Last updated: April 25, 2026
The privacy of your data is a big deal to us. In this policy, we lay out: what data we collect and why; how your data is handled; and your rights with respect to your data.
This policy applies to Encrypted Notes, and to anyone who visits the site or uses it.
Our guiding principle is to collect only what we need. Here’s what that means in practice:
You can sign up with just a nickname; we never require your email, real name, or any other identifying information. If you choose to provide an email, it’s used only for account recovery and (if you opt in) the newsletter. We never send marketing emails you haven’t explicitly subscribed to.
We’ll never sell your personal information to third parties, and we won’t use your name or company in marketing statements without your permission either.
If you sign up for a paid Encrypted Notes plan, you will be asked to provide your payment information and billing address. Credit card information is submitted directly to Paddle, our payment processor, and doesn’t hit Encrypted Notes servers. We store a record of the payment transaction for purposes of account history, invoicing, and billing support. We store your billing address so we can charge you for service, calculate any sales tax due, send you invoices, and detect fraudulent credit card transactions.
We don’t log IPs against your account. Because the frontend is served through Cloudflare, Cloudflare sees the IP addresses of incoming requests and logs them. We don’t link that data to your account in any way.
We don’t use cookies.
When you email Encrypted Notes with a question or to ask for help, we keep that correspondence, including your email address, so that we have a history of past correspondence to reference if you reach out in the future.
To provide products or services you’ve requested. We use some third-party subprocessors to help run our applications and provide the Services to you. You can view the third-party subprocessors we use on our Data Processors page.
No human or AI at Encrypted Notes looks at your content except for limited purposes with your express permission, for example, if an error occurs that stops an automated process from working and requires manual intervention to fix. These are rare cases, and when they happen, we look for root cause solutions as much as possible to avoid them recurring. We may also access your data if required in order to respond to legal process.
To help you troubleshoot or fix a software bug, with your permission. We can’t access your content directly. If a support case requires us to see something, we’ll ask you to send it to us: as a screenshot, a decrypted copy, or however’s appropriate.
To investigate, prevent, or take action against abuse. The only user-generated content visible to us is content you’ve explicitly published — published pages are, by design, unencrypted. If we receive a report about a published page, we’ll review it. We do our best to balance the privacy of our users against the safety of people reporting issues. If we discover you are using Encrypted Notes for a restricted purpose, we will take action as necessary, including notifying appropriate authorities where warranted.
Requests for user data. Our policy is to not respond to government requests for user data unless we are compelled by legal process or in limited circumstances in the event of an emergency request. We will comply with requests from law enforcement authorities if they have the necessary legal documentation, such as a warrant, subpoena, or court order, requiring us to disclose data. It is Encrypted Notes’s policy to notify affected users before we disclose data unless we are legally prohibited from doing so, and except in some emergency cases.
Preservation requests. Similarly, Encrypted Notes’s policy is to comply with requests to preserve data only if compelled by applicable laws or by a properly served legal request. We do not disclose preserved data unless required by law or compelled by a court order that we choose not to appeal. Furthermore, unless we receive a proper warrant, court order, or subpoena before the required preservation period expires, we will destroy any preserved copies of customer data at the end of the preservation period.
If we are audited by a tax authority, we may be required to disclose billing-related information. If that happens, we will disclose only the minimum needed, such as billing addresses and tax exemption information.
Finally, if Encrypted Notes is acquired by or merges with another company, we’ll notify you well before any of your personal information is transferred or becomes subject to a different privacy policy.
At Encrypted Notes, we strive to apply the same data rights to all customers, regardless of their location. Some of these rights include:
Many of these rights can be exercised by signing in and updating your account information. Please note that certain information may be exempt from such requests under applicable law. For example, we need to retain certain information in order to provide our services to you.
In some cases, we also need to take reasonable steps to verify your identity before responding to a request, which may include, at a minimum, depending on the sensitivity of the information you are requesting and the type of request you are making, verifying your name and email address. If we are unable to verify you, we may be unable to respond to your requests. If you have questions about exercising these rights or need assistance, please contact us at support@encryptednotes.com.
Your notes and attachments are end-to-end encrypted. They’re encrypted on your device with a key derived from your password, and they leave your device only in encrypted form. We don’t have the key and can’t decrypt them. Transport to and from our servers uses SSL/TLS. Database backups contain the same encrypted blobs that the live database does.
We keep your information for the time necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and your choices, after which time we may delete it. We may also retain and use this information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Encrypted Notes’s primary infrastructure is in the European Union. For a full list of our service providers and their locations, see our Data Processors page.
We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change to our policies, we will refresh the date at the top of this page and take any other appropriate steps to notify users.
Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Please get in touch by emailing us at support@encryptednotes.com and we’ll be happy to try to answer them!
Adapted from the Basecamp open-source policies / CC BY 4.0.