What we store, and where
Your account (your email address, or Apple's relay address if you use Hide My Email), your notes, folders, files and earlier versions of each note, your profile name and photo if you set them, and the AI apps you've connected. It's all stored at Supabase, our host, in Frankfurt, Germany.
The website and shared note pages run on Vercel, and are built in Frankfurt too. Vercel passes requests on to our server and sees a shared note while it shows the page, but it doesn't store your notes.
What's encrypted
- On the way: everything between the apps, the website and our server travels over HTTPS.
- Where it's stored: Supabase encrypts the database and files on its disks (AES-256).
- Locked notes, end to end: a locked note's text is encrypted on your device with a key made from your notes password, before it's uploaded. We never get the password or the key. Its title stays readable so your list can show it. If you forget the password, nobody can recover the note.
- Passwords and access tokens are stored only as one-way hashes.
Notes that aren't locked are not end-to-end encrypted yet. Our server has to read them to sync them, search them and hand them to the AI apps you approve.
Who can see what
- You, on every device you sign in on.
- Us. As the people running the database (that's Emil, who makes Amber Notes), we could technically read notes that aren't locked. We use them only to store, sync and show them to you. Supabase could too, under its contract with us.
- AI apps you approve, for the notes they ask for. They never see the text of locked notes, only their titles.
- Anyone with the link to a note you share, until you stop sharing it. Shared pages are hidden from search engines.
No ads, no tracking
There are no ads, and there never will be. The apps and this website have no tracking scripts, no third-party analytics and no crash-reporting tools, and the website sets no cookies. We never sell or share your data.
The apps count a few things on our own server, so we can tell whether Amber Notes works for people. Kept for 12 months, never shared:
- How many notes an AI connection changed on each day.
- Which days you used the app, to ask once, after a week, whether you'd like to share it.
- Which tips were shown and whether the feature was then used.
- Which first-run setup steps you've done.
- A random id for each installation and whether it's an iPhone or a Mac, to count devices.
Every log, and how long it's kept
We don't write the text of your notes, email addresses, access tokens or IP addresses into any log of our own. Our hosts log the requests that reach them; we can't turn that off, but they keep it briefly.
| Log | What's in it | Kept |
|---|---|---|
| Supabase request logs | Each request to our server: the time, the address it asked for, the IP address and device type, and a rough location from the IP address. | 1 day |
| Supabase sign-in logs | Each sign-in and sign-out: the time, the email address and the IP address. | 1 day |
| Supabase function and database logs | When each server function ran and what it was asked for, and errors, with names, addresses and ids blanked out. | 1 day |
| Sign-in records in our database | Each sign-in: the time, the email address and the IP address, to keep your account secure. | 30 days |
| Vercel request logs | Each request to this website: the time, the page, the IP address and device type, and whether it worked. | 1 hour |
| Rate limits | A one-way hash of the IP address, made with a key that changes every day, to stop floods of sign-in attempts. | 2 hours |
Our hosting plan keeps no backups of the database, so what you delete is gone.
AI connections
- Nothing reaches an AI app unless you connect one and approve it, in Amber Notes or on this website.
- You choose Read Only or Read and Edit for each one.
- Every change an AI makes keeps the previous version, so you can see what changed and restore it.
- Disconnect any AI app in Settings → Connect an AI. It loses access at once.
- What an AI app reads becomes part of your conversation with it, and the company behind it handles that under its own privacy policy.
Your data, your choice
- Export: Settings → Privacy & Security → Export My Data gives you a zip with every note as Markdown and everything else we keep about you as JSON.
- Delete: Settings → Delete Account deletes your account and everything in it from our server at once: notes, files, versions, AI connections, share links and usage counts.
- Deleted notes stay in Recently Deleted for 30 days, then they're gone for good.
- You can also ask us to correct, restrict or stop using your data, or object to the usage counts. Write to emil@norditech.se; we answer within a month. You can complain to the Swedish Authority for Privacy Protection (IMY).
Open source, so you can check
Everything above is in the code, and the code is on GitHub: the apps, the server and this website. Found a security problem? Write to emil@norditech.se, not a public issue.
The legal details are in the privacy policy.