Legal

Privacy Policy

Effective 17 September 2026. It covers myne.md, app.myne.md, sync.myne.md and the desktop and mobile apps.

The short version

Your notes are encrypted on your device before they go anywhere, and we hold no key that opens them. Signing up takes no email address — your account is a 20-character number you keep. We do not log IP addresses, set no cookies, run no analytics, and load nothing from anyone else's server.

What we do have is short and worth naming rather than glossing: a hash that identifies your account, a login verifier, your encrypted blobs, a record of which devices you enrolled, and two counters for storage and rate limits. That is the whole list, and it is below in full.

The flip side of holding no key: if you lose your password and your recovery phrase, nobody — including us — can get your notes back.

When the app talks to the network

Most privacy policies describe what a company promises. This table describes what the program does, feature by feature. It is derived from the code — the content-security policy that bounds the app, and two ratchets in the build that fail if a new outbound call appears without being recorded first.

Feature Leaves your device? Where to When
Sync Yes The sync server you configured — sync.myne.md, or your own While sync is switched on. This is the only feature that sends your notes anywhere, and they leave encrypted.
Spell check No — Dictionaries ship with the app; your personal word list lives inside the encrypted vault.
On-device AI No — The models ship inside the app and run on your machine.
AI via a local runtime Loopback only 127.0.0.1 on your own machine Only if you configure one. The address cannot be anything but loopback — the code rejects any other host rather than trusting what it resolves to.
AI via a remote provider Yes — note text leaves your device. An agent run also sends the titles and identifiers of every note in the scope you approved, before it has read any of them. It also carries what it remembers about you: distilled facts from earlier runs (at most 100 entries) and your voice preferences, each entry with a stable identifier. The provider you named Only when every condition is true, and the set differs by platform. On a computer there are five: you named a provider, you consented to that specific provider, you supplied its key, AI is enabled, and developer mode is on. On a phone the first four apply and there is no developer mode, so there are four. Every one of them is off by default, and with none named the code path is unreachable rather than merely disabled. One request per thing you ask for, except an agent run, which makes a bounded series of them: how many is decided by the model, not by us.
Web clipper No — The browser extension talks to the app over a local channel on your own machine.
Tor routing Routes sync through Tor The Tor network, then your sync server Only if you switch it on.
Update check None — There is no auto-updater. The app never phones home to ask whether it is current.
Analytics, telemetry, crash reports None — Never. None of it is in the build.
Fonts, CDNs, third-party assets None — Every asset is inside the app. The web app's content-security policy names exactly one external origin — your sync server — and the build is checked for third-party origins before it ships.

Two rows deserve emphasis rather than a footnote. Sync sends your notes, encrypted, to the server you chose — that is the feature. AI via a remote provider sends note text in the clear to a company that is not us, because that is what asking a remote model to read your note means. It is off, and turning it on takes five deliberate steps on a computer and four on a phone, which has no developer mode; once on, that provider's privacy policy governs what they do with what you send. We do not proxy it and we never see it.

One part of that is worth spelling out, because it is not what “note text” brings to mind. When you let the AI propose changes to a set of notes, the first thing it receives is the list: the title and identifier of every note in the scope you approved, sent before it has read a single one of them. So approving a folder and then stopping the run still sent that folder’s titles. Titles are often the most revealing line in a note. The identifiers are stable, so a provider that keeps requests can tell that two of them concern the same note.

Memory deserves the same spelling-out. When the assistant works for you across runs, it keeps distilled facts — how you like answers written, standing rules you taught it — and sends them along with every agent run, on every arm: your computer’s loopback runtime and a remote provider receive the same system turn. Each entry travels with a stable identifier, so a provider that keeps requests can link the same memory across runs. The assistant writes at most one entry per run, and everything it remembers is visible and editable in the app — the memory list, never a silent write.

What the sync server stores

The server is a blind blob store: it accepts, keeps and hands back ciphertext, and performs only structural operations on it — advancing a pointer, incrementing a counter, counting bytes. It never decrypts, merges or interprets anything, because it holds nothing that could.

What Why it exists
account_number_hash A 16-byte hash of your account number. The only account identifier the server has.
SCRAM verifier What the server checks your login against. It is not your password and cannot be turned back into it.
Encrypted blobs Your notes and attachments as ciphertext. We hold no key that opens them.
Version counter A number per blob, used to detect conflicting edits. It says that something changed, never when and never what.
Head pointer One pointer per vault to the latest state you pushed.
Device registry One record per device you enrolled, with a device id you generated. Needed because revoking a device requires knowing it exists — this is the one place your device count is unavoidably visible to the server.
Counters Total bytes stored and number of devices, for the quota and the rate limit.
Account policy Whether the account is frozen, and any storage or device limit set specifically for it. A freeze blocks writing; it never blocks reading what is already there. This is the one thing on this list the server keeps in plain text — it has to be readable to be enforced, and it says nothing about you beyond a limit and a flag.

