Last updated October 1, 2026
Privacy policy
The short version. Your notes go straight from your browser to your own Google Drive, OneDrive or Dropbox, and never pass through our servers. What we keep is what it takes to let your devices reach your storage and to know whether you have paid: an encrypted key to your storage, which storage accounts you connected and their email addresses, and your subscription’s email address. We don’t sell anything about you, we run no analytics or advertising, and the code is open source, so you can check all of this.
Who we are
The hosted Skysa Notes service, at skysa.com and notes.skysa.com, is run by David Furman, a sole proprietor doing business as Skysa (“Skysa”, “we”). We decide what personal information the service handles and why. Write to support@skysa.com about anything in this policy.
This policy covers the hosted service only. If you run Skysa Notes yourself from the public code, you are the one running it, and this policy does not apply to your copy.
Your notes
Every note is a Markdown file in a folder in your own storage. The app in your browser reads and writes those files directly with your storage provider. Our servers never receive, store or log the contents of a note, its title or its file name.
To let your devices do that, our server holds an encrypted key (an OAuth refresh token) for the storage account you connect, and hands your devices short-lived access from it. That key reaches only what the app is allowed to see: on Google Drive, the files the app created; on OneDrive and Dropbox, the app’s own folder. Our code never uses it to read your files, and the code is public.
Your notes are also kept in your browser’s storage on each device, so the app works offline. That copy never leaves the device except to sync with your storage. If you use the app without connecting storage (the free tier), everything stays on that device and we hold nothing about you at all.
What we keep, and for how long
| What | Why | How long |
|---|---|---|
| A connected storage account: the provider, the account’s ID and email address, the encrypted key to it, and when it was connected and last used | To let your devices sync, and to show you which account is connected | Until you disconnect it in the app, which deletes it and asks the provider to revoke the key. If you stop using the app without disconnecting, it stays until you ask us to delete it |
| Each signed-in device: a random ID, a one-way hash of the device’s sign-in credential, and when it was created and last used. Nothing that names the device, and no IP address | To let a device in, and to list your devices so you can sign one out | While the account is connected (a device idle for 180 days stops syncing until it connects again). Once a device is signed out or the account disconnected, the record is cut off from your account and keeps nothing that names you |
| Your subscription: its Stripe customer and subscription IDs, your email address, its status and its dates | To know whether your storage accounts may sync | For as long as the subscription exists, and afterwards so that subscribing again with the same address picks up where you left off. Deleted on request |
| Which storage accounts you linked to the subscription: each account’s provider, ID and email address, your subscription’s email address, and when it was linked or unlinked | To let every account you linked sync under one subscription, and to answer billing questions | Including links you have ended, until you ask us to delete them. Disconnecting an account in the app ends its link |
| Connect codes: a one-way hash of each code, the address it was sent to, and when | To check a code you type, and to limit how many codes an address gets | A code works for 15 minutes. Its record is deleted once it is an hour old, the next time anyone asks for a code |
| Free access we grant (for example to beta testers): the email address, until when, and a short note of why | To honour it | Until you ask us to delete it, including after it ends |
| Logs: a short record when something fails on our servers, written never to include an email address, a code or a key; and Cloudflare’s records of requests it blocks or slows down to stop abuse, which include the IP address and the address requested | To keep the service running, find faults and stop abuse | A few days at most, under Cloudflare’s retention |
Our database host can restore our databases to an earlier point for a limited period (currently up to 30 days), so something deleted can stay recoverable until that period passes. If we add backups, they will expire the same way.
We never have a password for you, because there is no account to create. Your storage account is how the app knows you, and your subscription’s email address is how we know you paid.
What we get from your storage provider
When you connect storage, you sign in with Google, Microsoft or Dropbox on their own page and choose to let Skysa Notes in. The provider then tells us your account’s ID and email address, and gives us the key described above. We ask for no more than the app needs:
- Google: your email address and Google account ID (
openid,email), and access to only the Drive files Skysa Notes creates (drive.file). - Microsoft: your email address and account ID (
openid,email), access to the app’s own OneDrive folder (Files.ReadWrite.AppFolder), and staying connected (offline_access). - Dropbox: your account ID and email address (
account_info.read), and access to the app’s own Dropbox folder.
Skysa Notes’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use what we get from any provider only to provide the sync you asked for, never for advertising, never to train any model, and we do not sell it or let anyone else read it.
Who else handles it
We use a small number of service providers, each only for the part of the service it runs:
- Cloudflare hosts the site, the app and our databases, keeps the request logs above, and protects the service from attacks.
- Stripe runs checkout, billing and the page where you manage your subscription. Your card details go to Stripe, never to us. Stripe sends receipts and billing emails, and keeps payment records as the law requires. See Stripe’s privacy policy.
- ZeptoMail, by Zoho, sends connect codes. It receives your address and the email, which contains the code, and keeps a record of messages sent for a limited time. Opens and clicks are not tracked.
- Your storage provider (Google, Microsoft or Dropbox) holds your notes under its own terms and privacy policy, as it holds the rest of your files.
These providers store and process data in the United States and in other countries where they operate. We share personal information with others only if the law requires it, and we would tell you unless the law forbids that. We do not sell or share personal information for advertising.
Cookies and tracking
The site at skysa.com sets no cookies and runs no scripts. The app sets two short-lived cookies, only while you connect storage: one holds the sign-in in progress (10 minutes), and one lets a repeated return from the provider’s page land in the same place (5 minutes). Cloudflare may set its own cookie to tell people from bots. There are no analytics, advertising or tracking cookies, and no third-party scripts.
One thing to know: if a note shows an image from elsewhere on the web, your browser fetches that image from the site that hosts it, which sees your IP address like any other visit.
Your choices and rights
- Disconnect a storage account in the app at any time. That deletes our record of it and revokes our key where the provider allows. You can also remove Skysa Notes from your Google, Microsoft or Dropbox account’s connected apps.
- Cancel your subscription from the subscription page. Your notes stay in your storage and on your devices.
- Ask us at support@skysa.com for a copy of what we hold about you, to correct it, or to delete it. We will answer within 30 days. Depending on where you live, you may have further rights under your local law, and we will honour them.
Your notes are already yours to take anywhere: they are plain files in your storage, and the app can download every note as Markdown at any time.
Security
Storage keys are encrypted, and device credentials and connect codes are stored only as one-way hashes. All traffic is encrypted. No system is perfectly secure; if a breach ever affects your information, we will tell you as the law requires.
Children
Skysa Notes is not meant for children under 13, and we do not knowingly collect information from them. If you think a child has given us information, write to us and we will delete it.
Changes to this policy
If we change this policy, we will post the new version here with a new date. If a change matters to subscribers, we will email them before it takes effect.
Contact
David Furman, a sole proprietor doing business as Skysa
support@skysa.com