Legal

Privacy Policy

Last updated: September 6, 2026

Nisabascribe is built around a simple premise: we shouldn't be able to read your notes, and we shouldn't need to know who you are to let you use the Service. This page describes, as plainly as we can, what data the Service actually handles based on how it's built - not generic promises.

Information We Do Not Collect

We do not ask for your name, email address, phone number, or any other personal information at any point, including when unlocking access. We do not use advertising trackers, marketing pixels, or third-party analytics anywhere on this site. No identity verification is required to use the Service. We do not log IP addresses anywhere in the application, including on the login page - our brute-force protection is keyed to the credential being attempted instead, so it never needs to know where a request came from.

Information We Do Collect

One-Time Share Recipients

Opening a one-time share link does not require an account, a username, a password, or any cookie - the recipient interacts with the Service anonymously and briefly. We do not log IP addresses anywhere in the Service, including on this page. The master key is entered directly in the recipient's browser and is never transmitted to us at any point; decryption happens entirely on their device. The instant the link is opened, the underlying note - its database record and its object on our storage provider - is deleted. No record that the exchange happened, or that a particular note ever existed, remains in our systems afterward.

Payments

All payments are made in Monero (XMR). We do not process credit cards, collect billing addresses, or use a third-party payment processor. Because Monero transactions can't be reversed, all payments are final and non-refundable.

Third-Party Services

Running the Service means relying on a small number of outside providers, each seeing only a limited slice of activity:

Fonts, styles, and scripts are all served directly from our own server rather than a third-party CDN, so loading a page here doesn't send your browser off to Google or anyone else in the background.

Data Retention & Deletion

Your notes stay stored until you delete them, they reach an auto-expiry date you set yourself, or your account is removed. If you choose to set a note to automatically delete after a number of days, it is removed on that schedule regardless of whether it was ever opened. You can also delete all of your notes at once from the My Notes page, or delete your entire account - notes, credentials, and payment records together - from the account menu in the navigation bar. A one-time share note follows a different, immediate rule instead of a schedule: it is deleted the instant its link is opened, by whoever opens it, rather than after any fixed period. In every deletion case, we remove the relevant records from our database and ask our storage provider to unpin the corresponding notes from IPFS as well - though because of how IPFS and Filecoin work, copies that already propagated to other nodes may remain retrievable by anyone holding the exact content identifier (CID) until the underlying storage deals lapse; deletion through our interface does not guarantee immediate removal from every node globally. Expired, unrenewed accounts remain in our database with their notes intact but inaccessible until renewed - we do not currently auto-purge that data, though you can still delete such an account yourself once logged back in via a renewal.

Your Rights Under GDPR and Similar Laws

Because this Service is built to never learn who you are, most of these rights work a little differently here than at a typical service:

If you believe we're not honoring one of these rights, or have a question this page doesn't answer, you're also entitled to lodge a complaint with your local data protection authority.

Your Encryption Keys & Login Credentials

Because we never receive or store the encryption key for any note, we have no way to recover one if it's lost - that note becomes permanently unreadable, by you and by us. The same applies to your username or password: the only recovery path is the payment-based renewal flow on the Verify Payment page, which requires the exact address and TXID of a payment you previously made.

Children

This Service is not directed at, and should not be used by, anyone under the age of 18.

Changes to This Policy

We may update this policy as the Service changes. Continued use after changes are posted constitutes acceptance of the revised policy.

Not Legal Advice

This page describes our actual technical practices as accurately as we can. It is not a substitute for legal advice, and depending on where you or we are located, additional obligations (such as GDPR or CCPA) may apply beyond what's described here.