason worth sitting with: those copies are also the only way back into the document if you forget the password, and there is no recovery. Removing them is a real trade, so it is yours to make. Note too that deleting a file asks the disk to forget where it was, which is not the same as scrubbing it — and if your backups folder is a synced one, copies may already have gone somewhere MojoPad cannot reach.
Real backups belong on a different disk. Settings ▸ Files & Backups ▸ Backups ▸ Keep backups in lets you point the automatic copies anywhere — an external drive, a NAS folder, or inside Dropbox or iCloud Drive so they leave the machine entirely. Click Choose…, pick a folder, and every backup from then on (automatic, hourly, and Back Up Now) lands there; File ▸ Show Backups in Finder follows along. Reset returns to the built-in location.
One promise worth knowing: if your chosen folder ever isn't reachable — the drive is unplugged, the volume unmounted — MojoPad does not skip the backup. It quietly falls back to the built-in folder, so there is always a copy somewhere.
Keep a document in Dropbox, iCloud Drive, or on a shared network volume and MojoPad looks after two things that trip up file-based apps used from more than one place.
Every save is all-or-nothing. A save lands completely or not at all, so a sync service copying your document mid-save can never grab a half-written file — it always sees a whole, valid document.
It notices edits from another machine. If the same document changes on a second computer while you have it open here, a quiet bar slides in: This document was changed on another device, offering Reload (take the latest from disk) or Keep mine (keep what's in front of you). While it waits for your choice, MojoPad holds your own saves, so the two machines can't quietly overwrite each other. MojoPad still works on one copy at a time — it doesn't merge simultaneous edits — but you'll always get a choice instead of a surprise. The bar comes up for a change to a page and for a change to how the wiki is arranged — a folder added or renamed, a page filed, a pin — made on the other machine.
While the bar is up, the arrangement waits. Moving a page into a folder (one you follow included), making, renaming, removing or reordering a folder, pinning, changing the folder focus or the sort, making, changing or deleting a property or a kind, saving a desk, making a saved view or changing one (a filter, a column, the sort, its name), importing, deleting a page or bringing one back, deleting one for good or emptying Recently Deleted, locking a page with a password or taking its password off, setting, changing or removing the wiki's own password, moving a page or a folder to another wiki, and switching the window to another wiki: each of these is turned down before anything on screen changes. If the bar comes up while you are typing a page's password, or answering whether to take it off, the page is left as it was; the same goes for choosing where to move a page or a folder to another wiki, or which column a saved view should use — nothing is moved or changed. If it comes up while you are asked about deleting pages for good, nothing is deleted and what you checked in Recently Deleted stays checked; while you are asked about deleting pages from a folder you follow, nothing is deleted and no file goes to the Trash; and while you are asked about the wiki's password, the password is left as it was. If the other machine takes the wiki's password off while the wiki is open here, your pages and folders are no longer saved here under the old password — that made the wiki impossible to open anywhere: your changes wait on the bar, and Reload opens the wiki as the other machine left it, with no password, and opens anything this Mac saved under the old password in the meantime. The bar says so, in every window of the wiki, from the moment it comes up: The password was taken off this wiki on another device, so the pages waiting here can’t be saved. Reload opens the wiki as the other device left it, with no password — copy anything you want to keep first. Keep mine can't save those pages in this case — the bar comes straight back, still saying it — so copy any words you want to keep (into a note outside MojoPad, say), choose Reload, and paste them back into the wiki once it has reloaded. A research answer that arrives meanwhile is offered again after Reload. While part of that change is still on its way here, while another window of the wiki is locked for inactivity, or if a new password was set on the other machine, Reload can't open the wiki with no password, and the bar says instead: This wiki’s password was changed on another device, so the pages waiting here can’t be saved. Keep this window open, and copy anything you want to keep. Once the rest of the change arrives, or the other window is unlocked, the bar says the first sentence again the next time it has something to tell you. The simple way to avoid all of this: set, change or take off a wiki's password only while the wiki is closed on your other Macs. A password changed while the wiki is open on two machines at once can, in a rare case, leave a page saved on one of them that neither can open. A page the other machine changed since this Mac last looked stays in Recently Deleted when you delete it for good or empty it, and the bar comes up. If the bar comes up just as a page you locked is saved, its earlier versions are kept until you choose: