← Back to CollabNote

Privacy Policy

Last updated: April 30, 2026

1. Who We Are

CollabNote (“we,” “us,” “our”) is a collaborative markdown note-taking service. You can reach us at districtzone0x9@gmail.com.

2. What Data We Collect

Account data

When you register, we collect your email address, display name, and a hashed password (bcrypt). If you sign in with Google, we receive your Google account email, name, and profile photo from Google’s OAuth service. We never receive or store your Google password.

Note content

The text content of every note, folder name, tag, and attachment you create is stored on our servers. This includes notes you share with collaborators. Notes you choose to encrypt with a password are stored as ciphertext — the encryption key is derived in your browser and the plaintext is never transmitted to our servers for those notes.

Usage and collaboration data

We log which notes are created, modified, deleted, and shared, along with timestamps. Real-time collaboration data (cursor positions, presence) is processed in memory and not permanently stored.

Payment data

Payments are processed by Stripe. We do not store your card number, CVV, or full payment details. We store your Stripe Customer ID and subscription status (active, canceled, etc.) to manage your Pro access.

Voice and audio

If you use Voice Notes or Voice Dictation (Pro features), audio is sent to Groq’s API for transcription. Audio is not stored by us after transcription completes. Groq’s own privacy policy governs their handling of that data.

AI-generated content

Pro AI features (AI Writing Assistant, AI Workspace Assistant, Similar Notes, AI Note Title) send the relevant note content to Groq’s API to generate responses. We do not store the AI responses beyond your current session. Groq’s privacy policy governs their processing.

Technical data

We collect standard server logs including IP addresses, browser/OS type, and request timestamps for security monitoring and debugging. These are retained for up to 30 days.

3. How We Use Your Data

  • To operate and deliver the CollabNote service
  • To authenticate you and maintain your session
  • To sync your notes across devices and share them with collaborators you invite
  • To process payments and manage your Pro subscription via Stripe
  • To power AI features by sending note content to Groq (Pro plan only)
  • To send transactional emails (e.g., subscription receipts) — we do not send marketing emails without your explicit consent
  • To debug issues and maintain security

4. Third-Party Services

We use the following third-party processors. By using CollabNote you agree to their respective privacy policies:

ServicePurposeData shared
StripePayment processingEmail, subscription metadata
GroqAI & transcription (Pro)Note content, audio
SupabaseOptional database storageNote content, account data
Google OAuthSign-in (optional)Email, name, profile photo
Fly.io / RenderHosting & infrastructureAll server data at rest

We do not sell your data to any third party.

5. Data Retention

Your account data and notes are retained until you delete them or close your account. Deleted notes are removed immediately from our active storage. Backup copies may persist in server snapshots for up to 30 days before permanent deletion. Subscription records are retained for 7 years for tax and compliance purposes.

6. Security

Passwords are hashed with bcrypt before storage. All traffic is encrypted in transit via HTTPS/TLS. Notes you explicitly encrypt with a password use AES-256-GCM encryption derived in your browser — we cannot read those notes. Unencrypted notes are stored as plaintext on our servers and accessible to us for operational purposes.

No system is perfectly secure. In the event of a data breach we will notify affected users within 72 hours of discovery.

7. Your Rights

You may at any time:

  • Access — request a copy of all data we hold about you
  • Delete — request deletion of your account and all associated notes
  • Correct — update your email or display name from within the app
  • Export — export your notes as Markdown via the built-in export feature
  • Object — opt out of any non-essential processing

To exercise these rights, email districtzone0x9@gmail.com. We will respond within 30 days.

8. Cookies and Local Storage

We use a single HTTP-only session cookie to keep you logged in. We do not use advertising or tracking cookies. Some preferences (theme, sidebar state) are stored in your browser’s localStorage and never sent to our servers.

9. Children

CollabNote is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has created an account, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy. Material changes will be communicated by email or in-app notice at least 14 days before they take effect. Continued use after that date constitutes acceptance.

11. Contact

Questions or requests: districtzone0x9@gmail.com

Terms of ServiceBack to App