Effective: October 2, 2026
Who we are: Tim Jensen, 224 Marie Drive, Holmen, WI 54636
Contact: Support@MarketingToolsCenter.com
The short version
- Your notes are yours. You can export all of them at any time, and delete your account yourself.
- We do not use analytics, tracking pixels, or advertising in the service.
- We do not sell or share your data, and your notes are not used to train AI models.
- Your notes are encrypted in storage and in transit, but not end-to-end encrypted. That means we could technically read them. We don't, and we would rather say so plainly than let you assume otherwise.
The rest of this page is the detail behind those four points.
What we collect
Your account. Your email address, and a display name if you give one. Passwords are stored only as hashes — we never see or store the password itself.
Your content. The notes you write or import, their titles, bodies and tags, the categories you create, any attachments, and the original files you upload during an import. We keep the originals so you can get them back unchanged.
Where your notes came from. For imported notes we record the source app and import batch, so you can later search by where a note came from and see which import it arrived in.
Billing. If you are on a paid plan we store your customer and subscription identifiers from our payment processor, and which plan you are on. If we refund a payment, we record the refund: the charge it was for and the amount. We never see or store your card details — those go directly to Stripe and stay there.
Your own AI key, if you add one. We store it encrypted, show you only its last four characters, and use it only for your own account's AI requests.
Usage and security records. How much storage you are using, records of AI operations run on your account and, for AI run on our key, what it has cost this month against your monthly allowance, and an audit log of significant actions such as sign-ins, exports, deletions and permission changes. We also keep a hashed device fingerprint so we can alert you when your account is accessed from a device we have not seen before, and the approximate place (country, region, city) a sign-in came from. We never store your IP address.
Two-step sign-in, if you turn it on. If you turn on two-step sign-in, we keep what it needs: your authenticator app's secret key, your security keys' public keys and the names you give them, your recovery codes (scrambled, so they can't be read back), and a recovery phrase if you set one. If someone enters your correct password but then fails the second step, each failed attempt is recorded in the audit log. After five of them within 24 hours we email you about it, at most once a day, so you can change your password.
Account settings. Your display name and, if you set them, a site name, logo, favicon, accent color, custom domain and payment-processor account identifier.
What we do not collect
There is no analytics, no tracking, no advertising, and no third-party tracker of any kind in this service. We do not analyze the content of your notes for any purpose other than performing the operation you asked for.
Why we hold it
| What | Why |
|---|---|
| Email and password hash | To create your account and sign you in |
| Your notes and files | To provide the service you are paying for |
| Billing identifiers | To take payment and manage your subscription |
| Audit log and device records | To keep your account secure |
| Storage and AI usage counts | To apply plan limits fairly |
We are based in the United States, at the address above. Nothing in this service stops you signing up from anywhere else, and we have not tried to exclude anyone.
If you are in the UK or the EU, the law there requires us to name a legal basis for each thing we hold. Ours are:
| What | Legal basis |
|---|---|
| Email and password hash | Contract — you cannot have an account without them |
| Your notes and files | Contract — holding them is the service you asked for |
| Billing identifiers | Contract — we cannot take a payment or manage a subscription without them |
| Storage and AI usage counts | Contract — they exist only to apply the plan limits you agreed to |
| Audit log and device records | Legitimate interest — see the next paragraph |
The last row is the one that is not contract, so here is the reasoning rather than just the label. Security records are not strictly necessary to store notes, so we do not pretend they are part of the deal. They exist to keep your account secure and to alert you if your account is accessed from a device we have not seen before. They are the least that achieves this: we record that an action happened and who did it, never the content it touched.
You have a right to object to anything held on that basis. We would rather be straight with you about how that would go: we are unlikely to be able to switch off security logging for one account while that account is still open, and we would sooner say so here than promise something we would then refuse.
This is our own assessment, not a lawyer's. It was written from what the code actually does, and every factual claim on this page can be checked against it. The reasoning is a starting position by people who are not qualified to give a final one. If you think a basis here is wrong, write to Support@MarketingToolsCenter.com and we will look at it properly rather than defend it.
