Privacy

Last updated

NoteWorks is built and operated by Strange Digital Group, LLC. This page says what we hold, why, who else touches it, and how to take it back or end it. It is written to be read, not to be defensible.

What we hold

The Vault is encrypted where we cannot reach it

Vault items are encrypted in your browser with a key derived from your passphrase. That passphrase never leaves your device and we have never had the key. A database dump of the vault tables reveals item counts and timestamps and nothing else — not titles, not URLs, not usernames. This is not a promise about our conduct; it is a property of the construction, and the same property is why we cannot help you recover a forgotten passphrase.

No training on your data

We do not train models on your content, and we do not permit our providers to. Content sent to a cloud model is retained by that provider only for the duration of the request and is not used for training. The list of providers is on the subprocessors page, and the mechanics are on the data processing page.

What we never do

Where it lives

On servers we operate, in a Postgres database with per-workspace row-level security, and in private object storage for audio and attachments. Backups are encrypted, kept for 30 days, and then expire. Nothing in a backup is ever read for content.

How long we keep it

Your rights

Export everything from Settings → Your account: a zip of every workspace as Markdown and JSON, plus your account record. Delete your account from the same place. Both are self-service; neither requires writing to us or waiting for us. If you want a correction, an explanation, or a copy in another form, write to us on the support page.

Children

NoteWorks is not intended for anyone under 16 and we do not knowingly hold their data.

Changes

When this page changes materially we will say so in the app before the change takes effect, not after. The date at the top is the last time any of it changed.