Legal

Privacy Policy

What Mydeas collects, why, who processes it, how long it is kept, and how to take it with you or delete it. Written in plain English to match what the product actually does.

Effective September 8, 2026 · Last updated September 15, 2026

Who we are

Mydeas is a notes app for the web, iOS, and Android, run from Wisconsin, United States. In this policy, “Mydeas”, “we”, and “us” mean the operator of the Mydeas service at mydeasapp.com. “You” means the person with the account. If anything here is unclear, write to [email protected].

The short version: your notes are yours. We collect what the product needs to work, we do not run third-party analytics or advertising trackers, we never sell data, AI features are off until you turn them on, and you can export everything or delete your account at any time without asking us.

What we collect

Everything below is collected because a feature needs it. We do not collect data “just in case”.

Account information

  • Email address — your sign-in identity and how we reach you about your account.
  • Password — if you sign up with email and password. We store only a bcrypt hash; we cannot see or recover your password.
  • Google or Apple sign-in identifier and name — if you sign in with Google or Apple, we receive a stable account identifier, your email address, and, when the provider shares it, the name on that account (Apple shares your name only the first time you sign in, and only if you allow it). We store that name as your display name, and it is shown to people you collaborate with — next to your comments, on shared notes, and in notifications. We do not receive your Google or Apple password, contacts, or any other data.
  • Display name and avatar — optional, set by you in settings (or taken from Google or Apple sign-in, as above). Your avatar is served from a web address that contains a long random identifier and needs no sign-in to load, so that collaborators’ apps can show it. Anyone who has that exact address can see the image; the address cannot be guessed or listed, and it changes when you upload a new photo.
  • Plan tier and billing references — whether you are on the free or paid plan, plus the Stripe customer and subscription identifiers Stripe assigns. We never see or store card numbers; Stripe handles payment details.
  • Role and status — whether the account is an administrator and whether it has been suspended.

Your content

  • Notes — titles and content, including formatting, checklists, and links. Note content is synced live between your devices through our sync relay and stored in our database.
  • Organization — notebooks, tags, note templates, tasks and their due dates, and comments on notes.
  • Attachments — images, audio, video, and PDFs you add to notes, stored as files on our server.
  • Text recognized in images — when you attach an image, we run optical character recognition (OCR) on it so the image becomes searchable. The recognized text is stored alongside the attachment. See AI features and OCR for the processor involved.
  • Version history — snapshots of a note’s content, taken at most once every five minutes while it is being edited, so you can view and restore earlier versions. We keep every snapshot from the last 30 days; after that, history is thinned to one snapshot per day, kept for up to one year.
  • Imports — content you import from Evernote (ENEX) or Notion is stored as ordinary notes and attachments.

Sharing and collaboration

  • Which notes and notebooks you have shared, with whom (by their Mydeas account), and at what permission level.
  • Public link tokens for notes or notebooks you have chosen to publish, and when they were created or revoked.
  • In-app notifications about shares, comments, and tasks involving you.
  • Reports and blocks — if you report a note, comment, or person, we store the report: what was reported, the reason you chose, any details you add, your account, and when. A person on our side reviews every report and records how it was resolved. If you block someone, we store that block (who you blocked and when) so it keeps applying; you can see and undo your blocks in settings.

Sessions and devices

  • Each sign-in creates a session token that lasts up to 30 days. We store a hash of it, not the token itself. On the free plan, the count of active sessions is what enforces the three-device limit; when a fourth signs in, the oldest session is signed out.
  • We do not collect device fingerprints, hardware identifiers, or precise location.

AI usage records

  • Whether you have turned AI actions on (they are off by default).
  • For each AI action you run: which action it was (clean up, summarize, or edit), the model used, how many input and output tokens it consumed, and when. We keep these to enforce the daily cap and to understand our costs. These records do not contain the note text or the result.