Keep mine saves it locked and then removes them, and Reload leaves the page as it was, versions and all. The bar says so on a line of its own — That change waits until you choose Reload or Keep mine — and gives a small nudge, and the status line says it too. Reload would have thrown such a change away, since it was never saved, so it is simply made again once you choose. An Undo pressed while the bar is up comes back, so it is still there to press afterwards; a suggestion you accept, or a site title you type, stays on screen the same way. Words you type into a page are not turned down: they stay in front of you while you decide, and Reload discards them, as its tip says. Opening and closing folders in the Pages panel is not turned down either, but it waits like the rest, so after Reload folders are open and closed as the other version has them. Things MojoPad does on its own, like reading a folder you follow, simply wait without a word — a paper your library brings in, or a project made from your task list, is filed in its folder once you choose Keep mine. A research answer that arrives, a clip, or something you capture is kept where it came from until then — even when the bar comes up only as it is saved — so Reload never loses it: it is offered again as the wiki reloads. A clip you turn away, or one already in the wiki, is let go of at once and not offered again. An AI assistant can read the wiki meanwhile but not add to it; it is told to wait until the bar is answered — before you are asked about its change, so no question comes up for a change that cannot be made.
Closing the window, or quitting MojoPad, while changes are waiting asks first — and so does closing a page opened in a small window, which can hold changes too. Cancel leaves everything as it was, so you can choose Keep mine or Reload; Close Without Saving lets them go. Words typed into a locked page are sealed again, and kept, when it locks itself.
A wiki with a password locks itself instead of closing. When you have been away past the time set in Settings ▸ Security and changes are waiting on the bar, closing would lose them — so the window covers everything with its lock screen instead and answers no assistant. The lock screen covers everything the window shows, a presentation, a flashcard review or an open question included, and while it is up the window runs no command but closing it and changing the theme: no new window or small window on the wiki, no sharing, printing or exporting, and no developer tools. The menu bar stops listing the wiki's pages, folders and snippets until the password brings it back, and a wiki with a password leaves no page names there once its last window closes. A window that opens on the wiki while every other window of it is locked gets the lock screen too, and nothing opens from it either. The wiki stops being shared as soon as no window of it is left in use — when a small window you were still using closes, say. Unlock… asks for the wiki's password in MojoPad's own window and brings everything back as you left it, the bar and your waiting changes included; the password is checked against the one this Mac opened the wiki with, whatever the wiki's file says now. The wiki is covered, not closed: it stays open behind the lock screen, because your waiting changes can only be saved while it is. If it can't be locked, it stays open as it was, and the status line says so.
Keep mine asks once more, in its own window, because it means the other machine's version is written over: say Keep Mine and the bar comes down and everything that was waiting is saved — the words you typed and the arrangement as you see it, even on a page you don't touch again; say Not Now and nothing changes — the bar stays up and your saves stay held, so you can still reload and read the other version first. If the other machine turned on Use no AI in this wiki, it is on here from the moment the bar comes up — or from the moment it arrives, if the bar is already up — and Keep Mine keeps it on. And if another window of this wiki saves a page this window is holding, you are asked which to keep, Use theirs or Keep mine, rather than having one copy quietly replace the other. Each such page is asked about in turn, and Keep mine on the bar saves everything else that was waiting but leaves those pages to their own question.
The bar comes up for a change the other machine made even a moment before your last save here. A sync keeps the time a file was saved on the other machine, so its change can arrive carrying an earlier time than yours. MojoPad compares each file with the one it last saw, not only the newest time in the wiki, so such a change is noticed too — even when all you did here was open or close a folder. A change the other machine made to a page or to the arrangement is never taken for one of this Mac's own because of when it arrived: while this Mac was saving, even saving that same page a moment later, or just as you opened a second window on the wiki, opened a page in a small window or switched a window to it. The bar comes up in every window that had not been told. And a save here that would go over a change the other machine made so recently that this Mac had not looked yet — to that same page, to the arrangement, or to a saved conversation — is not made: the bar comes up then, and the save waits for your choice like everything else. A saved conversation waits the same way while the bar is up, and Keep mine saves it.
