Legal
Privacy Policy
Last updated: September 6, 2026
Nisabascribe is built around a simple premise: we shouldn't be able to read your notes, and we shouldn't need to know who you are to let you use the Service. This page describes, as plainly as we can, what data the Service actually handles based on how it's built - not generic promises.
Information We Do Not Collect
We do not ask for your name, email address, phone number, or any other personal information at any point, including when unlocking access. We do not use advertising trackers, marketing pixels, or third-party analytics anywhere on this site. No identity verification is required to use the Service. We do not log IP addresses anywhere in the application, including on the login page - our brute-force protection is keyed to the credential being attempted instead, so it never needs to know where a request came from.
Information We Do Collect
- Account credentials. When your payment is verified, we generate a random username and password and store them so you can log in. We have no way to connect that username to a real identity.
- Encrypted note content. Your browser encrypts each note (AES-256-GCM) using a key you provide, derived with PBKDF2, before it ever leaves your device. You choose that key each time you create a note, so different notes may use different keys. We store only the resulting ciphertext, pinned to IPFS, and never receive any of your keys - what we hold is unreadable to us. Responsibility for the content of your notes rests entirely with you; see our Terms of Service for details.
- Note organization metadata. If you assign a category or color to a note, that value is stored in plain text alongside the encrypted content - it is not encrypted. Both are chosen from a small, fixed list (categories like "work" or "ideas"; colors like "gold" or "lapis") rather than free text, specifically so this metadata cannot itself describe or reveal what a note contains.
- Payment proof. To verify and renew your subscription, we store the Monero address and TXID your payment used, along with the expiration date it grants. This is the same information visible to anyone who has that TXID; we don't derive anything about your wallet or history beyond that one payment.
- A session cookie. One functional cookie keeps you logged in. It's marked HttpOnly, Secure, and SameSite=Strict, and isn't used for tracking or advertising.
One-Time Share Recipients
Opening a one-time share link does not require an account, a username, a password, or any cookie - the recipient interacts with the Service anonymously and briefly. We do not log IP addresses anywhere in the Service, including on this page. The master key is entered directly in the recipient's browser and is never transmitted to us at any point; decryption happens entirely on their device. The instant the link is opened, the underlying note - its database record and its object on our storage provider - is deleted. No record that the exchange happened, or that a particular note ever existed, remains in our systems afterward.
Payments
All payments are made in Monero (XMR). We do not process credit cards, collect billing addresses, or use a third-party payment processor. Because Monero transactions can't be reversed, all payments are final and non-refundable.
Third-Party Services
Running the Service means relying on a small number of outside providers, each seeing only a limited slice of activity:
- Our decentralized storage provider, built on IPFS and Filecoin, hosts your notes' ciphertext. It can see that an encrypted object of a given size exists; it cannot decrypt it.
- The Monero network, a public but privacy-focused blockchain, is used to verify payment. No party, including us, can extract your real-world identity from it.
Fonts, styles, and scripts are all served directly from our own server rather than a third-party CDN, so loading a page here doesn't send your browser off to Google or anyone else in the background.
Data Retention & Deletion
Your notes stay stored until you delete them, they reach an auto-expiry date you set yourself, or your account is removed. If you choose to set a note to automatically delete after a number of days, it is removed on that schedule regardless of whether it was ever opened. You can also delete all of your notes at once from the My Notes page, or delete your entire account - notes, credentials, and payment records together - from the account menu in the navigation bar. A one-time share note follows a different, immediate rule instead of a schedule: it is deleted the instant its link is opened, by whoever opens it, rather than after any fixed period. In every deletion case, we remove the relevant records from our database and ask our storage provider to unpin the corresponding notes from IPFS as well - though because of how IPFS and Filecoin work, copies that already propagated to other nodes may remain retrievable by anyone holding the exact content identifier (CID) until the underlying storage deals lapse; deletion through our interface does not guarantee immediate removal from every node globally. Expired, unrenewed accounts remain in our database with their notes intact but inaccessible until renewed - we do not currently auto-purge that data, though you can still delete such an account yourself once logged back in via a renewal.
Your Rights Under GDPR and Similar Laws
Because this Service is built to never learn who you are, most of these rights work a little differently here than at a typical service:
- Right to erasure. Delete Account, in the account menu, permanently removes your credentials, your notes, and their storage on IPFS in one action. This is irreversible and takes effect immediately.
- Right to access. There is no separate copy of your data to request - everything we hold about your account is already visible to you directly through the Service itself (My Notes, and the payment details you provided at signup).
- Right to rectification. Your username and password are randomly generated at signup rather than supplied by you, so there is no personal profile data to correct. Note content and metadata can be edited or deleted directly from My Notes at any time.
- Right to restrict or object to processing. We don't perform analytics, profiling, or marketing processing on your data to begin with, so there is nothing to opt out of in that respect.
- Legal basis for processing. We process account credentials and payment records to provide the Service you've paid for (performance of a contract), and the session cookie exists solely to keep that access working (a strictly necessary function, not one requiring separate consent under ePrivacy rules).
If you believe we're not honoring one of these rights, or have a question this page doesn't answer, you're also entitled to lodge a complaint with your local data protection authority.
Your Encryption Keys & Login Credentials
Because we never receive or store the encryption key for any note, we have no way to recover one if it's lost - that note becomes permanently unreadable, by you and by us. The same applies to your username or password: the only recovery path is the payment-based renewal flow on the Verify Payment page, which requires the exact address and TXID of a payment you previously made.
Children
This Service is not directed at, and should not be used by, anyone under the age of 18.
Changes to This Policy
We may update this policy as the Service changes. Continued use after changes are posted constitutes acceptance of the revised policy.
Not Legal Advice
This page describes our actual technical practices as accurately as we can. It is not a substitute for legal advice, and depending on where you or we are located, additional obligations (such as GDPR or CCPA) may apply beyond what's described here.