tidy notebook
PricingSelf-hostedSign in

Privacy notice

Version 3. In effect from [OWNER: date of effect].

Draft for the owner. This text is a draft. The owner must review it before the launch, and a person who knows the law must read it. Each mark in the form [OWNER: ...] is a fact that the owner must give. Remove this notice after the review.

This notice tells you which personal data Bhushan Prakash Khanale keeps when you use tidy notebook cloud, why, where, for how long, and what you can do about it. In this notice, "we" and "us" mean Bhushan Prakash Khanale.

This notice is for tidy notebook cloud only. tidy notebook self-hosted sends nothing to us.

Who is responsible

Bhushan Prakash Khanale, [OWNER: business contact address, subject to lawyer review], is responsible for your personal data. Write to support@tidynotebook.com with a question about this notice or to use a right below.

Paddle is the merchant of record for each payment. Paddle collects the data of the payment for its own work. [OWNER: link the privacy notice of Paddle]

What we keep

Your account. Your email address, the name that you give, and your password. We keep the password only as a hash, so nobody can read it. We also keep the date that you made the account, whether you proved your address, your role, the storage that you use, and the versions of the terms and of this notice that you accepted, with the time.

Your plan. The plan of your account, its seats, its state, and the state of each payment that Paddle tells us about. We keep the reference that Paddle gives to your account as a customer. When a billing owner invites a person to a seat, we keep the email address of that person. We do not get your card number.

Your use. The bytes that your account stores, and the bytes that it sends each month, so that the limits of your plan work.

Your notes. The notes, folders, pictures and files that you save, each earlier version of a note, and the notes in Trash. The server keeps them so that it can show, search and sync them on your devices.

What you publish. A published link shows the notes that you choose to any person who has the address. We keep a digest of each link and its settings, not the address itself.

Your devices. For each device that is signed in, the network address and the browser description of the sign-in. You can then see your devices in Settings and sign out one of them.

Protection against abuse. For a short time, a count of attempts from each network address and to each email address. This stops a person who tries to guess passwords or to send many messages to one mailbox.

Reports. When you report a published page, we keep the reason and the words that you write. We do not keep who you are.

Messages. When you ask for an account, an invitation or a new password, we send a message to your address. We also send a message when your plan ends, when you get a seat invitation, and before we remove an account.

Support. When you write to support@tidynotebook.com, we keep your message and your address. [OWNER: how long we keep a support message]

Why we keep it

  • To give you the service that you asked for: your account, your plan, your notes, sync on your devices, and the links that you publish. This is necessary for our agreement with you.
  • To keep the service safe: the attempt counts, the device list, the check of new passwords, and the reports of harmful pages. This is our legitimate interest in a safe service.
  • To obey the law, when a law tells us to keep or give data.

We do not sell your data. We do not show advertisements. The application loads no analytics, no tracker and no script from another company. This site loads no analytics, sets no cookie and loads no script.

Who else receives data

  • Railway runs our servers and our database, in its EU West region.
  • Cloudflare carries each request to tidynotebook.com and to its other addresses, and it serves this site. Cloudflare R2 keeps the pictures and the files that you upload, and a weekly copy of the database in a separate bucket. [OWNER: where Cloudflare R2 keeps the data]
  • Proton receives and stores your support messages. Read the Proton Mail privacy notice.
  • Resend delivers the messages that we send to you. [OWNER: where Resend processes the messages]
  • Paddle takes each payment. When you open your first checkout, we give Paddle the email address of your account.
  • Have I Been Pwned checks each new password against a list of leaked passwords. The server sends only the first five characters of a digest of the password. Your password and your address never leave the server.
  • A person who has the address of a link that you publish can read what it shows.

We run the service from India. [OWNER: the safeguard for each transfer of data out of your country]

How long we keep it

  • Your account and your notes stay until you remove them. A note in Trash stays until you delete it.
  • A new account starts locked. When no plan covers it, we remove it 30 days after you make it.
  • When a plan ends, the accounts that it covered are locked. We remove a locked account 90 days after its plan ended.
  • Before we remove an account, we send a message 30 days and 7 days before the removal.
  • A sign-up that nobody finishes goes after [OWNER: how long an unfinished sign-up waits].
  • The record of a device goes when the device signs out. It stops working when its session ends.
  • An attempt count goes after its time window, which is one hour at most.
  • When you remove your account, your notes, your devices and your settings go at once. Only an identifier and the time of the removal stay, so that the history of a shared note stays correct.
  • A weekly copy of the database goes to a separate bucket of Cloudflare R2. We delete each copy after 35 days.
  • Railway keeps backups of the database. [OWNER: how long Railway keeps a backup of the database] A backup keeps the data of a removed account until the backup goes.
  • [OWNER: how long we keep the record of a plan after its account goes]
  • The logs of tidy notebook hold no note text, no password and no network address. We keep them for [OWNER: log retention].

Cookies and storage on your device

The application sets one cookie, which keeps you signed in. The billing pages at billing.tidynotebook.com set one cookie of their own, which keeps you signed in there. Each cookie is necessary for the service, so we do not ask for your consent to it. This site sets no cookie.

The checkout on the billing pages loads the script of Paddle. [OWNER: the cookies and the storage that the checkout of Paddle uses]

Your browser also keeps a copy of your notes on the device, so that you can read and write them offline. That copy stays on the device and goes nowhere else.

Your rights

  • See and take your data. Select Export all notes in Settings to download every note and picture of a workspace as Markdown files. A locked account can also do this. Write to us for a copy of the other data.
  • Correct your data. Change your name in Settings. Write to us to change your address.
  • Remove your data. Select Remove my account in Settings. A locked account can also do this.
  • See your invoices. The customer portal of Paddle, from the billing pages, shows each invoice.
  • Object or restrict. Write to us if you object to a use of your data, or if you want us to stop it for a time.
  • Complain. You can complain to [OWNER: supervisory authority].

What we can see

The notes are not end-to-end encrypted. The people who run the service can read your notes when they must, for example to repair the service or to answer a court order.

Children

The service is not for a person under [OWNER: minimum age] years old.

Changes to this notice

When this notice changes, its version changes. The application then shows the new version before your notes open. You accept it, or you export your notes and remove your account.