Integrations, API keys, and webhooks

  • Slack — if you connect Slack, we store the workspace and channel you chose and the bot token Slack issues, encrypted with AES-256-GCM. The integration only posts a message to your chosen channel when you share something; it does not read Slack messages.
  • Google Calendar — if you connect Google Calendar, we store the refresh token Google issues, encrypted with AES-256-GCM, along with the identifiers of calendar events we create for your tasks. We request only the calendar-events scope; we do not read your existing calendar or calendar list.
  • API keys — if you create one, we store a bcrypt hash and a short, non-secret prefix so you can recognize it in the list. The full key is shown once and never stored.
  • Webhooks — if you register one, we store the destination URL, the event types you selected, and the signing secret we generate for it.

Operational data

  • Request metrics — for each API request we record the path, HTTP status code, response time, and timestamp in memory on the server, so we can see latency and error rates. This buffer holds at most the last 10,000 requests, is never written to the database, contains no query strings, request bodies, or IP addresses, and is lost when the server restarts.
  • Rate limiting — sign-in and a few other endpoints are rate-limited per client to prevent abuse. Those counters live in memory for one minute.
  • Server logs — standard application logs, which can include your account identifier next to errors and AI usage lines. They do not include note content or passwords.
  • Website page views — on the public pages of mydeasapp.com (the home page, features, pricing, and legal pages, not the signed-in app), we count visits ourselves: the page address, the domain of the site that linked you (not the full link), any campaign tags in the link (utm_source, utm_medium, utm_campaign), a coarse device type (phone, tablet, or desktop), and the country our edge provider reports. To count unique visitors without cookies, our server combines your IP address and browser user agent with a random value that is kept only in memory and replaced every day, and stores just the resulting one-way code. Your IP address and user agent are never stored, and the code cannot be linked to you or to your visits on other days. We only look at these counts in aggregate, and page-view records are deleted after 13 months. If your browser sends Do Not Track or Global Privacy Control, no page view is sent or recorded.
  • In-app feedback — if you use “Send feedback” in the app, we store your message, the category you picked (bug, idea, question, or other), and the context the app attaches so we can act on it: the platform (web, iOS, or Android), the app version, and the page or screen you were on. It is linked to your account and deleted when you delete your account.
  • Administrator audit log — every action an administrator takes in the internal admin dashboard (for example suspending or deleting an account) is recorded with who did it and when.
  • Support email — if you write to us, we keep the correspondence so we can help you. Our support mailbox is hosted by our email provider (see Third-party processors).

How we use it

  • To provide the service: store, sync, search, share, and export your notes.
  • To sign you in and keep your account secure.
  • To run the optional features you turn on or invoke — AI actions, Slack, Google Calendar, API keys, webhooks.
  • To bill paid plans and keep your plan status in sync with Stripe.
  • To enforce plan limits (note count, storage, devices, daily AI actions) and to prevent abuse.
  • To keep the service running: monitoring latency, errors, and storage use.
  • To understand, in aggregate, how many people visit our website and how they found it.
  • To answer support requests.
  • To comply with the law and enforce our Terms of Service.

What we do not do

  • We do not sell your data, and we do not share it with anyone for advertising.
  • We do not run third-party analytics or tracking scripts, and the web app loads no third-party JavaScript. Fonts are bundled with the app, not fetched from a font service at page load. The only measurement is the aggregate, cookieless page-view count on our public website described under Operational data. Error reporting is not analytics: it fires only when something actually breaks, carries no identifiers for you, and is bundled with the app rather than loaded from another company’s servers (see Sentry).
  • We do not set cookies from the web app. Sign-in tokens are kept in your browser’s local storage and sent only to our API. Our edge provider (Cloudflare) may set its own operational cookies for security and bot protection, which we do not read.
  • We do not use your notes to train AI models, and we do not send any note content to an AI provider unless you run an AI action on that note.
  • We do not read your notes. Note content is not end-to-end encrypted — it is encrypted in transit and stored on our servers so that sync, search, sharing, and version history can work — so a small number of people operating the servers could technically access it. We do so only when necessary to investigate abuse, respond to a legal obligation, or help you with a support request you have made, and the admin dashboard itself shows account metadata (email, plan, storage used, note count, AI usage), not note content.