What we never have

This list is as load-bearing as the one above it, because it sets the limit of what any request to us can produce — yours, or a court's.

  • Email address, name, postal address, phone number
  • Payment details — the beta is free and takes none
  • IP addresses in any persisted form, connection logs, access times
  • Readable content, note titles, folder names, tags
  • Timestamps that mean anything to you — those live inside the ciphertext
  • Cookies, analytics identifiers, advertising identifiers, fingerprints

Some of these are architectural rather than promised. Sign-up asks for no email because there is no field for one. Rate limiting counts per account rather than per address because the server never keeps an address to count. Your timestamps are inside the encrypted blob, so no operator — us, or anyone self-hosting — can read when you wrote something.

How long we keep it, and how you delete it

Everything listed under "what the sync server stores" is kept until you delete your account, and no longer. Deleting removes the vault, the attachments, the device registry, the login verifier and the counters.

You delete it yourself, from inside the app. That is deliberate: because we hold no email address, an emailed deletion request is one we could not verify — anyone who learned your account number could otherwise have your vault destroyed. Inside the app you are already authenticated, so the question does not arise.

Backups

Encrypted backups run on a 14-day rotation. A deleted account therefore disappears from the live service immediately and from the last backup set within 14 days. We are stating the number because most services do not: "deleted immediately" is rarely true of anyone who keeps backups, and a policy that omits the backup window is describing a system that does not exist.

Backups hold the same ciphertext the server holds. They are as unreadable to us as the originals.

The web app, and what it stores in your browser

The web app at app.myne.md keeps your encrypted vault in your browser's own storage (OPFS), so it can work without re-downloading everything and so your notes survive a reload. This is storage on your device, not on ours, and it holds the same ciphertext.

Under § 25 TDDDG this needs no consent banner: it is strictly necessary for the service you explicitly requested — a notes app that cannot store your notes is not the service. We describe it here rather than asking you to click a box, because the box would be theatre. We set no cookies at all, and we store nothing for any purpose other than running the app you opened.

Donations

If you donate, it goes through Open Collective and their fiscal host. Payment details reach them, never us; we see the amount and whatever name the donor chooses to show. Your Myne account and a donation are not linked, and cannot be — there is nothing on the account to link to.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing. Two of these work differently here, and the reason is the same in both cases:

Access and portability. Your notes are already in your hands — that is what the app is. What we hold beyond them is the short list above, and we cannot decrypt any of it. An export lives in the app, and it produces more than we could.

Erasure. Deletion is in the app, for the verification reason described above. Write to us if that path fails you and we will work it out.

You may also complain to a supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow.

Who is responsible

Ömer Duran
Potsdam, Germany
privacy@myne.md

The full postal address is published in the Impressum when the public beta opens; until then it is available on request at the address above. There is no data protection officer: the thresholds of § 38 BDSG are not met — there are no employees.

Processors

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, runs the machines. myne.md, app.myne.md and sync.myne.md all live in Hetzner's Falkenstein data centre in Germany, under an Art. 28 processing agreement. There is no other processor: no CDN, no analytics vendor, no crash reporting service, no email delivery service, no payment processor.

Nothing is transferred outside the EU. All processing happens in Germany, and access to the production system is held by one person.

Abuse reports and legal requests

Reports go to abuse@myne.md. We cannot read what people store, so we cannot screen it, and we do not pretend otherwise — what we can do on a valid report is act on the account. What a valid report contains, and what happens after one arrives, is on the reporting page.

Requests from authorities go to legal@myne.md and are answered against the list above and no further: we can only hand over what we have, and what we have is a hash, a verifier, some counters and ciphertext we cannot open. There is no key in our possession, no German law obliges a provider to break its own encryption, and encrypted data is handed over encrypted. The long form — which legal basis reaches what, and why § 22 TDDDG cannot reach data that was never collected — is on the law enforcement page.

Changes

If this policy changes in a way that affects you, the apps show you the new version rather than quietly swapping the page. Each version carries its effective date, and the previous text stays available in the site's history — this page is in a public repository, so every edit to it is a public commit.

Deutsche Fassung: Datenschutzerklärung.