Keep MojoPad up to date on every machine that opens the wiki. It is the machine with the wiki open that notices a change made on the other one. An older MojoPad did not notice a change to how the wiki is arranged alone — a folder added, a page filed, a pin — so the next time you changed its folders there, it saved its older copy of the arrangement back over the change made here, without a word.
The safest habit remains one machine at a time: close the document on one before opening it on the other, and let your sync service finish.
Three ways this comes up. You keep a wiki in iCloud Drive and use it on your laptop and your desktop; at the desktop you set a password on it while it is still open on the laptop. Or a colleague who shares a synced folder with you puts a password on a wiki you both use. Or somebody who can reach that folder puts a password on it without telling you. In each case the wiki on this Mac was opened with no password, and a password has since been set on it somewhere else.
What you see. The bar at the top of every window of the wiki says A password was set on this wiki on another device. and, under it, Your changes here are kept in this window until you unlock it. If you don’t know the password, choose Export my changes… to save them to a file. From that moment nothing this Mac does is written into the wiki: not a page (in any pane), not your folders, not a conversation, a page's history, what MojoPad found searching by meaning, an attachment, a recording, a flashcard review or a research answer. That is on purpose — each would otherwise go into a wiki its owner has just protected, readable by anyone who has the file. Nor does MojoPad keep copies of the wiki's words anywhere else on this Mac from then on, and if the wiki was being shared on your network, sharing stops. Keep mine and Reload are not offered here: neither would save your changes, and Reload would drop them.
Your changes are not lost. They wait in the window, and you can keep typing, in any pane. In case MojoPad closes unexpectedly while they wait, it also keeps a copy of them on this Mac, outside the wiki and locked with this Mac’s own keychain; the next time MojoPad starts, it offers to save that copy to a file, keep it for later, or delete it. If that copy can’t be kept — there is too much waiting for it, or this Mac’s keychain isn’t available — MojoPad says so, and Export my changes… is the way to keep a copy. The copy kept before then is removed, so MojoPad never offers an older copy as if it held your latest changes.
The same goes for a page with a password of its own. When a page’s own password is put on, changed or taken off in another window or on another device while you are writing in it here, your words wait on the page’s own bar, and MojoPad keeps a copy of them on this Mac in case it closes unexpectedly — from the moment they start waiting, and again after every change. Words you wrote while the page had a password are locked in that copy with that password, the one the page had while you wrote them, so they can’t be read on this Mac without it. Words written while the page had none are kept as above, with this Mac’s keychain — or with the wiki’s own password, if the wiki has one. Once you choose Unlock… on the page’s bar, the whole copy is locked again with the page’s password as it is now — the one you just typed — since that is the password your words are written with from then on, and the one Keep mine saves them with. So the password to give for a copy is the one you last unlocked the page with. The next time MojoPad starts after closing unexpectedly, it names the page and the wiki and offers the same three choices: Save to a File… asks for that password first, in its own small window with the hint if one was set, and then asks where to save; Later keeps the copy for the next start; Delete Them removes it. Once your words are saved into the page, or you choose Use theirs, or the page is deleted in another window, or you close the window or the reference card you were writing in, the copy is removed — but not when saving them fails (a full disk, or a wiki on a network drive that has gone away): the copy stays until they are saved. If it can’t be kept, MojoPad says so, and Export my changes… on the page’s bar is the way to keep a copy.
A research answer that arrives meanwhile waits too — and if it arrives after you closed the wiki’s window, quitting MojoPad asks first and offers to save it to a file.
If you know the password, choose Unlock… MojoPad asks for it in its own small window, which shows the hint if one was set. Type it and choose Unlock. Every other page is then shown as the other Mac left it, in whichever pane it is open, so you pick up whatever was changed there; everything that was waiting here is saved at once, sealed with that password; and the bar goes away. Where the other Mac also changed a page you changed here, your copy is the one kept, as the password window says before you answer. If the wiki is open in more than one window, unlocking it in one unlocks it in all of them, and each saves what it was keeping. A wrong password is said in that window and changes nothing, so you can try again. From then on the wiki works as any wiki with a password does, and asks for the password the next time it opens.
