Privacy policy
Last updated: 17 September 2026
Marknote is designed to keep your notes on your own devices. This policy explains what the app, the website, the support desk and the optional Marknote Sync service do and do not handle, what we store when you use them, why, for how long, and what you can do about it.
Who we are
Marknote is published by Marknote Limited, a company registered in England and Wales with company number 17460221. Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
We are the controller of the personal data described in this policy, registered with the Information Commissioner's Office under registration number ZC250231. For anything about it, write to dpo@marknote.md.
The short version
- The desktop app collects nothing and sends nothing about you unless you use a feature that needs the network, and each of those is listed below.
- If you use Marknote Sync, your notes are encrypted on your device with a passphrase only you hold. We store and relay that ciphertext. We cannot read it, and neither can anyone who takes it from us.
- We keep the account details, sign-in records and sync bookkeeping needed to run the service, for the periods listed below, and nothing for advertising.
- You can see, change, export and delete your account yourself from the account pages.
- This website asks before using Microsoft Clarity, and loads nothing from it until you say yes.
What the app does not do
- It does not collect, transmit or analyse your notes or your usage automatically.
- It has no analytics and no automatic crash reporting, and no telemetry unless you use Marknote Sync, which reports only the counts described under Marknote Sync below.
- It embeds no third-party trackers, ad networks or analytics SDKs.
- It does not need an account. Sync is optional and off until you sign in.
Network requests the app makes
Marknote works offline. These are the only times it talks to the network, and what each request carries:
- Feature flags — at launch, about every five minutes while it runs, and when its window comes back to the front, the app asks our sync service which features are switched on. The request carries no identifier and nothing about you or your notes; the answer is kept in your settings file so the app is stable offline.
- When you are signed in to Marknote Sync — the app also refreshes your account summary (plan and storage) on the same schedule, and syncs as described under Marknote Sync below.
- The theme marketplace — opening Settings → Themes → Get more themes fetches the listing from marknote.md, and installing a theme downloads its file from marknote.md and checks it against the listing's checksum before anything is written. Nothing about you is sent; it is the same as visiting marknote.md/themes in a browser.
- Local AI — if you use the Ask tab or the AI writing actions, the app sends the text of the notes involved to the Ollama server at the address set in Settings, which is your own computer unless you change it. Nothing about this goes to Marknote. If you point it at another machine, the text of those notes goes there.
- Git — with the remote you configured, using credentials held by your operating system. We do not see those communications.
- Installing Pandoc — if you accept the guided install for Word, EPUB and LaTeX export, the app runs
winget, which downloads Pandoc from Microsoft's package source. - Contact support — only when you send a ticket, as described below.
- The Microsoft Store checks for updates on its own schedule; that is Windows, not Marknote.
What is stored on your computer
The following stays on your computer and is not transmitted to us or to anyone else.
- Application settings —
%LocalAppData%\Marknote\settings.json: theme choices, window size and position, editor preferences, recent files, open tabs, keybinding overrides, journal folder, custom CSS, and the last answer to the feature-flag check. - Workspace configuration —
<your folder>\.marknote.json: pinned files and per-workspace settings. A folder bound to Marknote Sync also carries<your folder>\.marknote\: which vault it belongs to, what has been synced, and a copy of each note as it was last synced (used to merge edits), in plain text like the notes themselves. - Secrets — your sign-in token, your vault key if you chose to remember it on this device, and the keys of notes you have shared, in Windows' protected storage, tied to your Windows account and unreadable if copied elsewhere. Never in settings.json.
- Installed themes and plugins —
%LocalAppData%\Marknote\themes\and\plugins\. - Crash log —
%LocalAppData%\Marknote\crash.log, written only when the app hits an unhandled error, never sent automatically, shown in the crash-recovery dialog, and attached to a support ticket only if you choose to include diagnostics. - Auto-save backups — beside your documents as
*.marknote-backup, removed after a successful save.
Contact support from the app (opt-in)
Help → Contact support (also About → Get help) sends a ticket to Marknote support. Signed in with your Marknote account, the app sends it for you and shows the ticket number; otherwise it opens a pre-filled ticket at support.marknote.md in your browser. Nothing is sent until you press the button, and you see exactly what is attached before you do.
- What is attached when "Include diagnostics" is on — Marknote version, Windows edition, .NET version, your settings-file path, your active folder path, and the end of the crash log if there is one. You can preview it in the dialog, or turn the switch off.
- What is never attached — your notes, their contents, file names other than the active folder path, or your git credentials.
- Who reads it — Marknote support staff. Never put a password or a vault passphrase in a ticket; support cannot read your notes and never asks for either.
Marknote Sync (beta, opt-in)
Marknote Sync is in beta and free while it is. It is off until you create an account, sign in and bind a folder to a vault. A Marknote that never signs in sends nothing to the service.
