Legal

Privacy Policy

Last updated 17 August 2026

ForkLeaf is a Markdown editor that stores your notes in a GitHub repository you own. That design decides most of this policy: there is no ForkLeaf database holding your writing, so most of the questions a privacy policy usually has to answer do not arise.

The short version. Your notes are in your browser and in your own GitHub repository. We never store them. We collect anonymous usage events and a small account record. We do not sell anything to anyone, and there are no advertising trackers.

1. Who this covers

This policy applies to the hosted ForkLeaf service. ForkLeaf is open source under Apache-2.0, and anyone may run their own instance — a self-hosted copy is operated by whoever deployed it, not by us, and this policy does not govern it. A self-hosted instance with no Firebase configuration collects nothing described in section 3.

2. Your notes

Notes are stored in exactly two places, and neither is a server we run:

LocationWhat is storedControlled by
Your browserNotes you have opened, plus the queue of changes not yet pushed, in IndexedDBYou. Clearing site data deletes it.
Your GitHub repositoryNotes as .md files, with their full commit historyYou, under GitHub's own terms and privacy policy

Note content passes through our servers in memory when it is being relayed to the GitHub API, in order to attach your access token server-side. It is not written to disk, not logged and not retained.

3. What we do collect

Account information. When you sign in with GitHub we store, in Google Firestore:

  • Your GitHub numeric id and username
  • Your display name and avatar URL
  • When your account was created and when it was last active

That is the whole record. It exists so a subscription has something to attach to and so the app can show which account you are signed in as.

Usage analytics. Through Google Firebase Analytics we record which screens are opened and which features are used — for example that a note was created, a diagram was inserted, or an export was run. These events contain no note content, note titles, filenames or repository names.

Session data. Your GitHub access token and public profile, encrypted into an httpOnly cookie that only our server can decrypt. It expires after 30 days. It is never readable by JavaScript in your browser and never appears in a URL.

Server logs. Our hosting provider keeps standard HTTP request logs — IP address, user agent, path, timestamp — for operational and security purposes.

4. What we do not collect

  • The content of your notes
  • The names of your notes, folders or repositories
  • Your GitHub password — we never see it; authentication happens on github.com
  • Payment card details — no payment provider is currently connected at all
  • Location data beyond what an IP address implies
  • Anything from advertising networks, data brokers or session-replay tools

5. Cookies

ForkLeaf sets two cookies, both strictly necessary:

CookiePurposeLifetime
forkleaf_sessionYour encrypted sign-in session30 days, or until you sign out
forkleaf_oauth_stateCross-site request forgery protection during sign-in10 minutes, deleted as soon as it is used

Firebase Analytics may set its own identifiers in browser storage. It is not used for advertising, and blocking it does not affect the app.

Preferences such as your theme choice are kept in localStorage on your device and are never sent to us.

6. Who else is involved

ProviderRoleWhat they receive
GitHub, Inc.Hosts your notes repository and authenticates youEverything in your repository — it is your repository on their platform
Google (Firebase)Product analytics and the account recordAnonymous usage events and the account record in section 3
Our hosting providerServes the applicationStandard HTTP request logs

We do not sell personal information, and we do not share it with anyone beyond the processors above.

For users in the UK, EEA and other jurisdictions with equivalent law, our lawful bases are:

  • Contract — session data and the account record are necessary to provide a service you asked for.
  • Legitimate interests — anonymous analytics and server logs, to keep the service working and to understand which features matter. You can block both without losing functionality.

8. How long we keep it

  • Session cookie: 30 days, or until you sign out.
  • Account record: until you ask us to delete it.
  • Analytics events: according to the retention window configured in Firebase, currently 14 months.
  • Server logs: according to our hosting provider’s retention policy, typically 30 days.
  • Your notes: we do not hold them, so there is nothing for us to retain or delete. They persist for as long as you keep the repository.

9. Your rights

Depending on where you live you may have the right to access, correct, delete, export or restrict processing of your personal data, and to object to it. To exercise any of these, email praneeth2006.dev@gmail.com.

You can also do most of it yourself, immediately:

  1. Notes on GitHub — delete the repository in your GitHub settings. It is your data in your account; we cannot delete it for you.
  2. Notes in your browser — clear site data for this domain.
  3. Your session — sign out, then revoke ForkLeaf at GitHub → Settings → Applications → Authorized OAuth Apps.
  4. Your account record — email us and it will be deleted within 30 days.
Do step 1 before step 2. Notes in the “On this device” workspace exist only in your browser — clearing site data destroys them, and there is no other copy anywhere.

10. International transfers

GitHub and Google both operate globally and may process data outside your country, including in the United States, under their own standard contractual clauses and transfer mechanisms.

11. Children

ForkLeaf is not directed at children under 13, and we do not knowingly collect their personal information. GitHub requires account holders to be at least 13.

12. Changes to this policy

If this policy changes materially, the date at the top of the page changes and a notice appears in the app. The history of every revision is public in the git repository, so you can diff it.

13. Contact

Privacy questions, data requests and complaints: praneeth2006.dev@gmail.com. For security vulnerabilities, please follow the disclosure process in SECURITY.md instead of filing a public issue.

The engineering-level account of the same material, with the exact document shapes, is in the documentation.