Last updated October 1, 2026

Privacy policy

The short version. Your notes go straight from your browser to your own Google Drive, OneDrive or Dropbox, and never pass through our servers. What we keep is what it takes to let your devices reach your storage and to know whether you have paid: an encrypted key to your storage, which storage accounts you connected and their email addresses, and your subscription’s email address. We don’t sell anything about you, we run no analytics or advertising, and the code is open source, so you can check all of this.

Who we are

The hosted Skysa Notes service, at skysa.com and notes.skysa.com, is run by David Furman, a sole proprietor doing business as Skysa (“Skysa”, “we”). We decide what personal information the service handles and why. Write to support@skysa.com about anything in this policy.

This policy covers the hosted service only. If you run Skysa Notes yourself from the public code, you are the one running it, and this policy does not apply to your copy.

Your notes

Every note is a Markdown file in a folder in your own storage. The app in your browser reads and writes those files directly with your storage provider. Our servers never receive, store or log the contents of a note, its title or its file name.

To let your devices do that, our server holds an encrypted key (an OAuth refresh token) for the storage account you connect, and hands your devices short-lived access from it. That key reaches only what the app is allowed to see: on Google Drive, the files the app created; on OneDrive and Dropbox, the app’s own folder. Our code never uses it to read your files, and the code is public.

Your notes are also kept in your browser’s storage on each device, so the app works offline. That copy never leaves the device except to sync with your storage. If you use the app without connecting storage (the free tier), everything stays on that device and we hold nothing about you at all.

What we keep, and for how long

WhatWhyHow long
A connected storage account: the provider, the account’s ID and email address, the encrypted key to it, and when it was connected and last usedTo let your devices sync, and to show you which account is connectedUntil you disconnect it in the app, which deletes it and asks the provider to revoke the key. If you stop using the app without disconnecting, it stays until you ask us to delete it
Each signed-in device: a random ID, a one-way hash of the device’s sign-in credential, and when it was created and last used. Nothing that names the device, and no IP addressTo let a device in, and to list your devices so you can sign one outWhile the account is connected (a device idle for 180 days stops syncing until it connects again). Once a device is signed out or the account disconnected, the record is cut off from your account and keeps nothing that names you
Your subscription: its Stripe customer and subscription IDs, your email address, its status and its datesTo know whether your storage accounts may syncFor as long as the subscription exists, and afterwards so that subscribing again with the same address picks up where you left off. Deleted on request
Which storage accounts you linked to the subscription: each account’s provider, ID and email address, your subscription’s email address, and when it was linked or unlinkedTo let every account you linked sync under one subscription, and to answer billing questionsIncluding links you have ended, until you ask us to delete them. Disconnecting an account in the app ends its link
Connect codes: a one-way hash of each code, the address it was sent to, and whenTo check a code you type, and to limit how many codes an address getsA code works for 15 minutes. Its record is deleted once it is an hour old, the next time anyone asks for a code
Free access we grant (for example to beta testers): the email address, until when, and a short note of whyTo honour itUntil you ask us to delete it, including after it ends
Logs: a short record when something fails on our servers, written never to include an email address, a code or a key; and Cloudflare’s records of requests it blocks or slows down to stop abuse, which include the IP address and the address requestedTo keep the service running, find faults and stop abuseA few days at most, under Cloudflare’s retention

Our database host can restore our databases to an earlier point for a limited period (currently up to 30 days), so something deleted can stay recoverable until that period passes. If we add backups, they will expire the same way.

We never have a password for you, because there is no account to create. Your storage account is how the app knows you, and your subscription’s email address is how we know you paid.

What we get from your storage provider

When you connect storage, you sign in with Google, Microsoft or Dropbox on their own page and choose to let Skysa Notes in. The provider then tells us your account’s ID and email address, and gives us the key described above. We ask for no more than the app needs:

Skysa Notes’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use what we get from any provider only to provide the sync you asked for, never for advertising, never to train any model, and we do not sell it or let anyone else read it.

Who else handles it

We use a small number of service providers, each only for the part of the service it runs:

These providers store and process data in the United States and in other countries where they operate. We share personal information with others only if the law requires it, and we would tell you unless the law forbids that. We do not sell or share personal information for advertising.

Cookies and tracking

The site at skysa.com sets no cookies and runs no scripts. The app sets two short-lived cookies, only while you connect storage: one holds the sign-in in progress (10 minutes), and one lets a repeated return from the provider’s page land in the same place (5 minutes). Cloudflare may set its own cookie to tell people from bots. There are no analytics, advertising or tracking cookies, and no third-party scripts.

One thing to know: if a note shows an image from elsewhere on the web, your browser fetches that image from the site that hosts it, which sees your IP address like any other visit.

Your choices and rights

Your notes are already yours to take anywhere: they are plain files in your storage, and the app can download every note as Markdown at any time.

Security

Storage keys are encrypted, and device credentials and connect codes are stored only as one-way hashes. All traffic is encrypted. No system is perfectly secure; if a breach ever affects your information, we will tell you as the law requires.

Children

Skysa Notes is not meant for children under 13, and we do not knowingly collect information from them. If you think a child has given us information, write to us and we will delete it.

Changes to this policy

If we change this policy, we will post the new version here with a new date. If a change matters to subscribers, we will email them before it takes effect.

Contact

David Furman, a sole proprietor doing business as Skysa
support@skysa.com