Privacy Policy

Effective 14 August 2026.

What we collect, why, and who else sees it. No dark corners.

What we collect

Your email address, from Google when you sign in. It is how we know which account is yours. We do not receive your Google password, and we ask Google for nothing beyond your basic profile and verified email.

Your workspace — the documents, comments and history you put there. We store it because storing it is the product.

Access tokens, stored only as irreversible hashes. We cannot read your tokens, which is why a lost one must be replaced rather than recovered.

Operational logs — request paths, timestamps, IP addresses, and errors — kept short-term to keep the Service running and to investigate abuse.

Feature usage events — when a feature is used we record its name, your account, and a timestamp: "created a document", "ran a search", "changed access". Never the content: no document text, no titles, no file paths, no search terms. This is first-party only and exists so we can see where the product loses people.

No third-party analytics, no advertising, no tracking cookies. The only cookie we set is the one that keeps you signed in. Nothing on these pages talks to an analytics company, because there isn't one.

What we never do

We do not sell your data. We do not share it with advertisers. We do not train AI models on your content, and we do not permit our providers to. We do not read your documents, except in the narrow case where you ask us for support and give us permission, or where the law requires it.

Who else is involved

Google — sign-in only, and receives what any OAuth sign-in receives.

Amazon Web Services — our servers and storage, in the US (Ohio, us-east-2). Your workspace lives on disks there.

Google Fonts — the landing page loads two typefaces from Google's font CDN, so Google sees the IP address of visitors to that page. Signed-in pages do not depend on it.

That is the complete list of third parties. There is no analytics vendor, no CDN in front of your content, and no data broker.

Who can see your documents

Only the people you grant access to, and only the folders you grant. This is enforced by construction: someone with partial access is served a repository that does not contain the other folders at all.

Anyone with the server's operating-system access — currently the founder — could technically read the disk. We do not, and a future version will narrow this further, but we would rather state it plainly than imply protection we have not built.

How long we keep it

Your workspace, for as long as your workspace exists. Backups are kept for up to 7 days on a rolling basis. Delete your workspace and both are gone within 30 days. Logs are kept up to 30 days.

Your choices

You can export everything at any time with git clone — the complete workspace, in a standard format, without asking us. You can revoke tokens on /tokens, change who has access on /access, and request deletion of your workspace and account by writing to us.

If you are in the EU or UK, you have rights to access, correct, delete, restrict, and port your data, and to object to processing; the export above satisfies portability directly, and we will honour the rest on request. Our legal basis is performance of our contract with you, and our legitimate interest in operating and securing the Service.

If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anyone exercising their rights.

Children

The Service is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We will post updates here with a new effective date, and announce material changes before they take effect.

Contact

[email protected] — for privacy requests, questions, or to have your data deleted.