Privacy Policy
Last updated August 9, 2026
This Privacy Policy explains what information DeNotes(“DeNotes”, “we”, “us”) collects, how it is used, and the choices you have. DeNotes is built so that your note content stays under your control, on your own device or in your own Google Drive.
Summary
- We store the minimum needed to run your account and sync structure.
- Your note content lives in your storage: on your device, or in your Google Drive.
- We do not sell your data, and we do not read files in your Drive that DeNotes did not create.
Information we store
Account information. Authentication is handled by Clerk. When you sign in with one of the providers offered on the sign-in screen, such as Google or GitHub, Clerk provides us with basic profile details such as your name, email address and avatar so we can identify your account. We never see your password for that provider.
Workspace metadata. We store lightweight structural data in our database (hosted on Supabase): your folders, file and note titles, note metadata (such as tags, timestamps and whether a note is archived or pinned), goals, and sync state. This metadata lets your workspace appear correctly across sessions.
Preferences.Your display settings, including your light or dark theme and your Pro accent color, are saved to your account so they follow you to any device you sign in on. A copy is also kept in your browser’s local storage so the app opens in the right appearance before your account has loaded. Other interface state, such as which folders you have expanded, stays on your device only.
Private Vault. If you set a vault passcode, we store it only as a cryptographic hash, which cannot be reversed to recover the passcode. If you turn on biometric unlock we store the public half of a key pair created by your device. Your fingerprint or face never leaves your device and is never sent to us. The vault controls access to items in the DeNotes interface; it is not encryption of the note files themselves.
Messages you send us. If you use the contact form or request a discount, we store your name, the reply address you give, and the message, so we can respond and keep a record of the conversation.
Payments.If you subscribe to DeNotes Pro, payments are processed by Flutterwave, our payment processor. You enter your card, bank or mobile-money details on Flutterwave’s own secure payment page. Those details go directly to Flutterwave: DeNotes never sees or stores them, and we hold no card numbers of any kind.
To take a payment we share your name, email address and the amount and currency to be charged with Flutterwave. In return we store what we need to run your subscription: which plan you are on, whether it is billed monthly or yearly, when the current period ends, whether it has been cancelled, and a record of each payment: its date, amount, currency, whether it succeeded, and Flutterwave’s reference for it. That record is what you see under Billing in your settings.
Renewals, cancellation and refunds. A subscription renews automatically until you cancel it. You can cancel at any time from your billing settings; you keep Pro until the end of the period you have already paid for, and nothing is charged after that. Except where the law requires otherwise, payments are not refunded. If you believe you have been charged in error, write to us at team@denotes.space and we will look into it.
What stays in Google Drive
When you connect Google Drive, the actual content of your notes is written as plain Markdown files inside a dedicated DeNotes folder in your own Drive account. This content is never copied into our database.
DeNotes requests only the drive.file scope, which limits our access to files that DeNotes itself creates. We cannot see, list or open the rest of your Drive. The OAuth tokens that permit this access are stored server-side and are never exposed to your browser.
What DeNotes does not access
- We do not access files in your Google Drive other than those DeNotes created.
- We do not store the body of your notes in our own database.
- We do not sell, rent or trade your personal information.
- We do not use your notes to train machine-learning models.
Analytics and cookies
We use PostHog to understand how DeNotes is used and where it fails. It is configured to keep your writing out of what it collects: text and form inputs are masked, so the words in your notes are not captured. Session replay records masked interactions only, and is switched off entirely while your Private Vault is open.
We use cookies that the Service needs to function: a session cookie set by Clerk to keep you signed in, and short-lived cookies used during biometric vault unlock. We do not use advertising cookies and we do not sell your data.
Service providers
We rely on a small number of trusted providers to operate DeNotes:
- Clerk: authentication and session management.
- Supabase: the database that stores account and workspace metadata.
- Flutterwave: payment processing and subscription billing.
- Google Drive: storage for your note content, within your own account.
- PostHog: product analytics, processed in the European Union.
Each provider processes data only as needed to deliver its part of the service and is subject to its own privacy commitments.
Data retention and deletion
We keep your account and metadata for as long as your account is active. You can disconnect Google Drive at any time from your settings.
When you delete your account, we close it immediately and permanently: your sign-in is removed and the account cannot be reached or restored. We keep a closed record of the account, without your notes, for legal, accounting and anti-fraud purposes. When you close your account you can also ask for your stored note files to be deleted. If you do not, note content in your Google Drive stays where it is, remains yours, and can be deleted by you directly at any time.
Security
We use reputable providers, encrypt data in transit, and keep sensitive credentials such as OAuth tokens on the server. No system can be guaranteed perfectly secure, but we design DeNotes to hold as little of your data as possible.
Children
DeNotes is not directed to children under 13, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this policy as DeNotes evolves. When we make material changes, we will update the date above and, where appropriate, notify you.
Contact
Questions about privacy? Email us at team@denotes.space.