The principle. Your notes are encrypted on your device with a key protected by a passphrase only you hold, before anything leaves it. So are their names, the vault's name and any images. The service stores and relays ciphertext, keyed digests and sizes. It cannot read your notes and neither can we; if you lose both the passphrase and the recovery key, nobody can recover them, including us.
What we store to run your account
| What | Why | How long |
|---|---|---|
| Your email address, whether it is confirmed, a password hash or your passkeys, and your display name and profile picture if you set them | To sign you in and to send account mail | While the account exists. An account whose address is never confirmed is deleted two days after it was made |
| Your plan, the storage you use, and the dates of a lapsed plan's grace period | To apply the plan's limits and tell you before sync turns read-only | While the account exists |
| When you agreed to the newsletter, if you did | To prove and honour that choice | While the account exists, or until you withdraw |
| A sharing key pair: the public half, so another account can share a vault with you, and the private half locked under your own vault key, which we cannot open | To make vault sharing possible | While the account exists |
| Your devices: a name and platform as the app reports them, the app version, when each was last seen, and its place in the sync history | To sync, to let you see and revoke devices, and to count devices against your plan | While the account exists |
| Browser sessions on the account pages: when each began and was last used, the browser and the IP address | So you can sign a session out from the Security page | Until signed out, or after fourteen days unused |
| A recent-activity list: sign-ins by method, passkey and password changes and session sign-outs, with the IP address and browser | So you can spot a sign-in that was not you | 90 days |
| What our mail provider said about each account mail we sent you: the address, the subject, when, and whether it was delivered. Never the message itself | To answer "I never got the email" | 90 days, including after the account is deleted |
| Security and support records: what was done to the account, by whom and why, notes our support staff add, when staff opened the account's details, and the IP address | To keep the service secure and account for every action taken on an account | 12 months, including after the account is deleted |
| Support tickets: what you write at support.marknote.md or from the app, the files you attach, and our replies. Tickets are not encrypted like your notes; support staff read them | To answer you, and so you can read the answer | While the account exists; deleted with it |
Checks when you sign up or reset a password. Creating an account, asking for a password reset and asking for a new confirmation link run Cloudflare Turnstile, so that automated sign-ups cannot use the service to send mail to other people. It usually finishes without you doing anything. Cloudflare sees your IP address and signals from your browser to tell a person from a bot, and sets no advertising or tracking cookies. When you choose a password, the service checks it against Have I Been Pwned's list of passwords exposed in data breaches. Only the first five characters of a one-way hash of the password are sent; the password never leaves our server, and the check cannot tell which password it was.
What we store to sync your notes. For each vault: an identifier, the encrypted name, the encrypted keys (which only your passphrase or recovery key can open), running totals of documents and bytes, and which generation of key it is under. For each document: an identifier, the encrypted path, the encrypted content, keyed digests that let devices tell what changed, its size rounded up so the exact length is hidden, timestamps, and which device wrote it last. None of this reveals a note's name or contents. A deleted note stays as a marker for 90 days so your other devices learn of the deletion; a deleted vault is removed from our servers 90 days after you delete it.
Health counters. When it syncs, the app reports how many edits it merged, how many conflict copies it made, how many wrong passphrase or recovery-key attempts and how many decryption failures it met, as counts. No content and no names.
Sharing a note by link. When you share a note, the app makes a copy of it and its images, encrypts the copy under a new key, and uploads the ciphertext. The key travels in the link after the #, which browsers never send to any server, so only someone with the link can read the note — not us. We store the ciphertext, its size, when it was made and last updated, an expiry and a password salt if you set them, and a name for the link that you choose, which is stored unencrypted (the app tells you so when it asks). We count how many times a link was opened and when it was last opened; we do not record who opened it. Stopping a share, or reaching its expiry, deletes the encrypted copy, and the record of the link is removed seven days later. A link also stops at once if the vault it came from is removed from sync, or if the person who made it is removed from a shared vault.
Sharing a vault with another account. Inviting someone looks up their sharing public key by their email address (only for a confirmed account that has one) and stores, with the vault, that their account has access, their role, and the vault key locked to their key, which we cannot open. Their edits count against the vault owner's storage. Removing them ends their access; rotating the vault key afterwards re-encrypts the vault so the old key is useless.
What our support staff can see. Our support tools show account details, plan, device names, vault identifiers and counts, share identifiers and the names you gave them, the activity list, support tickets and the records of actions taken on the account. They cannot show notes, note names, vault names, keys or passphrases, because we do not have the keys. Every action staff take on an account is recorded with a reason, and so is every time staff open an account's details.
Where. The service runs on Microsoft Azure in the UK South region, with its database in Germany West Central (our separate test environment's database is in France Central). Both are in the European Union, which UK law recognises as protecting personal data adequately. We will move the database to the UK when Microsoft makes that possible for us, and this paragraph will change when we do. Account mail is sent through Azure Communication Services, the website and the support desk run on Azure App Service, and our support mailbox runs on Microsoft 365. Microsoft's privacy statement covers those services, which it provides to us as our processor.
