Go Scribi

Privacy

This describes what the software actually does. Every claim below is checkable against the source, and several of them are things most products cannot say. It is not legal advice, and it should be reviewed by a lawyer before anyone is charged money.

Operated by [ENTITY], [ADDRESS]. Questions, requests and complaints: [PRIVACY_EMAIL]. Governed by the law of [JURISDICTION].

What we collect

Your account. An email address, and optionally a name. A password if you set one — passwords are optional here, and stored only as a bcrypt hash. If you sign in with Google we receive your email address and name and nothing else; we do not ask for access to your Google account beyond identifying you.

What you write. Notes, checklists, annotations, folder names, templates, and the files you upload. This is the whole point of the product and it belongs to you.

How you use it. Sign-in times and the network address a sign-in came from, kept so that you and we can see whether somebody else has been in your account. Which workspace you were last in, so the app opens where you left off.

A time zone, reported once by your browser, so that a note dated "today" is dated the day you are actually having.

We do not collect anything else. There is no analytics package, no advertising network, and no third-party script of any kind on any page of this application.

Where it lives, and who else touches it

Who What they handle
[ENTITY] The application and its database
Fly.io Hosting and the database servers
Tigris Uploaded files and images, in a private bucket
Resend Sign-in links, invitations and plan notices
Google Optional sign-in, if you use it
Stripe Payments — when billing is enabled; it is not yet

That is the complete list. Nobody else receives your data, and none of it is sold, rented or shared for advertising.

Some specifics worth stating

Your notes stay out of our logs. Note bodies, checklist items, annotations and search queries are filtered out of application logs before anything is written down. When something goes wrong on a page, what you wrote is not in the error report.

Uploaded files are private. They are stored in a bucket that is not public, and nothing is ever served from it directly. Every read goes through the application, which checks whether you are allowed to see it first.

Text recognition runs on our own machines. When we pull the text out of a scanned document or a photograph so you can search it, that happens on our infrastructure. No document of yours is sent to a third-party service to be read.

We do not read your notes. Nobody at [ENTITY] opens your content as a matter of course. The admin tools deliberately show counts, dates, sizes and states — never the words you wrote — and that boundary is asserted by our own tests.

Sign-in is rate limited, and passwords, tokens and sign-in codes are never stored in a form that can be read back.

How long we keep it

Your content stays until you delete it. Deleting a workspace deletes its notes, its checklists, and the files attached to them, including from the file store — not merely hidden from you.

Sign-in records are kept for [SIGNIN_RETENTION] so that unusual activity can be noticed. Sessions expire on their own and are removed when you sign out.

Deleting your account removes your personal details and the workspaces you alone own. Content in a workspace shared with other people stays with that workspace, because it is theirs as well as yours.

Getting your data out

Export is unconditional. Every workspace exports to a zip file — notes as Markdown, files as files — on every plan including the free one, at any time, without asking us. It works even while a workspace is frozen for being over its limit. This is not a feature we can withdraw as leverage; it is how the product works.

If you would rather we did it, or you want something we do not offer as an export, write to [PRIVACY_EMAIL].

Your rights

Depending on where you live, you may have the right to see the personal data we hold about you, to correct it, to have it deleted, to object to how we use it, and to complain to a regulator. Most of this you can do yourself from inside the app; for anything else, write to [PRIVACY_EMAIL] and we will answer within [RESPONSE_DAYS] days.

Our legal basis for handling your data is performing the contract you entered into by making an account, and our legitimate interest in keeping the service running and secure.

Cookies

One cookie, which keeps you signed in. See the cookie page.

Children

This is not intended for children under [MINIMUM_AGE], and we do not knowingly create accounts for them.

Changes

If this changes in a way that matters, we will say so by email before it takes effect rather than quietly editing the page. The date at the bottom is the date of the last edit, and it comes from the file's own history rather than from somebody remembering to update it.

Last updated August 20, 2026.