Who else touches your data
We use a small number of service providers. Each one only receives what it needs.
| Provider | What it does | What it sees |
|---|---|---|
| Convex | Database, file storage, authentication | Your account and all your content |
| Vercel | Hosting the application | Requests to the site |
| Stripe | Payments | Your payment details, name and email — we never see the card |
| Resend | Transactional email such as password resets and new-device alerts | Your email address and the message |
| OpenRouter | Routes AI requests to model providers | The note text involved in the operation you requested |
| Vimeo | Hosting training videos | Video playback requests |
| Have I Been Pwned | Checks passwords when you set one, and at most once a week when you sign in, against known breaches — only the first five characters of a hash ever leave our servers | Nothing identifying — see below |
On password breach checking. We check whether your password appears in known public breaches when you set a password, and again at most once a week when you sign in. A password found in a breach is never refused at sign-in; you are asked to change it. Your password is never sent anywhere. We hash it locally and send only the first five characters of that hash, receiving back a list of candidates to compare against on our side. The service cannot learn your password or which account it belongs to.
On AI. Note text is sent to model providers only when you run an operation that needs it — categorizing, suggesting tags, or drafting a merge. Requests are routed only to providers operating under no-training terms with zero or short retention, so your notes are not used to train anybody's model. Routing is done on our servers; providers do not receive your identity.
AI run on our key is limited to a monthly allowance per account, and we keep a running total of what it has cost this month, plus a short-lived note of each AI step still in progress, so we can apply that allowance. Profile shows you how much of it you have used, as a percentage. Both are deleted with your account. If you add your own OpenRouter key, your AI requests go to OpenRouter under your key instead, OpenRouter bills you for them, and they do not count toward the allowance.
How your data is encrypted
Your data is encrypted in transit using TLS, and at rest in our database.
It is not end-to-end encrypted. We hold the keys, which means an operator with database access could technically read your notes. We do not do this as a matter of routine, access to production is limited, and significant actions are written to an audit log — but we are not going to claim a protection we have not built. If end-to-end encryption is a requirement for you, this service does not currently meet it.
Who can see your notes
Other users cannot. Every read and write is checked against the note's owner on the server. There is no route by which one account reaches another's content.
Account administrators cannot. Administrators can see your email address, display name and account status, and can suspend or remove your account. They cannot read your notes.
Support Access is the one exception, and only you can turn it on. If you need help, you can grant temporary access to your account for a period you choose — 4 hours, 24 hours, 3 days or 7 days. While it is on, a support operator can act in your account to diagnose the problem. You can revoke it at any time, it expires on its own, and both the start and the end of every support session are written to the audit log. It is off unless you switch it on.
How long we keep things
| Data | Retained |
|---|---|
| Your notes and files | Until you delete them, or you delete your account |
| A canceled account | Purged 30 days after cancellation |
| A fully refunded account | Purged 30 days after the refund |
| Export archives | Deleted automatically 24 hours after they are generated |
| Support access grants | Until they expire or you revoke them |
| Audit log entries | Kept indefinitely — see below |
| Records of your payments | Kept by our payment processor for as long as tax and accounting law requires — at least three years — and not deleted with your account |
Records of your payments — who paid, what and when — are kept by our payment processor for as long as tax and accounting law requires, at least three years. They are not deleted with your account.
The audit log is kept longest, and we would rather explain it than bury it. Audit entries have no end date at all: they are append-only, they are never edited or deleted — including by us — and they survive the deletion of the account they describe. A record that can be quietly altered or removed is not evidence of anything, and evidence is the entire reason it exists. It is what lets you, or us, reconstruct what actually happened to an account.
What outlives your deletion is the entry. Most entries hold only an account identifier and the action taken, but some also record an email address, such as the one an account signed up with. We also keep a record of each message our payment processor sends us about a payment, and of each account it asked us to create, including the email address; those are not deleted with your account either.
This corrects an earlier version of this page, which said audit entries were kept for twelve months. That was never true — no such deletion was ever built. We would rather publish the correction than leave a tidier number standing.
Your rights
Get your data out. You can export everything at any time from your account: your notes as both Markdown and JSON, your categories, and every original file you imported, delivered as a single zip. Nothing is held back and no export fee applies.
Delete your account. You can do this yourself. It requires your current password, and it takes effect immediately — your content is purged and every active session is ended. It is not reversible. Records of your payments — who paid, what and when — are kept by our payment processor for as long as tax and accounting law requires, at least three years. They are not deleted with your account.
Correct your data. You can edit your notes and your display name in the service. Your sign-in email address cannot be changed.
Depending on where you live you may also have rights to object to or restrict processing, or to complain to a data protection regulator. To exercise any right, or to ask what we hold about you, contact Support@MarketingToolsCenter.com.
Children
This service is not intended for children. You must be at least 16 years old to use it.
Changes
If this policy changes materially we will say so in the service or by email before the change takes effect.