Leaving. Security → Delete account on the account pages removes, at once, the account, its vaults and every note on our servers, its share links, devices, browser sessions, recent-activity list and support tickets. The mail and security records in the table above are kept for the period shown. If you ask us to delete your account instead, we disable it straight away and delete it seven days later; you can change your mind in that week. Notes on your own devices are ordinary files and are not touched either way.
Website analytics (Microsoft Clarity, opt-in)
This website, marknote.md, and the Marknote Sync account pages at account.marknote.md can use Microsoft Clarity to understand how their pages are used: which pages people read, where they scroll, what they click. It runs only after you choose Allow on the bar shown on your first visit to each; the choice is kept per site, so the account pages ask once too. Until then, and if you choose No thanks, nothing from Clarity is loaded. A browser that sends the Global Privacy Control signal is treated as having declined and is not asked.
- What Clarity records — page views, clicks, scrolling and mouse movement, replayed as anonymised session recordings and heatmaps, together with your browser, device type, screen size, country and the referring page. Microsoft processes this under its privacy statement.
- What it never records — text you type. Form fields are masked, and the playground editor is masked explicitly. On the account pages the whole page is masked, so a recording there holds the layout and where you clicked, never your details.
- Cookies — two, set by Clarity when you allow it:
_clck, which keeps a user id for up to a year, and_clsk, which links the page views of one visit for a day. Your choice itself is kept in your browser's local storage, not a cookie. - Why — to see where the site is unclear and improve it.
- Where it doesn't run — never in the app, and never in the sync service itself: nothing about your notes, vaults or devices passes through Clarity.
- Changing your mind — , or use Withdraw consent on the Profile page of your account, and the bar asks again. Clearing the site's data in your browser does the same.
The share viewer
A shared note opens at share.marknote.me, a page that decrypts the note in your browser with the key from the link. The page loads only its own files and the ciphertext from our service. We count the view; we do not record who you are. Requests are rate-limited by address, and those counters expire within minutes.
Why we use your data
UK data protection law asks us to say which lawful basis each use rests on:
- To provide what you asked for (contract) — your account, sync, sharing, account mail and support tickets.
- Your consent — the newsletter and website analytics. You can withdraw it at any time, and withdrawing does not affect what was done before.
- Our legitimate interests — keeping the service and your account secure and working: the sign-up and password checks, the recent-activity list, the mail and security records, rate limits and the health counters. We have weighed these against your interests and keep them to what the purpose needs.
We do not sell personal data, use it for advertising, or make decisions about you by automated means alone.
Third-party components
The app renders its preview with Microsoft Edge WebView2, a Windows component covered by the Microsoft Privacy Statement. KaTeX, Mermaid and highlight.js are bundled with the app and loaded from disk; they make no network requests.
Plugins
Plugins are JavaScript written by third parties, installed by you to %LocalAppData%\Marknote\plugins\, and run in a sandboxed embedded browser. A malicious plugin could still misuse what Marknote exposes to it. Install plugins only from sources you trust; their authors are responsible for how they handle data, and we do not audit plugin code.
Themes and the theme marketplace
A theme is a single file of colours with an optional stylesheet — no code. Installing one fetches it from marknote.md and checks it against the listing's checksum; the stylesheet is checked so that it cannot fetch or run anything, and a theme that tries is refused. An Install in Marknote link opens the app, which downloads and checks the theme and asks you before installing it.
File system access
Marknote reads and writes only files you choose through the standard file pickers, drag and drop, or by opening a folder as a workspace. It does not scan or index files outside folders you have opened.
Your rights
Under UK data protection law you can ask for a copy of the personal data we hold about you, have it corrected, have it erased, receive it in a portable form, restrict or object to how we use it, and withdraw a consent at any time. For a Marknote Sync account you can do most of this yourself: the account pages show what we hold; Profile changes your details; Security → Export downloads a copy of your account data and your encrypted notes (the readable copy of your notes is the files on your own device); Security → Delete account erases it. If you cannot sign in, we can instead email a download link for the same export to your account's confirmed address; the link works for seven days, and the file is deleted from our servers after that. For anything else, or if you have no account, write to privacy@marknote.md; we answer within a month.
If you are unhappy with how we have handled your data, please tell us first. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Children's privacy
Marknote Sync accounts are for people aged 13 or over, and we do not knowingly collect personal information from anyone under 13.
Contacting us
For questions about this policy: dpo@marknote.md
Marknote Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Company number 17460221. ICO registration ZC250231.
Changes
We may update this policy from time to time. The "Last updated" date at the top shows the current version. Material changes are noted in the app's release notes and the website's changelog, and account holders are told by email when a change affects the service.