If the pages can’t be read from disk at that moment — the other Mac may still be syncing them — nothing that was waiting is saved, since it could go over pages the other Mac changed. The wiki is unlocked, and the bar stays, now with Reload and Keep mine, and says what happened: Reload shows the wiki as the other Mac left it, and Keep mine saves this window’s copy over it, sealed with the password.
Anything this Mac wrote in the moment before it learned of the password is sealed as well. If some of it could not be, MojoPad says what, and that changing the wiki’s password (File ▸ Set Document Password…) tries once more. And, as when you set a password yourself, it offers to delete the unprotected backups it kept of the wiki while it had none — the choice is yours, since they are also a way back.
If you don’t know the password, choose Export my changes… MojoPad asks where to save a file — choose a folder outside the wiki, such as Documents — and saves everything waiting in this window into it, whichever pane you typed it in, as a page you can open in any web browser: each page under its name, with its synopsis, notes, tags, properties and the passages you marked, and then each conversation waiting. Equations, diagrams and citations appear as their source. A page locked with a password of its own is left out, and MojoPad says so. Changes to your folders and flashcard reviews can’t go into a file, and MojoPad says that too: only unlocking saves them. If there is too much waiting for one file — pictures pasted into a page are kept inside it — MojoPad saves it in several, asks where to save each one, and says how many; a single page too large for any file is named, and stays waiting here. Nothing in the wiki changes, and the bar stays, so you can still unlock later. Once the file is saved you can close the window, ask whoever set the password for it, or copy what you need from the file into another wiki. Export my changes… is on the bar in the two cases above as well, where the other Mac took the password off or changed it.
Closing the window or quitting asks first while changes are waiting, and names the two ways to keep them: choose Cancel, then Unlock… or Export my changes… in the bar.
If Unlock says the wiki can’t be unlocked here, no password is asked for, and there are two reasons it may say so. The password in the wiki may not be one MojoPad makes — it may come from a newer MojoPad, or from something other than MojoPad; update MojoPad on this Mac. Or the password can’t be read on this Mac right now while the wiki’s pages are still protected — the record of it was taken out of the wiki, or damaged. Nothing is written into the wiki in either case. Use Export my changes… to keep what is waiting.
A page linked to a file on your Mac is not written back to that file — not while the bar is up, and not after you unlock, since a wiki with a password keeps its pages’ words out of files outside it. An AI assistant connected to MojoPad is told the same thing and adds nothing to the wiki until it is unlocked. Mail Drop leaves a message with attachments in your mailbox until the wiki is unlocked (see Mail Drop). A diagnostic report (Help ▸ Save Diagnostic Report…) says which wikis are waiting, and why — including a research answer kept for a wiki with no window open.
If you leave the window unused, it locks. When you have set MojoPad to lock after a time with no use (Settings ▸ Security) and that time passes, a lock screen covers the window, as it covers a wiki with a password of its own: nothing of the wiki shows behind it, and a connected AI assistant reads nothing from it — not even an answer it was still waiting on — until the wiki is unlocked. Clicking or typing on the lock screen does not open it again. While it is up, the window opens no other window or small window on the wiki, nothing is shared or printed from it, and nothing is exported from it but the changes waiting in this window, which the lock screen’s own Export my changes… saves to a file. Your changes keep waiting behind it, and so does the copy kept in case MojoPad closes unexpectedly. The lock screen offers the same two ways on as the bar: Unlock… asks for the password set on the other Mac and then does just what the bar’s Unlock… does, and Export my changes… saves what is waiting to a file, for when you don’t know the password, and says on the lock screen what it saved. If the wiki is open in two windows and you unlock one, the other stays locked until you unlock it too — you left it unused as well — and its Export my changes… still saves what is waiting in it. And if the password is taken off while the window is locked, on the other Mac or in another window here, Unlock… asks for nothing and opens the window, since the wiki has no password to keep it closed any more; the bar then offers Keep mine, which saves your changes, and Reload.