Third-party processors

These are the companies that handle some of your data on our behalf. Each one is there for a specific reason and receives only what that reason requires.

ProviderPurposeWhat they receive
Amazon Web ServicesHosting; OCROur servers, database, and attachment storage run on AWS Lightsail in the US East (Ohio) region (us-east-2), so all of your data is stored there. Separately, AWS Textract receives the bytes of each image attachment once, to recognize text in it.
CloudflareDNS, TLS, edge proxyAll traffic to mydeasapp.com passes through Cloudflare’s network, which terminates TLS and forwards requests to our servers. Cloudflare sees connection metadata (including your IP address) in transit.
StripePaymentsIf you subscribe, Stripe collects and stores your payment details and billing address on its own checkout and billing-portal pages. We receive your email, the customer and subscription identifiers, and subscription status events.
AnthropicAI actions (opt-in)Only when you have turned AI actions on and run one: the plain text of that note and, for the edit action, your instruction. Nothing is sent otherwise.
SentryError reportingWhen something breaks in the web app, the admin, our API, the sync service or the mobile apps, the error is reported to Sentry so we can fix it: the error message and stack trace, the browser or device model and OS, the app version, and the page path with any note identifiers and query strings removed. Note content, titles, search terms, email addresses and IP addresses are not sent — IP storage is switched off on our Sentry projects — and browser reports are sent through mydeasapp.com rather than to Sentry directly. Sentry keeps error reports for 90 days.
GoogleSign-in; Calendar (opt-in)If you sign in with Google, Google knows you signed in to Mydeas. If you connect Google Calendar, we create and update all-day events in your calendar for tasks with due dates, sending the task’s text, its date, and a link back to the note.
AppleSign-inIf you sign in with Apple, Apple knows you signed in to Mydeas. If you chose to hide your email, we receive Apple’s relay address instead.
SlackNotifications (opt-in)If you connect Slack, we post a short message to the channel you chose when you share a note or notebook. The message contains the note or notebook title and the email address you shared it with; it does not contain note content.
Our email providerSupport mailboxIf you email [email protected], your message, your email address, and anything you attach are stored in our mailbox, which our email provider hosts.

Each of these providers handles data under its own privacy policy. We do not use any provider for advertising or analytics, and we will update this table before adding one.

AI features and OCR

AI actions

AI actions (clean up, summarize, and edit) are off by default. Turning them on is a single switch in the app that names the vendor (Anthropic) and says what is sent. While the switch is on, note text is still sent only when you explicitly run an action on a specific note — never in the background, and never for notes you have not selected. The result comes back as a suggestion you can accept or discard; we never change a note automatically.

Free accounts can run 1 AI action per day and paid accounts 50, resetting at midnight UTC. Requests go from our server to Anthropic’s API; your browser or phone never talks to Anthropic directly. We do not use your content to train models, and Anthropic processes these requests under its commercial API terms.

OCR of image attachments

To make photos and scans searchable, every image you attach to a note is sent once to AWS Textract, which returns any text it can recognize. That text is stored with the attachment and included in search. OCR is not currently optional; if you would prefer an image not be processed, do not attach it. We may add a per-account switch in future and will note it here if we do.

Sharing and public links

When you share a note or notebook with another Mydeas user, they can see its content at the permission level you chose, and their edits and comments are attributed to their account. When you create a public link, anyone with the link can view that note — or, for a notebook link, every non-trashed note in that notebook — without signing in. Public links are view-only, are not listed or indexed by us, and stop working the moment you revoke them. You are responsible for what you share and with whom; see the Terms of Service.

