Privacy Policy
Last updated: 23 August 2026
Heldnote runs entirely in your browser. There is no account, no server that holds your notes, and no analytics. We never receive what you write.
Only two things leave your device: the optional Google Drive backup, which you switch on yourself, and the ordinary request logs every web host keeps.
1. Who we are
Heldnote is operated by Ömer Faruk Bayrak, operating as OFCode.
For the processing described in sections 4 and 5, we are the controller under the GDPR and the veri sorumlusu under Law No. 6698 (KVKK).
2. What we do not collect
- No account, sign-up, email address or profile.
- No analytics, telemetry, tracking pixels, advertising or fingerprinting.
- No cookies.
- No third-party requests while you use the app — the typeface is served from heldnote.app itself.
- We do not receive, read, store or transmit the contents of your notes. There is no server that could.
3. What is stored on your device
Everything Heldnote keeps is held by your own browser, on your own device. It is not transmitted to us and we have no means of reading it.
IndexedDB — database heldnote, with four object stores: notes (your note contents), drafts (unsaved text), versions (the full version history), meta (application bookkeeping).
localStorage — nine small preference and status values:
- heldnote-language — your chosen interface language
- heldnote-theme — light or dark appearance
- heldnote-editor-font — serif or monospace writing face
- heldnote-wrap — whether lines wrap
- heldnote-zoom — your text size
- heldnote-drive-connected — whether Drive backup is connected
- heldnote-drive-last-backup — when the last backup ran
- heldnote-drive-last-error — the last backup error, so it can be shown to you
- heldnote-drive-token — your Google access token, if connected (see section 5)
You can erase all of it at any time by clearing site data for heldnote.app in your browser settings, or by deleting notes inside the app. We cannot do it on your behalf, because we never held it.
4. Hosting
heldnote.app is hosted on GitHub Pages, provided by GitHub, Inc. As with any web host, GitHub receives and logs ordinary request data when you load the site — including your IP address, the time of the request and your browser's user agent.
We have no access to those logs and make no use of them. GitHub processes them for security and operational purposes under its own privacy statement. We mention it because "no third-party requests" is true of the page but not of the act of loading it, and the difference matters.
5. Google Drive backup (optional)
This feature is off until you turn it on. If you connect it:
- Google's sign-in flow grants Heldnote one scope:
https://www.googleapis.com/auth/drive.appdata. That scope reaches only a hidden, application-specific folder inside your own Google Drive. Heldnote cannot see, list or open any other file in your Drive. - Heldnote writes a single file,
heldnote-backup.json, containing your notes and version history, into that folder. The transfer runs directly between your browser and Google. It does not pass through any server of ours, because we do not have one. - The access token Google returns is stored in your browser's localStorage under
heldnote-drive-token, so the connection survives a page reload. Any script running on heldnote.app could read it. Heldnote loads no third-party scripts, but we would rather state this plainly than leave it unsaid.
You can disconnect at any time inside the app, and revoke Heldnote's access entirely at myaccount.google.com/permissions. The backup file is yours; delete it from your Drive whenever you like.
6. Google API Services Limited Use
Heldnote's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies
Heldnote sets no cookies. There is no consent banner because there is nothing to consent to.
8. Children
Heldnote is not directed at children, and collects no personal data from anyone regardless of age.
9. Retention
We hold no personal data, so we have nothing to retain or erase. Data on your device remains until you remove it. A Drive backup remains until you delete it. GitHub's request logs are retained under GitHub's own policy, not ours.
10. Your rights in the EU, EEA and UK
Under the GDPR you have rights of access, rectification, erasure, restriction, objection and portability. In practice we hold nothing to which those rights could attach: your notes are on your device, exportable from within the app and deletable by clearing site data.
If you believe we hold personal data about you, write to privacy@heldnote.app and we will answer. You may also lodge a complaint with your national supervisory authority.
11. Your rights under KVKK
Under article 11 of Law No. 6698 you may learn whether your personal data is processed, request information about it, request correction or erasure, and object to results produced solely by automated analysis. As above, the processing described here does not put your notes in our hands at any point.
Applications may be sent to privacy@heldnote.app or to the postal address in section 1. You may also complain to the Kişisel Verileri Koruma Kurulu.
12. International transfers
We transfer nothing, because we receive nothing. Loading the site involves GitHub's global infrastructure; using the optional backup involves Google's. Both operate internationally under their own safeguards and their own policies.
13. Changes to this policy
If this policy changes, the date at the top changes with it. Anything material will be described on this page rather than slipped in.
14. Contact
Data protection: privacy@heldnote.app
Everything else: contact@heldnote.app
Ömer Faruk Bayrak (OFCode), Konyaaltı / Antalya / TR 07070