Privacy Policy
The short version
- Your note lives on your devices. If you do not use sync, your note is not sent to us.
- If you use sync, your note is encrypted on your device before it is uploaded. The key stays on your devices. We cannot read your note.
- No ads, no analytics and no trackers, in the app or on this website.
- If you lose every device that holds your key, your synced data cannot be recovered by anyone, including us.
Who we are
Nearleaf is made and operated by staticvar (staticvar.dev), referred to as "we" below. We run the Nearleaf apps for Android, iOS and Mac, the optional sync service, and this website. We are responsible for the personal data described in this policy.
What stays on your device
Nearleaf keeps your note in a local database inside the app's private storage. Using the app without sync does not require an account and does not send your note anywhere.
The app stores these things locally:
- Your note, as plain text. We do not add a separate layer of encryption to the on-device copy; it relies on your device's own protection, such as its lock screen and app sandbox.
- Sync bookkeeping, if you use sync: your account and device identifiers, a copy of the note as of the last sync, your position in the revision history, and any encrypted change still waiting to upload.
- Merge highlights: the positions and times of text that was merged from another device, so it can be highlighted until you dismiss it.
- App preferences, such as appearance and dictation language.
- Your encryption key, if you use sync. See Encryption and your key.
Nearleaf for Android opts out of Android's cloud backup and device-to-device transfer, so none of this is copied into those backups. The pairing camera step uses your phone's own camera app, so Nearleaf does not ask for camera permission.
What our sync service stores
This applies only if you use sync. The service is a relay: it stores and forwards encrypted changes between your devices. It is designed so that it never needs your note in readable form. For each saved change it stores:
- The encrypted change
- Ciphertext of up to 64 KiB that only your devices can decrypt. It contains your edit, not a readable copy of your note.
- Ordering and integrity data
- A sequence number, the hash of the previous change and of this one, a random batch identifier used to recognise retries, the key epoch (a counter that changes if your key changes), and a format version.
- Which device sent it
- The identifier of the sending device.
- When it arrived
- A timestamp from our server clock.
To authorise your devices, the service also holds:
- Your account identifier and each device identifier. These are opaque identifiers, not your name or email address. The account identifier also decides which stored note history belongs to you.
- For each sync token, a one-way SHA-256 hash of the token (never the token itself) with its expiry time.
While your devices are connected, the service keeps the connection state needed to deliver changes and to tell each of your devices how many of your other devices are online.
Pairing messages. When you add a device, the two devices exchange small encrypted messages (up to 4 KiB each) through the relay, together with a pairing identifier, the two device identifiers and an expiry of at most two minutes. This data is deleted when it expires or when pairing is cancelled.
What we can infer. Even without reading your note, a sync service can see that you use Nearleaf, when you make changes, roughly how large they are, and how many devices you have. We do not use this for anything other than running the service.
The sync service as built does not store your name, email address, phone number, password, payment details or location. If that ever changes, we will update this policy before the change takes effect.
Encryption and your key
- When you first turn on sync, your device generates a random 256-bit key. It is not derived from a password or any account detail.
- Changes are encrypted on your device with AES-256-GCM before upload and decrypted only on your devices.
- The key is never uploaded. The one exception is pairing a new device: the key travels from your device to the new one inside a message sealed with keys agreed directly between the two devices (ECDH on the P-256 curve) and a one-time secret carried in the QR code. The relay only forwards the sealed message.
- Connections to the sync service use HTTPS and secure WebSockets. Unencrypted connections are only allowed to your own computer for development.
Where the key is kept on each platform:
- Android: in the app's no-backup storage, wrapped by a non-exportable key in the Android Keystore.
- iOS: in the Keychain, marked this-device-only and not synchronised through iCloud Keychain.
- Mac: in a file in the Nearleaf folder of your Application Support directory, readable only by your user account. It is not additionally encrypted at rest.
If you lose all your devices
The key exists only on your devices. If you lose or reset every device that holds it, your synced data on our servers can no longer be decrypted, and neither we nor anyone else can recover it.
Restoring a phone from a backup does not bring the key back. Keep at least one paired device, and pair a replacement before you retire the old one.
Payments
Subscriptions are sold, billed and managed by Google Play or the Apple App Store, under their terms and privacy policies. We never see your payment card or billing details. We receive only subscription status, such as whether a subscription is active and when it ends, so we can switch sync on or off.
No analytics, ads or tracking
- The apps contain no analytics, advertising or crash-reporting libraries.
- We do not sell or share your data for advertising, and we do not build profiles.
- This website sets no cookies and runs no scripts. It loads nothing from other sites, and the pages are served with a security policy that blocks it.
- Our sync service does not record request contents, and request logging and tracing are switched off in its configuration. The only thing it logs is a technical error report (error type, message and stack trace) when something unexpected fails. It cannot contain your note, because the server never has it in readable form.
Our hosting providers still see ordinary network information, such as your IP address, to deliver requests. See the next section.
Service providers
- Cloudflare
- Runs the sync service on Cloudflare Workers and Durable Objects. It stores the encrypted data described above and, like any network provider, processes connection data such as IP addresses to deliver traffic. Data may be handled in data centres outside your country. Cloudflare also hosts the nearleaf.page website and pairing page, and may process ordinary web server logs such as IP address, requested address and browser type. We do not use Cloudflare Web Analytics. See Cloudflare's own privacy policy.
- Netlify
- Hosts the original nearleaf.staticvar.dev website and pairing link page. It may keep ordinary web server logs (such as IP address, requested address and browser type) under its own policy. We do not use Netlify analytics.
- Google and Apple
- Provide app distribution, payments and subscription management. If you opt in through your device settings, they may give us aggregate download or crash statistics.
If we add another provider that handles personal data, we will list it here before using it.
Retention and deletion
- On your device: data stays until you delete the app or its data.
- Pairing messages: deleted at expiry, within two minutes of creation at most.
- Encrypted changes: kept, in order, so that any of your devices can catch up from wherever it left off. The service does not currently delete or compact them automatically. Because changes are kept as history, text you later delete from your note may still exist, encrypted, in that history.
- After a subscription ends: sync stops and your note stays on your devices. We keep the encrypted copy on our servers for 30 days after your subscription ends, so you can resubscribe without losing sync history. After those 30 days we delete it.
Deleting your server data. Email me@staticvar.dev to ask us to delete your encrypted data. Because we do not hold your name or email address, we may need an identifier from your app to find your data. We will act on a verified request within 30 days. Data held in our providers' own redundancy systems is removed on their schedules.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export personal data we hold about you, to object to or restrict how it is used, and to complain to your local data protection authority. Contact us to use these rights. We will respond as far as we can identify data as yours. Note that we cannot read your note, so we can only provide or delete the encrypted form.
Children
Nearleaf is not directed at children under 13 (or under 16 where local law sets a higher age). We do not knowingly collect personal data from children. If you believe a child has used the sync service, contact us and we will delete the data.
Changes to this policy
We may update this policy as the product changes. The effective date at the top shows the current version. We will make material changes visible on this page and, where the app can, in the app, before they take effect.
Contact
Questions about privacy or this policy: me@staticvar.dev. See also our Terms of Service.