Legal

Privacy Policy

What we store, why we store it, how long we keep it, and who else sees it.

Last updated Sep 6, 2026

Before you launch: replace the bracketed placeholders below with your registered entity name, address and jurisdiction, and have these documents reviewed by a lawyer in the country you operate from. They describe how this software actually behaves, but they are not legal advice.

1. Controller

[Legal entity name], [Registered address], is the data controller for the personal data described here. Contact: [email protected].

2. What we collect

You give us

  • Email address — to identify your account, confirm it belongs to you, and send account and billing notices.
  • Username — to display in the interface.
  • Password — stored only as a scrypt hash. We cannot read it, and neither can anyone who obtains a copy of the database.
  • Note content — the notes you write, stored so we can show them back to you.

Generated automatically

  • Session records — a session token, its expiry, and the IP address and browser user-agent it was created from, so you can review and revoke active sessions.
  • Security log — sign-ins, failed sign-in attempts, password changes, payments and webhook events, with the originating IP address. This exists to detect abuse and to investigate payment disputes.
  • Rate-limit counters — short-lived counters keyed by IP address or account.

3. What we do not do

  • We do not read your notes, except where you explicitly ask support to investigate.
  • We do not use your notes to train machine-learning models.
  • We do not sell or rent personal data.
  • We do not run advertising or third-party analytics trackers.

4. Cookies

We set one cookie: an httpOnly session cookie that keeps you signed in. It is not readable by JavaScript, is marked SameSite=Lax, and is sent only over HTTPS in production. Your theme preference is stored in your browser's local storage and never leaves your device. There are no advertising or tracking cookies, so there is no consent banner to click through.

5. Processors we share data with

  • Our hosting and database provider — stores the application and the database.
  • NOWPayments — our payment provider. When you start a checkout they receive the amount, an order reference and, if supplied, your email. They never receive your notes. Their own privacy policy applies to what they hold.
  • Our email provider — receives your email address and the message content in order to deliver verification, password-reset and billing emails.

6. Legal basis

Where the GDPR applies, we rely on: performance of a contract for your account, notes and subscription; legal obligation for retaining payment records; and legitimate interest for the security log and rate limiting, which keep the service usable and accounts safe.

7. Retention

  • Notes, sessions and credentials — kept until you delete them or close your account, then removed.
  • Profile — on account deletion your email, username and display name are replaced with anonymous placeholders.
  • Payment records — retained after account deletion, including the email address the payment was made with, because accounting and anti-fraud rules require a traceable financial record. They are no longer linked to a usable account.
  • Security log and rate-limit counters — the counters expire within hours; log entries are kept while they remain useful for investigating abuse.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or erase your personal data, to object to processing, or to complain to a supervisory authority. You can exercise access and erasure yourself from the account page. For anything else, write to [email protected] and we will respond within 30 days.

9. Security

Passwords are hashed with scrypt. Session cookies are httpOnly and signed. Every database query for notes is scoped to the owning account. Payment callbacks are accepted only with a valid HMAC signature. No system is perfectly secure, and we do not claim otherwise — if a breach affects you, we will notify you and the relevant authority as the law requires.

10. International transfers

Our infrastructure and processors may store data outside your country, including outside the EEA. Where required, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.

11. Changes

We will post updates on this page and, for material changes, notify you by email before they take effect.

Privacy Policy — FlowNote