Normally FlowJoe keeps your Flow in its own storage inside the app. Workspace Folder mode changes that: your Flow is written to a folder you choose, as ordinary files you can open, copy, and back up like anything else on your drive.
Workspace Folders are available in the desktop app.
Older backups may keep a Workspace paused. When a Flow already contains private nodes, FlowJoe preserves their full content in owner-only storage, replaces it in the Workspace with redacted placeholders, and verifies the saved file before resuming saves. A copy shared or backed up before migration cannot be recalled. If an older Workspace backup still contains private text, FlowJoe leaves it unchanged and keeps saving paused. Keep the backup intact while deciding how to handle it.

Where to find it

Open Settings → Data and look for the Workspace Folder card. Everything below happens there — there is no File menu entry and no context-menu item for this. On first launch, the desktop app offers Keep FlowJoe local, Workspace Folder, and Decide later. Choosing Workspace Folder takes you to this card to select or create the folder. If you skip onboarding, the card remains available in Settings.

Setting one up

The card shows different buttons depending on whether a folder is connected. When you create a workspace, FlowJoe shows its progress — “Preparing workspace…”, then “Copying media 3 of 12…” — and you can Cancel partway through. One Flow lives in one folder. New Workspace is hidden while you are already connected. The card shows the current Flow name, the selected or last-known folder path, and whether that folder is connected. Before connecting to an existing folder, FlowJoe summarizes both versions and calls out missing media references separately from files not used by the current Flow. The review makes no changes; Workspace media is not deleted automatically.

What lands on disk

flow.json is plain, indented JSON, so a version-control tool like Git can diff and merge it as text. media/ holds your files one per item. They are named by FlowJoe’s internal id and carry no file extension, so treat this folder as storage rather than a gallery to browse. Edit flow.json outside FlowJoe only if you know the format. If a Git merge leaves conflict markers in it, FlowJoe cannot open the workspace until you clean them out.

Backups, Git, and syncing

Because your Flow is a normal folder, ordinary tools work on it: Time Machine, an external drive, or a sync client all back it up like any other directory, and Git can version flow.json as text.
Network and shared drives are not supported yet. FlowJoe checks before connecting and refuses a folder on a network or shared drive: “That folder is on a network or shared drive. FlowJoe can only use a folder on this computer’s own disk for now.” Keep your workspace on the computer’s own disk. If a sync client leaves conflict files in the folder, FlowJoe notices and tells you.
Replacing files inside media/ by hand is not a supported way to swap media — FlowJoe watches flow.json, not the media folder.

When something changes outside FlowJoe

If flow.json changes on disk while FlowJoe is running — a sync client pulling a newer copy, or you editing it directly — FlowJoe tells you rather than silently picking a side. If the change does not collide with your work, it refreshes and says so. If it does, you get Someone changed this Workspace file outside FlowJoe and choose:
  • Use External Changes — take the version on disk.
  • Keep My Changes — keep what is in FlowJoe and overwrite the file.
  • Open External as New Flow — open the disk version separately and decide later.

Missing, retained, and changed media

  • A missing media reference is listed separately; FlowJoe does not replace it with a different file.
  • Files present in the folder but unused by the current Flow are counted and retained; Workspace media is not deleted automatically.
  • Settings → Data → Inspect Stale References shows missing targets and any safely repairable metadata. Safe repairs remove only the stale metadata link; they do not delete media files.
  • If FlowJoe detects that a media file changed after it was read, it stops the write and opens the existing review path. The outside copy is preserved until you resolve the review.

When saving pauses

If FlowJoe cannot reach the folder — the drive is unplugged, permission was lost, or the folder moved — it stops saving rather than losing your work. The status bar shows Saving is paused, and edits are refused until you sort it out. Joe is told too, and will say he cannot make changes until the workspace is reconnected. Your ways out, all on the same card:
  • Reconnect Workspace — reconnect once the drive is back.
  • Use Local Copy — continue from FlowJoe’s own recent copy of your work.
  • Rebuild Workspace — write the workspace out to a new folder.
  • Switch to Local Storage — go back to the app’s own storage.
  • Start New Local Project — begin a fresh Flow.
FlowJoe keeps a Local Recovery Copy inside the app while you work in a workspace, which is what Use Local Copy restores from. See History & Recovery. If a save was interrupted halfway, connecting reports it and offers Clear Interrupted Save. FlowJoe only clears saves it can prove never completed; anything else it leaves alone and tells you so.

Private nodes

Workspace files represent password-protected private nodes as “Private node (not shared)” placeholders. When you create one in a Workspace, FlowJoe keeps it out of the live Flow until protection and its device-only copy are confirmed; only then can it be saved to the Workspace. When opening an older Flow, FlowJoe first confirms a durable owner-only copy before running load-time migrations, then checks the Workspace file before normal saving resumes. If FlowJoe cannot confirm that local copy, the connection stops before hydration or saving. Copies made before migration may remain elsewhere and cannot be recalled. If a retained Workspace backup still contains private text, FlowJoe leaves it intact and keeps the Workspace paused.

Exports still work

Workspace mode does not replace .fj export. You can still export a full .fj package or JSON at any time — see Export & Import. Restore points are not included in a workspace folder or a .fj file; they live with the app on this device.