Retention and deletion

  • While your account exists, we keep your content until you delete it. Notes you delete go to the trash, where they stay until you empty it or permanently delete them; trashed notes are not purged automatically. Permanently deleting a note removes its content, attachments, version history, comments, tasks, and any public link.
  • Version history: every snapshot from the last 30 days is kept; older history is thinned to one snapshot per day and deleted once it is a year old.
  • Sessions expire after 30 days, or sooner when signed out or displaced by the free-plan device limit.
  • Website page-view records are deleted after 13 months.
  • Request metrics exist only in server memory, hold at most the last 10,000 requests, and are gone on restart.
  • Deleting your account (Settings → Account, confirmed by retyping your email) first cancels any active Stripe subscription, then permanently deletes your notes, notebooks, tags, attachments and their files, version history, sync documents, comments, tasks, shares, public links, notifications, feedback you sent from the app, your avatar, API keys, webhooks, Slack and Google Calendar connections (including the encrypted tokens), sessions, and your user record. This runs as one transaction: it either completes fully or not at all. It cannot be undone.
  • What may remain after deletion: comments you left on other people’s notes and tasks assigned to you on their notes stay on their notes, shown as “(deleted user)” with no link back to you. Content-free usage records (AI action counts and token totals, the administrator audit log) may be retained; they reference an account identifier that no longer resolves to anyone. Stripe retains transaction records as required by financial regulation. Copies may persist briefly in server backups before those are overwritten.

Export

You can take everything with you at any time, on either plan, with no request form. Any note can be exported as Markdown or HTML, and your whole account can be exported as a single ZIP containing every note, your attachments, and a manifest. Export is available in the web app, the mobile app, and the API, and it is never paywalled.

Security

  • All traffic is encrypted in transit with TLS, both at the edge and between the edge and our servers.
  • Passwords and API keys are stored as salted bcrypt hashes. Session refresh tokens are stored hashed.
  • Slack and Google Calendar tokens are encrypted at rest with AES-256-GCM.
  • Webhook deliveries are signed with HMAC-SHA256 so your receiver can verify they came from us. Incoming Stripe webhooks are signature-verified before we act on them.
  • Sign-in, registration, and public-link endpoints are rate-limited.
  • Application servers are reachable only through the reverse proxy, never directly from the internet.
  • Administrator actions are recorded in an audit log.

No system is perfectly secure. If we learn of a breach affecting your data, we will tell you promptly and describe what happened and what we are doing about it. If you believe you have found a security issue, please email [email protected].

Your rights

Wherever you live, you can do the following yourself, without contacting us:

  • Access and portability — export any note or your entire account (see Export).
  • Correction — edit your name, avatar, and any content directly in the app.
  • Deletion — delete individual notes, or your whole account from settings.
  • Opt out of AI processing — leave AI actions off, or turn them off at any time.
  • Disconnect integrations — remove Slack, Google Calendar, API keys, and webhooks from settings, which deletes the stored tokens and secrets.

If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have rights under data-protection law such as the GDPR to object to or restrict certain processing and to lodge a complaint with your local supervisory authority. Our legal basis for processing is performance of our contract with you (providing the service), our legitimate interests in keeping the service secure and running, and your consent for the optional features you turn on. If you are a California resident, you have rights under the CCPA/CPRA to know what personal information we collect, to delete it, and to not be discriminated against for exercising those rights; we do not sell or share personal information as those laws define it. To exercise any right you cannot exercise yourself in the app, email [email protected] from your account address and we will respond within 30 days. We honor these requests for everyone, not only people in those regions.

Where your data lives

Your data is stored in the United States, on servers in AWS’s US East (Ohio) region. Cloudflare routes traffic through its global network, and the processors listed above may process data in the countries where they operate. If you use Mydeas from outside the United States, you are transferring your data to the United States, where privacy laws may differ from those in your country.

Children

Mydeas is not directed at children under 13, and we do not knowingly collect personal information from them. You must be at least 16 years old (or the age of digital consent in your country, if higher) to create an account. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

When we change this policy, we will update the “Last updated” date at the top. For material changes — a new processor, a new category of data, or a change to how long we keep something — we will tell you in the app before the change takes effect. We will not apply a material change retroactively to data we already hold without giving you a chance to export and leave first.

Contact

Questions, requests, or concerns about privacy: [email protected]. We read every message.

This policy is written and published by Mydeas. It describes our own practices and is not legal advice from any third party.