Nottuk logoNottuk

Privacy

Last updated 22 September 2026

Nottuk is a notes app. This page explains what we store, how note content is encrypted, and the limits of that protection.

What we store

  • Account details you give us: your name and email address, plus whether that email has been verified.
  • Sign-in sessions, including a session token, expiry, and the IP address and browser user agent recorded with the session.
  • Your notes, folders, tags, favorites, pins, and trash state.
  • Sharing details: public link tokens, permissions, expiry, and the email addresses you invite to a private share.

We use this information to run the product: sign you in, show your notes, and deliver shares you create. We do not sell personal information, and we do not run advertising or third-party analytics trackers.

Notes are encrypted — still avoid sensitive data

Note titles, body text, excerpts, and the editor document are encrypted before they are written to the database. Encryption uses AES-256-GCM. Each value gets its own random initialization vector, and the ciphertext is bound to that note so it cannot be swapped onto a different note.

This is encryption at rest. Nottuk holds the encryption key so the app can decrypt a note when you open it. It is not end-to-end encryption, and it is not a zero-knowledge vault. Anyone who can use the service with your account — including the operator of this deployment — can read notes in order to display them.

Do not save sensitive data in Nottuk. Encryption reduces the chance that a raw database copy is readable. It does not make the app a safe place for secrets. We do not recommend storing any of the following:

  • Passwords, recovery codes, API keys, access tokens, or private cryptographic keys.
  • Payment card numbers, bank account details, or tax identifiers.
  • Government ID numbers, passport details, or copies of identity documents.
  • Health, medical, or other information covered by a privacy law we do not claim to meet.
  • Anything you would not want exposed if your account, device, or a share link were compromised.

Nottuk is not a password manager and is not certified for HIPAA, PCI, or similar regulated data. Do not use it for that kind of information.

Practical precautions

  • Treat a share link as a secret. Anyone with the link can read that note for as long as the share is active. Set an expiry, use view access when edit access is unnecessary, and revoke the link when you are done.
  • Private shares go to the email addresses you enter. Confirm the address before you send it.
  • Sign out on shared or public computers. A signed-in browser can open your notes.
  • Keep your email account secure. Sign-in uses a one-time code sent to that address.
  • Encryption does not cover text you copy into another app, screenshots, exports, or messages you send yourself.
  • Account fields such as your name and email are stored so we can sign you in. They are not encrypted the same way as note content.

How long we keep data

Notes stay in your account until you delete them. Trashed notes remain recoverable until you permanently delete them. Sessions expire on their own. If you delete your account, we delete the account record and the notes, folders, tags, and shares tied to it.

Cookies and local storage

Sign-in uses a session cookie. Theme and accent choices are stored in your browser. Details are on the Cookies page.

Your choices

You can edit or delete notes, revoke shares, and sign out at any time. To ask what we hold about your account, use the email address on that account and contact the operator of this Nottuk deployment.

Changes

If this policy changes, the date at the top of the page will change with it. Continued use of Nottuk after an update means you accept the revised policy. The Terms cover how the service may be used.