Privacy Policy

Last updated: 17 July 2026

This policy explains what personal data To Self collects, why, and what rights you have over it.

Who is responsible for your data

To Self is the data controller for the personal data described in this policy. You can reach us at [email protected]. A postal address is available on request.

What we collect, why, and our lawful basis

Email address Collected when you create an account. Used only for authentication and account-related emails (confirmation, password reset, email change). Lawful basis: performance of our contract with you.

Your content The text of your notes and the names of your notebooks, folders, and file attachments are encrypted on your device before being uploaded, using a key protected by your password. We store them only in encrypted form and cannot read them. Some related information is kept unencrypted on our servers so that sync can work — see “What we can and can’t see” below. The local database on your device (notes, notebooks, folders, files, and link preview metadata) is also encrypted at rest using a key derived from your master key, so that metadata such as timestamps and folder structure cannot be read from the device’s filesystem by other processes. The contents of your file attachments, including any video thumbnails generated from them, are likewise stored encrypted on your device, so neither the attachment files nor their thumbnails can be read by other processes or by anyone with direct access to device storage. To play a video, the app temporarily decrypts it on your device for playback; this decrypted copy never leaves your device and is deleted when playback ends. Lawful basis: performance of our contract with you.

Feedback messages (optional) Signed-in users can submit feedback via the in-app form. The submission is forwarded to our private issue tracker without any account identifiers — the issue contains only the text you typed and, optionally, an email address you choose to share. If you are not signed in, the feedback option opens a pre-filled email to [email protected] in your mail client; any message you choose to send is routed to us by Cloudflare Email Routing and stored in our mailbox, which is hosted by Proton. Lawful basis: our legitimate interest in improving the service.

Usage counters We store aggregate counts of your notes, notebooks, and total file storage used, solely to enforce free tier limits. We do not track how you use the app. Lawful basis: our legitimate interest in operating the service within its limits.

Device and subscription status Each device you sign in on is registered with a device identifier, platform (e.g. iOS, Android), an optional name, and timestamps for when it was first seen and last active, so that sync and free tier device limits can work. We also store your account’s subscription tier (free, trial, or pro), trial start/end dates, and which device is currently designated for sync on the free tier. This identifies devices and enforces tier limits — it is not used to track how you use the app. Lawful basis: performance of our contract with you (enforcing tier and device limits) and our legitimate interest in preventing abuse of trial offers.

Connection data Our authentication provider processes your IP address and device/browser information to keep accounts secure and prevent abuse. Lawful basis: our legitimate interest in security.

We do not use analytics services, crash reporting tools, or any other third-party tracking.

Where your data is stored and who processes it

Your account and content are stored by Supabase in their West EU (London) region, within the UK. The text of your notes and the names of your notebooks, folders, and files are encrypted on your device before they are uploaded, so Supabase receives those in encrypted form only. Outbound account emails are sent through Resend. Our website is hosted by Cloudflare, which also routes inbound email you send us to a mailbox hosted by Proton.

ProcessorPurposeLocationPolicy
Supabase Inc.Authentication and encrypted cloud syncUK (London)supabase.com/privacy
Resend (Resend Inc.)Sending account and authentication emailsUSAresend.com/legal/privacy-policy
GitHub (Microsoft)Storing in-app feedback submissions (no account identifiers in the issue)USAdocs.github.com/en/site-policy/privacy-policies
Cloudflare, Inc.Website hosting and inbound email routingUSAcloudflare.com/privacypolicy
Proton AGStoring inbound email sent to us (e.g. feedback from signed-out users)Switzerlandproton.me/legal/privacy

What we can and can’t see

We cannot read the content of your notes, and we cannot see the names you give your notebooks, folders, or files. These are encrypted on your device with a key that is unlocked by your password, and we store only the encrypted form together with an encrypted copy of that key. If you set up a recovery phrase, we also store a second encrypted copy of your key protected by that phrase; we cannot read either copy.

To provide sync and enforce free tier limits, some information is stored without encryption:

  • when each item was created, last updated, and (if applicable) deleted;
  • how your notes, notebooks, and folders are arranged in relation to one another;
  • the size and type of each file attachment;
  • the usage counts described above;
  • the device and subscription status information described above.

This information is linked to your account but does not reveal the contents, titles, or filenames of what you store.

International transfers

Your account data and content are stored in the UK. When we send you an account email, your email address is processed by Resend in the United States. When you submit in-app feedback as a signed-in user, your message is processed by GitHub (Microsoft) in the United States. Inbound email you send us is routed by Cloudflare in the United States and delivered to a mailbox hosted by Proton in Switzerland. Transfers to the United States (Resend, GitHub, Cloudflare) are protected by standard contractual clauses (the UK International Data Transfer Addendum) under each processor’s data processing terms. Switzerland is covered by the UK’s data protection adequacy regulations, so no additional safeguards are required for transfers to Proton.

How long we keep your data

We keep your data for as long as your account is active. Notes, notebooks, folders, and files stored locally on your device are retained encrypted on the device after you sign out; they become accessible again when you sign back in with the same account. If a different account signs in on the same device, the previous account’s locally-stored data is permanently deleted from the device. You can delete your account at any time from the Settings page in the app. When you do, your notes, files, and all associated data are deleted from our servers immediately. Feedback you submitted via the in-app form is stored as issues on GitHub; those issues are not linked to your account and are not deleted when your account is closed. Emails you send to [email protected] (including feedback) are kept only as long as needed to deal with your message, then deleted. If you no longer have access to the app, you can request deletion by emailing [email protected] from your registered address — see the account deletion page for details; we will process the request within 30 days. Some backups may persist for up to 60 days before being fully purged.

Your rights

Under UK data protection law you have the right to access, correct, delete, restrict, or object to our use of your personal data, and to receive a copy of it in a portable format. You can delete your account directly from the Settings page in the app; if you no longer have access to the app, you can also request deletion by email. To exercise any other rights, email [email protected].

If you have a concern about how we handle your data, please contact us first so we can try to put it right. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

Cookies and local storage

The app stores a session token and your email address on your device to keep you signed in and to let you sign back in if your session expires. This is essential to the service and is not used for tracking or advertising.

Children

You must be at least 13 years old to use To Self.

Changes to this policy

We may update this policy from time to time. We will update the “Last updated” date at the top of this page when we do.

Contact

For any questions about your data or to make a privacy request, email [email protected]. A postal address is available on request.