Version 2026-10-04

Privacy Policy

This policy explains what Notchbox holds about you, who else handles it, and what you can do about it. "We" and "us" means the independent developer who runs Notchbox.

The short version

Everything you write in Notchbox is encrypted in your browser before it is sent. We hold no key that can open it. We can see your email address and some facts about your account's activity, and our server logs record the internet address each request came from. We can't see what you wrote.

What we hold

  • Your email address, confirmed with a code. We use it to sign you in, to confirm it is yours, and to warn you about your account (for example when your password, a passkey or a two-factor setting changes), and, if ever needed, to tell you about something that affects the service itself. We don't send marketing.
  • Encrypted entries and settings. Each one is a locked block we store and send back to you. We can see how many there are, roughly how big each one is (sizes are rounded up), and when each one last changed.
  • Locked copies of your key. The key that opens your data is stored only in locked form: one copy for your password, one for your recovery code and one for each passkey. We cannot open any of them.
  • What we need to check a sign-in. A value your browser works out from your password (not the password itself), and the same for your recovery code. If you add a passkey, its public key and a short label for the device. If you turn on two-factor sign-in, its secret (stored encrypted), your backup codes (stored only in a form that can check them, not read them) and, for each device you ask us to remember, a label such as "Chrome on Windows".
  • Sessions: a record that you are signed in, until it ends or you sign out.
  • Server logs. For each request: the internet (IP) address it came from, your browser type, the exact address requested and the page you came from (with any secret code in them hidden), when, and whether it worked (and, when you are signed in, your account's internal number). The logs never contain your email address, your password or anything you send in the body of a request. If you installed Notchbox as an app, the address it opens with marks it as the app, so our logs show when it was opened from its icon rather than a browser tab. We keep them for 3 months.
  • Which version of the Terms and this policy you accepted, and when, so we can show that you agreed.
  • The invite code you signed up with.
  • Emails to us. When you sign up, confirm your email, or your unconfirmed account is removed, and when you use the contact or invite-request form, we are sent an email with your email address, the invite code, your account's internal number, the time, your browser type, your IP address, the network name it resolves to, and your rough country. A vulnerability report sends only what you type, the time it arrived and, if you give one, your email address so we can reply. These emails stay in our mailbox until we delete them. Our server does not store contact messages.

We use this information only to run the service, to keep it and your account secure, and to meet our legal obligations.

What we can't see

The contents of any entry, your password, your recovery code, the key that opens your data, and anything in a backup file you export. This is why we can't reset your password or recover your data for you.

Your browser also keeps some things on your own device: an encrypted copy of your data, so the app can keep working if the connection drops after you've unlocked it, and the date of your last backup. While you use the Maps tab, the location picker or the Venue page's map, the map provider's own code stores map data in your browser; the app clears it when it locks, though your browser's ordinary cache may keep map images for a while.

Who else handles data

ProviderWhat forWhat it sees
Network and security providerProtects the whole service, checks for bots on the signup, contact and vulnerability-report pages, and keeps traffic totals from every requestEvery request on its way to us (the app and the public pages alike): your IP address, your browser and the signals its security check reads from it, timing, and your encrypted data in transit. It can't open your entries. From those same requests it also keeps totals (visits, pages or addresses requested, rough country, browser type) across the whole service; it sees requests, never the contents of your entries. No script is added to any page for this.
Hosting providerHosts our server and databaseWhat we hold, as above.
Email providerSends our emailsYour email address and the email's text: a code, a security alert, or a message you sent us through the contact form, and our own notices about sign-ups and messages, which include your IP address and browser. Never your entries.
Mailbox providerHolds the emails we receiveThe emails described under What we hold: your email address, the invite code, time, browser type, IP address and network name, rough country, and any message you sent us. Never your entries.
Map providerDraws the Maps tab, the location picker and the Venue page's mapThe map areas you view, your IP address and browser, and the map provider's own usage counts. When you press the 📍 GPS button while adding or editing an entry, the location picker opens at where you are, so the map provider also sees the streets around you at that moment. Never your entries.
Backup storage providerKeeps a daily copy of our database with a different company from our host, so one failure can't lose everything. Each copy is kept for 30 daysEncrypted files, and when they arrive and how large they are. It can't open them: each copy is encrypted before it leaves our server, and the key that opens it is kept offline by us, never by the backup provider or our host.
Log providerKeeps our server logs for 3 months and emails us when something on the server failsWhat the logs hold: IP address, browser type, the addresses requested and the page you came from, when, and your account's internal number. Never your email address, your password or your entries.

Currency rates are fetched by our server, not your browser, so the rate service never sees you.

Your entries are encrypted on your device before they reach us, so there's nothing in them for us to sell. The one thing we can read that identifies you is your email address, and we never sell or share it. The app itself carries no advertising, tracking or analytics of its own. Nothing inside it follows what you do. Our network and security provider, which sits in front of the whole service, keeps traffic totals from every request passing through it, the public pages and the app alike (visits, pages or addresses requested, rough country, browser type), without adding a script to any page; it sees requests, never the contents of your entries. We may in future add an analytics service to the public pages only, never to the app. If we do, this policy will list it here before it starts.

Cookies

We use only the cookies the service needs to work, so there is no cookie banner:

  • Session: keeps you signed in until the session ends or you sign out.
  • Remembered device: set only if you use two-factor sign-in and choose to remember a device, so you aren't asked for a code on it every time. It lasts up to 30 days.
  • Known device: set when you sign in, so a flood of wrong passwords aimed at your address doesn't lock your own devices out. It lasts up to 30 days.
  • Security check: our network and security provider sets a short-lived cookie on every page, for 30 minutes, to tell people from automated traffic, and another when your browser passes its check on the signup, contact and vulnerability-report pages, so you aren't checked again for a while.

We use no advertising or analytics cookies today.

How long we keep it

  • Your account: until you delete it. Deleting it removes your email address, every encrypted entry and everything else stored with the account, except a record that you agreed to our Terms: the version, the date you agreed, the date you deleted the account, and a scrambled form of your email address that we can't turn back into your address but can match if you give it to us. We keep that record for 10 years after you delete your account, in case of a dispute. Log lines already written stay until their 3 months are up. Copies in our backups are gone within 30 days.
  • Server logs: 3 months.
  • Emails to us about sign-ups and messages: until we delete them.
  • An account whose email was never confirmed: removed after seven days.

Your rights

Wherever you live, you can:

  • See your data: everything you wrote is in the app, and only you can read it.
  • Take a copy: export your data from Settings at any time.
  • Correct it: edit or delete any entry in the app.
  • Delete it: delete your account from Settings at any time.
  • Object, or ask: about anything we hold on you, or how we use it.

Most of this you can do yourself in Settings. For anything else, send a "Privacy request" through the contact form, and we will answer within the time the law where you live requires. Because we can't read your entries, we can't find, change or delete a particular entry for you; you do that in the app. You may also have the right to complain to the data protection authority where you live.

Children

Notchbox is only for people aged 18 or older. If we learn that an account belongs to someone younger, we will delete it.

Where your data is held

Our servers are in North America. The companies listed above may handle data in other countries as part of the services they provide to us.

Changes

The version date at the top of this page is the date of the policy in force. When we change the policy, that date changes. If a change is significant, we will announce it on this site before it takes effect.

Contact

Use the contact form. We don't publish an email address.