Legal
Privacy
Last updated 21 September 2026
Written against what the code actually does. It changes when the product does.
The app on your computer needs no account and sends us nothing. This page is about the cloud service: what we store once you sign up, where it sits, and how to get rid of it.
Who is responsible
[LEGAL ENTITY — beta, not yet registered], established in [COUNTRY], decides what is collected here and why. Questions, requests, complaints: .
What we store
- Your account — email address, password (hashed; the sign-in system holds it, we never see it), username and display name if you set them.
- What you put in a workspace — files, notes, ink, connectors, names, file attributes, and the layout of your desktops and windows.
- Sharing — the email addresses you type into an invite (a pending invite expires after 14 days), and who is a member of what, with their role.
- Hub listings — slug, description, tags, the cover image you upload, and how many times the workspace was forked.
- Reports — who reported which workspace and the text they wrote. Visible to moderators, not to other visitors.
- How the product is used — when an upload to the cloud starts, stalls, or finishes, and when you hit a storage or file-size ceiling: sizes, file counts, file types, and whatever you type into the free-text box on those screens. It is how the 100 MB and 25 MB numbers get decided without a survey.
- Metering — per day, the number of bytes served from your public workspaces to people who are not members, and the bytes your account downloads from other people’s public workspaces.
- Technical records — server logs and the counters that enforce rate limits, keyed by IP address. The fair-use share on a public link is counted per IPv4 address or IPv6 /64.
- The waitlist — if you leave an address on the Pricing page, we keep it to write to you once, when paid plans open.
- Feedback — if you send a note on the Feedback page, we keep the email, the category (bug, idea, or other), the message, and any screenshots you attach (up to five), so we can read it and write back.
Where it is stored
The database and the sign-in system run on Supabase in Ireland (eu-west-1). Your workspace files sit in a private Backblaze B2 bucket in the United States (us-east-005) and are served only through links that we sign for one reader at a time. Screenshots attached to a Feedback note stay in the same Irish Supabase project as the note, not in that US bucket. By using the cloud service you accept that workspace files are stored in the US.
Who else processes it
- Supabase — database, accounts, live updates, and feedback screenshots (Ireland).
- Backblaze B2 — file storage (United States).
- Render — the API server.
- Vercel — hosting for the app and this site.
- Plunk — sign-in, invite, and moderation email.
There are no advertising or analytics trackers on this site or in the app. We do not sell anything to anyone.
What other people see
A private workspace is visible to you and the people you invite. An unlisted public link is visible to anyone who has the URL, live, as you keep writing. A Hub listing is visible in the public gallery, with your username and display name on it. Reports are not shown to other visitors.
Two things are easy to miss. Everyone who shares a workspace with you can see the email address of every other member of it, including yours. And preview images are generated only for workspaces that are public — a private one is never rendered on our servers.
Cookies and browser storage
The app keeps your sign-in session in your browser so you do not log in twice a day. This site stores one cookie for the light/dark setting. No third-party cookies, no tracking pixels.
How long we keep it
- Trash: rows are removed for good 30 days after you delete them; the files behind them are cleared from storage a day or two later, which is also the window for undoing an accidental delete.
- Pending invites: 14 days, then the row goes.
- Deleting a workspace deletes what is inside it. Deleting your account (in the app, after a fresh sign-in) removes the account and everything attached to it, including usage records and metering counters.
- Server logs: a short operational window. Backups at our providers linger a little longer.
- The waitlist address: until paid plans open, or until you ask us to drop it.
- Feedback notes and their screenshots: until we have acted on them, or until you ask us to drop them.
- If paid plans arrive, payments will run through a merchant of record and billing records will be kept as long as the law requires them. There is no paid plan today, and we store no card details; this page will be updated before that changes.
Your choices
You can read and correct your profile in the app, export a whole workspace as a .pile from the desktop app, delete a workspace, and delete the account itself. For anything you cannot do from the app — a copy of what we hold, a correction, an objection, or a deletion you want confirmed — write to . If you are in the EU or the UK you also have the right to complain to your data protection authority.
Children
The service is not meant for anyone under 13, and where local law sets a higher age for agreeing to data processing, that age applies. If we learn an account belongs to someone younger, we delete it.
Security
Access is enforced in the database itself, row by row, not only in the app. The file bucket is private: downloads go through links that expire (15 minutes by default), and passwords are handled by the sign-in system, never stored by us. If you find a hole, the Support page says where to write.
Changes
When this page changes, the date at the top changes with it. For anything material we write to the address on your account.