Legal
Privacy Policy
Last updated 17 August 2026
ForkLeaf is a Markdown editor that stores your notes in a GitHub repository you own. That design decides most of this policy: there is no ForkLeaf database holding your writing, so most of the questions a privacy policy usually has to answer do not arise.
1. Who this covers
This policy applies to the hosted ForkLeaf service. ForkLeaf is open source under Apache-2.0, and anyone may run their own instance — a self-hosted copy is operated by whoever deployed it, not by us, and this policy does not govern it. A self-hosted instance with no Firebase configuration collects nothing described in section 3.
2. Your notes
Notes are stored in exactly two places, and neither is a server we run:
| Location | What is stored | Controlled by |
|---|---|---|
| Your browser | Notes you have opened, plus the queue of changes not yet pushed, in IndexedDB | You. Clearing site data deletes it. |
| Your GitHub repository | Notes as .md files, with their full commit history | You, under GitHub's own terms and privacy policy |
Note content passes through our servers in memory when it is being relayed to the GitHub API, in order to attach your access token server-side. It is not written to disk, not logged and not retained.
3. What we do collect
Account information. When you sign in with GitHub we store, in Google Firestore:
- Your GitHub numeric id and username
- Your display name and avatar URL
- When your account was created and when it was last active
That is the whole record. It exists so a subscription has something to attach to and so the app can show which account you are signed in as.
Usage analytics. Through Google Firebase Analytics we record which screens are opened and which features are used — for example that a note was created, a diagram was inserted, or an export was run. These events contain no note content, note titles, filenames or repository names.
Session data. Your GitHub access token and public profile, encrypted into an httpOnly cookie that only our server can decrypt. It expires after 30 days. It is never readable by JavaScript in your browser and never appears in a URL.
Server logs. Our hosting provider keeps standard HTTP request logs — IP address, user agent, path, timestamp — for operational and security purposes.
4. What we do not collect
- The content of your notes
- The names of your notes, folders or repositories
- Your GitHub password — we never see it; authentication happens on github.com
- Payment card details — no payment provider is currently connected at all
- Location data beyond what an IP address implies
- Anything from advertising networks, data brokers or session-replay tools
5. Cookies
ForkLeaf sets two cookies, both strictly necessary:
| Cookie | Purpose | Lifetime |
|---|---|---|
forkleaf_session | Your encrypted sign-in session | 30 days, or until you sign out |
forkleaf_oauth_state | Cross-site request forgery protection during sign-in | 10 minutes, deleted as soon as it is used |
Firebase Analytics may set its own identifiers in browser storage. It is not used for advertising, and blocking it does not affect the app.
Preferences such as your theme choice are kept in localStorage on your device and are never sent to us.
6. Who else is involved
| Provider | Role | What they receive |
|---|---|---|
| GitHub, Inc. | Hosts your notes repository and authenticates you | Everything in your repository — it is your repository on their platform |
| Google (Firebase) | Product analytics and the account record | Anonymous usage events and the account record in section 3 |
| Our hosting provider | Serves the application | Standard HTTP request logs |
We do not sell personal information, and we do not share it with anyone beyond the processors above.
7. Why we are allowed to process it
For users in the UK, EEA and other jurisdictions with equivalent law, our lawful bases are:
- Contract — session data and the account record are necessary to provide a service you asked for.
- Legitimate interests — anonymous analytics and server logs, to keep the service working and to understand which features matter. You can block both without losing functionality.
8. How long we keep it
- Session cookie: 30 days, or until you sign out.
- Account record: until you ask us to delete it.
- Analytics events: according to the retention window configured in Firebase, currently 14 months.
- Server logs: according to our hosting provider’s retention policy, typically 30 days.
- Your notes: we do not hold them, so there is nothing for us to retain or delete. They persist for as long as you keep the repository.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, export or restrict processing of your personal data, and to object to it. To exercise any of these, email praneeth2006.dev@gmail.com.
You can also do most of it yourself, immediately:
- Notes on GitHub — delete the repository in your GitHub settings. It is your data in your account; we cannot delete it for you.
- Notes in your browser — clear site data for this domain.
- Your session — sign out, then revoke ForkLeaf at GitHub → Settings → Applications → Authorized OAuth Apps.
- Your account record — email us and it will be deleted within 30 days.
10. International transfers
GitHub and Google both operate globally and may process data outside your country, including in the United States, under their own standard contractual clauses and transfer mechanisms.
11. Children
ForkLeaf is not directed at children under 13, and we do not knowingly collect their personal information. GitHub requires account holders to be at least 13.
12. Changes to this policy
If this policy changes materially, the date at the top of the page changes and a notice appears in the app. The history of every revision is public in the git repository, so you can diff it.
13. Contact
Privacy questions, data requests and complaints: praneeth2006.dev@gmail.com. For security vulnerabilities, please follow the disclosure process in SECURITY.md instead of filing a public issue.
The engineering-level account of the same material, with the exact document shapes, is in the documentation.