Your notes are encrypted on your device before they are sent anywhere. We operate the service and cannot read them.
A note-taking application with client-side encryption. Notes are encrypted in the browser using a key derived from your password, which never leaves your device. What reaches our servers is ciphertext — the operator, the hosting provider, and anyone who compels either of them sees encrypted blobs and nothing else.
Because the encryption key is derived from your password and held only by you, account recovery works through a recovery key shown once at signup. If both the password and the recovery key are lost, the data is unrecoverable. That is the direct consequence of the operator not holding a key, and it is deliberate.
Generic Note sends transactional email only. There is no marketing email, and no mailing list of any kind.
Recipients are exclusively people who created an account themselves and confirmed their own address. No address is ever purchased, imported, or added by anyone other than its owner.
Weekly backups are disabled with one click in account settings, and from an unsubscribe link in every backup email. Address verification and security notifications are strictly transactional — they are sent only in response to an action on the account, and are not subject to opt-out while the account exists. Deleting the account stops all email.
Bounce and complaint events are captured and acted on automatically. A hard bounce suppresses the address and marks the account unverified, so nothing further is sent to it. A spam complaint immediately disables all non-essential email for that account.
hello@jingwu.dev — for questions about the service, its email practices, or to have an address removed.