A note taking and to-do app with sync between Linux, macOS, Windows, and mobile
About this app
Note: This release can lag significantly behind the official release which can be an issue when a timely update is needed. It may be less secure because the app might have a known security vulnerability for several days, even if the official app has been patched. It does not have camera capabilities nor location functions. Issues with this version might be raised on https://gitlab.com/fdroid/fdroiddata for user @muelli
Joplin is a note taking and to-do application, which can handle a large number of notes organised into notebooks. The notes are searchable, can be copied, tagged and modified either from the applications directly or from your own text editor. The notes are in Markdown format.
Notes exported from Evernote and other applications can be imported into Joplin, including the formatted content (which is converted to Markdown), resources (images, attachments, etc.) and complete metadata (geolocation, updated time, created time, etc.). Plain Markdown files can also be imported.
The notes can be securely synchronised using end-to-end encryption with various cloud services including Nextcloud, Dropbox, OneDrive and Joplin Cloud.
Full text search is available on all platforms to quickly find the information you need. The app can be customised using plugins and themes, and you can also easily create your own.
The application is available for Windows, Linux, macOS, Android and iOS. A Web Clipper, to save web pages and screenshots from your browser, is also available for Firefox and Chrome.
Licensed under MIT.
What's New in v3.6.20
Imported from the F-Droid repository index.
Version history
May 24, 2026 · 144.4 MB · Android API 24–36 · code 2097808
Imported from the F-Droid repository index.
SHA-256 774ab07eca97c05d1a33f416e0ff330f20ba84ec6012f5f4248673c31a284032
May 21, 2026 · 144.4 MB · Android API 24–36 · code 2097807
Imported from the F-Droid repository index.
SHA-256 24c366c0c1e98d11f78474622652048abd70c167b7ee2a9d7277c6a3e8aea946
May 7, 2026 · 144.4 MB · Android API 24–36 · code 2097806
Imported from the F-Droid repository index.
SHA-256 7da968663b6c31c46433ac05cf8161376da3e943e3f44219db1ce9a4c930e405
Will it run on your device?
92%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be net.cozic.joplin is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 3.6.19 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Joplin first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Joplin, and a listing is removed when the evidence for it stops holding up.
Get Joplin
Every source we list for net.cozic.joplin is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
774ab07eca97c05d1a33f416e0ff330f20ba84ec6012f5f4248673c31a284032
Signing certificate
48a1cf9201b9079a6e0d5b33693e496db3c5cbec64a85afccd75e16d7a6cd54d
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.