Your data

A plain inventory of what ForkLeaf holds about you, where each piece lives, and how to get rid of it. The formal version is the privacy policy; this is the engineering account.

Your notes

WhereWhatWho can read it
Your browser (IndexedDB)Every note in every workspace you have opened, plus the pending-change queueYou, on that device
Your GitHub repositoryNotes as .md files, with full commit historyWhoever you have granted access to that repository
ForkLeaf serversNothing. Note content passes through the API proxy in memory and is not written down.—

There is no notes table. This is not a policy commitment that could be revised — it is the architecture. See How ForkLeaf works.

Your session

The session cookie

Contains your GitHub access token, the refresh token that renews it, and your public profile — id, login, name, avatar URL — encrypted with JWE (A256GCM). httpOnly, SameSite=Lax, Secure in production, 30-day expiry. Only the server can decrypt it. The refresh token is there because a GitHub App’s access token expires after eight hours; it is spent server-side to get a new one, and never reaches the browser either.

The OAuth state cookie

A random value that lives for ten minutes during sign-in and is deleted the moment it is used.

Analytics and account records

The hosted deployment uses Firebase for product analytics and for a thin account record. A self-hosted copy with no Firebase configuration collects none of this and works identically.

Analytics

Firebase Analytics records which screens are opened and which features are used — note created, diagram inserted, note exported, repository connected. Events carry no note content, no filenames, no repository names and no note text.

It degrades to nothing when unavailable: private browsing, a blocked script or a missing IndexedDB all result in analytics simply not running, and the app does not care.

The user record

One Firestore document, at users/{uid}:

users/abc123
{
  "githubId": 12345678,
  "githubLogin": "you",
  "displayName": "Your Name",
  "avatarUrl": "https://avatars.githubusercontent.com/u/12345678",
  "createdAt": "2026-08-14T09:12:00Z",
  "lastSeenAt": "2026-08-17T16:40:00Z"
}

That is the entire record. It exists so a subscription has something to attach to. The uid is an anonymous Firebase identity created automatically — you are never asked to sign in to Firebase, and it is not your GitHub login.

Who else is involved

PartyRoleWhat they see
GitHubStores your notesEverything in the repository — it is their repository hosting
Google (Firebase)Analytics, user record, billing stateAnonymous usage events and the small profile above
The hostServes the appStandard HTTP request logs: IP, user agent, path

No advertising networks, no data brokers, no session-replay tooling, no third-party trackers.

Deleting everything

  1. Notes on GitHub: delete the repository from your GitHub settings. That is your data in your account — ForkLeaf cannot and does not delete it for you.
  2. Notes in this browser: clear site data for this domain, which drops the IndexedDB database.
  3. Your session: sign out, then revoke the app at GitHub → Applications (the hosted ForkLeaf is registered as a GitHub App, so it is under Authorized GitHub Apps).
  4. Your Firebase record: email the address in the privacy policy and it will be deleted.
Step 1 first. Deleting the browser copy of an unsynced local-workspace note is irreversible — there is no other copy of it anywhere.