Your data
A plain inventory of what ForkLeaf holds about you, where each piece lives, and how to get rid of it. The formal version is the privacy policy; this is the engineering account.
Your notes
| Where | What | Who can read it |
|---|---|---|
| Your browser (IndexedDB) | Every note in every workspace you have opened, plus the pending-change queue | You, on that device |
| Your GitHub repository | Notes as .md files, with full commit history | Whoever you have granted access to that repository |
| ForkLeaf servers | Nothing. Note content passes through the API proxy in memory and is not written down. | — |
There is no notes table. This is not a policy commitment that could be revised — it is the architecture. See How ForkLeaf works.
Your session
The session cookie
Contains your GitHub access token, the refresh token that renews it, and your public profile — id, login, name, avatar URL — encrypted with JWE (A256GCM). httpOnly, SameSite=Lax, Secure in production, 30-day expiry. Only the server can decrypt it. The refresh token is there because a GitHub App’s access token expires after eight hours; it is spent server-side to get a new one, and never reaches the browser either.
The OAuth state cookie
A random value that lives for ten minutes during sign-in and is deleted the moment it is used.
Analytics and account records
The hosted deployment uses Firebase for product analytics and for a thin account record. A self-hosted copy with no Firebase configuration collects none of this and works identically.
Analytics
Firebase Analytics records which screens are opened and which features are used — note created, diagram inserted, note exported, repository connected. Events carry no note content, no filenames, no repository names and no note text.
It degrades to nothing when unavailable: private browsing, a blocked script or a missing IndexedDB all result in analytics simply not running, and the app does not care.
The user record
One Firestore document, at users/{uid}:
{
"githubId": 12345678,
"githubLogin": "you",
"displayName": "Your Name",
"avatarUrl": "https://avatars.githubusercontent.com/u/12345678",
"createdAt": "2026-08-14T09:12:00Z",
"lastSeenAt": "2026-08-17T16:40:00Z"
}That is the entire record. It exists so a subscription has something to attach to. The uid is an anonymous Firebase identity created automatically — you are never asked to sign in to Firebase, and it is not your GitHub login.
Who else is involved
| Party | Role | What they see |
|---|---|---|
| GitHub | Stores your notes | Everything in the repository — it is their repository hosting |
| Google (Firebase) | Analytics, user record, billing state | Anonymous usage events and the small profile above |
| The host | Serves the app | Standard HTTP request logs: IP, user agent, path |
No advertising networks, no data brokers, no session-replay tooling, no third-party trackers.
Deleting everything
- Notes on GitHub: delete the repository from your GitHub settings. That is your data in your account — ForkLeaf cannot and does not delete it for you.
- Notes in this browser: clear site data for this domain, which drops the IndexedDB database.
- Your session: sign out, then revoke the app at GitHub → Applications (the hosted ForkLeaf is registered as a GitHub App, so it is under Authorized GitHub Apps).
- Your Firebase record: email the address in the privacy policy and it will be deleted.