Privacy
This describes what the software actually does. Every claim below is checkable against the source, and several of them are things most products cannot say. It is not legal advice, and it should be reviewed by a lawyer before anyone is charged money.
Operated by [ENTITY], [ADDRESS]. Questions, requests and complaints: [PRIVACY_EMAIL]. Governed by the law of [JURISDICTION].
What we collect
Your account. An email address, and optionally a name. A password if you set one — passwords are optional here, and stored only as a bcrypt hash. If you sign in with Google we receive your email address and name and nothing else; we do not ask for access to your Google account beyond identifying you.
What you write. Notes, checklists, annotations, folder names, templates, and the files you upload. This is the whole point of the product and it belongs to you.
How you use it. Sign-in times and the network address a sign-in came from, kept so that you and we can see whether somebody else has been in your account. Which workspace you were last in, so the app opens where you left off.
A time zone, reported once by your browser, so that a note dated "today" is dated the day you are actually having.
We do not collect anything else. There is no analytics package, no advertising network, and no third-party script of any kind on any page of this application.
Where it lives, and who else touches it
| Who | What they handle |
|---|---|
| [ENTITY] | The application and its database |
| Fly.io | Hosting and the database servers |
| Tigris | Uploaded files and images, in a private bucket |
| Resend | Sign-in links, invitations and plan notices |
| Optional sign-in, if you use it | |
| Stripe | Payments — when billing is enabled; it is not yet |
That is the complete list. Nobody else receives your data, and none of it is sold, rented or shared for advertising.
Some specifics worth stating
Your notes stay out of our logs. Note bodies, checklist items, annotations and search queries are filtered out of application logs before anything is written down. When something goes wrong on a page, what you wrote is not in the error report.
Uploaded files are private. They are stored in a bucket that is not public, and nothing is ever served from it directly. Every read goes through the application, which checks whether you are allowed to see it first.
Text recognition runs on our own machines. When we pull the text out of a scanned document or a photograph so you can search it, that happens on our infrastructure. No document of yours is sent to a third-party service to be read.
We do not read your notes. Nobody at [ENTITY] opens your content as a matter of course. The admin tools deliberately show counts, dates, sizes and states — never the words you wrote — and that boundary is asserted by our own tests.
Sign-in is rate limited, and passwords, tokens and sign-in codes are never stored in a form that can be read back.
How long we keep it
Your content stays until you delete it. Deleting a workspace deletes its notes, its checklists, and the files attached to them, including from the file store — not merely hidden from you.
Sign-in records are kept for [SIGNIN_RETENTION] so that unusual activity can be noticed. Sessions expire on their own and are removed when you sign out.
Deleting your account removes your personal details and the workspaces you alone own. Content in a workspace shared with other people stays with that workspace, because it is theirs as well as yours.
Getting your data out
Export is unconditional. Every workspace exports to a zip file — notes as Markdown, files as files — on every plan including the free one, at any time, without asking us. It works even while a workspace is frozen for being over its limit. This is not a feature we can withdraw as leverage; it is how the product works.
If you would rather we did it, or you want something we do not offer as an export, write to [PRIVACY_EMAIL].
Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, to correct it, to have it deleted, to object to how we use it, and to complain to a regulator. Most of this you can do yourself from inside the app; for anything else, write to [PRIVACY_EMAIL] and we will answer within [RESPONSE_DAYS] days.
Our legal basis for handling your data is performing the contract you entered into by making an account, and our legitimate interest in keeping the service running and secure.
Cookies
One cookie, which keeps you signed in. See the cookie page.
Children
This is not intended for children under [MINIMUM_AGE], and we do not knowingly create accounts for them.
Changes
If this changes in a way that matters, we will say so by email before it takes effect rather than quietly editing the page. The date at the bottom is the date of the last edit, and it comes from the file's own history rather than from somebody remembering to update it.
Last updated August 20, 2026.