privacy

Privacy policy,
plainly stated.

This describes what blk/txt collects about you, why, and how long it keeps it. It applies the same way to the hosted web app, the API, and the mobile client.

What we collect

When you open an account, we store your email address and a hash of your password, never the password itself. We store the text you write or import, and everything the app derives from it: the dated blocks it is split into, the entities and metrics extracted from it, and the annotations from the optional analysis that suggests key terms, concepts, and similar notes. If you generate an API token for the CLI or another client, we store a hash of that token as well, never the plaintext, which is shown to you once at creation and never again. If you are on the paid plan, we store your subscription status as reported by our payment provider: an identifier for your record with them, the plan you are on, and when the current billing period ends. Finally, we keep a running daily count of a fixed, small set of events, such as a trial starting or a login happening, with nothing else attached to that number: no identifier that ties a count back to an account, a device, or a network address.

What we do not collect

We run no analytics script and load no third-party tracker on any page, so nothing about how you use the app is sent to an outside service. We do not collect an advertising identifier of any kind, because we run no advertising. We do not record your location unless you attach a coordinate to a specific note yourself, and even then the value is rounded to a coarse resolution before it is stored, closer to neighbourhood scale than a street address. Card numbers, billing addresses, and other payment details never reach us at all: our payment provider's own hosted page collects them directly, and what comes back to us is limited to a status and an identifier for your record there.

How we use it

Your notes and everything derived from them exist to run the parsing, search, and timeline features you use the app for, and for nothing else. No language model reads your notes as part of that. Your email and password hash authenticate you. Subscription status decides whether the paid features of your account are open. The daily event counts tell us whether the trial and the paid plan are being used at all, in aggregate, and say nothing about any one visitor. Your network address is used only for a moment, to apply a rate limit against repeated login or trial attempts from the same source; it is not stored against your account or kept alongside anything else we hold.

Where it lives

The hosted service runs on a server operated by our hosting provider, and its database is continuously streamed to a separate object storage service operated by a backup provider, so your account survives the loss of the machine it runs on. Both act as processors on our instructions, handling data only to help run the service, never as services we sell your data to. Traffic between your browser or the mobile app and our servers is encrypted in transit.

Locked notes

Locking a note encrypts its current text and location under a key derived from your account password. Nobody, us included, can read it without that password, and there is no way to recover it if the password is lost. That guarantee covers a note's current wording. It does not cover a note's past states: earlier versions kept in its history remain unencrypted in the database, including the original wording if you lock a note you have never edited, so someone with direct access to the database could still read those earlier versions. Write with that in mind.

The trial

The trial needs no account, no card, and no email address. It runs for 48 hours measured from your last visit to it, and once that window passes with no activity, its contents are permanently cleared. Treat it as a look at the product, not a place to keep anything you would mind losing.

Exporting and deleting your data

You can export everything your account holds, in JSON, CSV, or Markdown, at any time, whether or not your plan is current: export is never behind the paywall. You can delete your account and everything in it from Settings or from the mobile app. Deleting an account removes it from the live database immediately; a copy can remain in a recent backup snapshot for up to 30 days afterward, which is how long our backup provider retains one before it is rotated out.

Who we share it with

We share what is necessary to run the service with five kinds of processor and nobody else: our payment provider, to bill the paid plan; our hosting provider, to run the server your account lives on; our backup provider, to hold the streamed backup described above; an email delivery provider, to send the weekly letter to an account that turns email on for it and confirms an address; and a push delivery provider, to deliver that same letter as a notification to an account that turns that on instead. We do not sell or rent your data, and we do not share it with an advertiser, a data broker, or any party outside of running the service you signed up for.

Children

blk/txt is not directed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has given us information, contact us using the details below and we will remove it.

Changes to this policy

We update the date at the top of this page whenever this policy changes, and describe a material change in the section above rather than leaving the date to speak for itself. Continuing to use the service after a change means you accept the updated policy.

Contact

[Placeholder: the maintainer needs to add a monitored contact email or postal address here before this page is published. Nothing below this line is a working contact yet.]