Privacy

Plain language, not a legal contract. If something here is unclear, ask — see Contact below.

Tldr: while you're signed out, your writing stays only in your own browser. If you sign in (not live yet), it syncs to Firebase, a Google Cloud product, and Google's own staff have the same operator-level access any hosted database gives its host. Noos Notes is not end-to-end encrypted, and we can't promise every copy of something you delete disappears instantly everywhere. There's a real person behind this, reachable below.

What's stored while you're signed out

Writing without an account is the normal way to use Noos Notes. Everything you type is kept only in your own browser's local storage (IndexedDB) on the device you're using. It survives reloads, restarts, and normal navigation, but it never leaves that browser on its own — we don't see it, and it isn't backed up anywhere by us. If you clear your browser's site data, use a private/incognito window, or switch devices, that writing is gone. We don't have a copy.

What happens if you sign in

Signing in isn't live yet — this section describes what it will do once it is, honestly, in advance.

Signing in is meant for syncing your Writings and Letters across devices. Once it's live, a signed-in account's data is processed and stored by Firebase, which is a Google Cloud product. That means Google's own infrastructure holds it, under Google's own operational and security practices — Firebase/Google staff have the same privileged, operator-level access to production data that any team hosting a database on someone else's cloud has to accept. We don't control or audit Google's internal access, and we can't promise otherwise.

Analytics

We use PostHog, a US-based analytics company, to understand broad usage patterns — things like which screens get used, not what you wrote. PostHog never receives the words you write, a Writing's or Letter's title, or search text.

For a signed-in account, PostHog may receive your account's internal ID and your account email as identifiers attached to your usage events — that makes this data directly identifying inside PostHog, even though it never includes anything you actually wrote. While signed out, events are anonymous.

While Noos Notes is still in pre-launch testing, none of this reaches PostHog at all — analytics only start once the product is genuinely open to the public.

Error monitoring and infrastructure logs

We use Sentry for error monitoring and Google Cloud's own logging for infrastructure. Both are content-free by design: they receive technical details like error messages, stack traces, and timestamps, scrubbed of anything you wrote, any title, or your account email — never your content, never your identity tied to it.

Letters and email delivery

Letter delivery isn't live yet — no Letter has actually been emailed by this product. This section describes the plan honestly rather than staying silent about it.

When a scheduled Letter's date arrives, we plan to send it to your verified email using Resend, a US-based transactional email service. Sending an email necessarily means Resend can read that Letter's body — that's how delivery works. Resend's own policy is to retain a copy of a sent message for about 30 days for delivery/debugging purposes, after which it expires on their side. Until this pathway is actually wired up and turned on, no Letter body ever reaches Resend, or anywhere outside your own browser and (if you're signed in) Firebase.

What we don't do

Contact

Noos Notes is built by one person. For anything not covered above — account access, exporting or deleting your data, a lost-inbox recovery case, or anything else — reach out on Discord or X (@nsrCodes). Both are checked by the founder directly; there is no support team standing between you and a real decision about your data.

— nsrCodes

← back to noos notes