What we store, and where#
Your account (your email address, or Apple's relay address if you use Hide My Email), your notes, folders, files and earlier versions of each note as encrypted copies, your profile name and photo if you set them, your devices, and the AI apps you've connected. It's all stored at Supabase, our host, in Frankfurt, Germany.
The website and shared note pages run on Vercel, and are built in Frankfurt too. Vercel passes requests on to our server, including the requests AI apps make, and sees a shared note while it shows the page, but it doesn't store your notes. Our server does its work in Frankfurt: a request from anywhere enters Supabase's network at the nearest location and is passed to Frankfurt before it's handled.
What's encrypted#
- End to end: your notes, their titles, folder names, file names and files, and every earlier version are encrypted on your device before they're uploaded. The key is made on your first device, and only your devices, and AI connections you approve, can unlock it. We store only the encrypted copies, and we can't read them.
- Your key: iCloud Keychain carries it between your iPhone and Mac. Apple encrypts iCloud Keychain end to end, so Apple can't read it either.
- Your recovery key: a key you save yourself, shown in Settings, Privacy & Security on your devices. It's the fallback when a device can't get your key from iCloud Keychain. We keep your notes' key only locked with it, and we never get the recovery key.
- Locked notes: encrypted a second time, with a key made from your notes password. That key never leaves your devices, so not even an AI you connect can read a locked note's text. If you forget the password, nobody can recover it.
- On the way and on disk: everything travels over HTTPS, and Supabase encrypts its disks as well (AES-256).
- Passwords and access tokens are stored only as one-way hashes.
Signing in, with Apple or a password, only tells us who you are. Your password has nothing to do with your notes' key.
What stays readable to us#
To sync your notes and run your account, some details aren't encrypted:
- Your email address and your sign-in records.
- Your profile name and photo.
- Your notes-password hint.
- The size and dates of each note, file and version.
- Which folder each note is in, and which notes are sub-notes of which.
- Which notes are pinned, and which are locked.
- The names of the AI apps that edited a note.
- Your list of devices.
- Your AI connections: their names, access, and when they were made and last used.
- The usage counts listed below.
- A note you share, while it's shared, since anyone with the link can read it.
When you connect an AI#
- You approve it on your device. Your iPhone or Mac asks you, and you type the number the page you started on shows there. With no device nearby, you can approve in the browser with your recovery key.
- Our server opens your notes for it. Approving gives that AI connection a copy of your notes' key, locked with a key derived from that connection's access token. We store only a hash of the token; the token itself arrives with each of the AI's requests. During each request our server unlocks your whole notes' key in memory, reads the notes the AI asks for, and forgets the key when the request ends.
- Our hosts carry that text. For AI requests, the text of the notes the AI reads or writes, and its access tokens, pass through Vercel and Supabase in readable form on their way. Neither stores your notes.
- Locked notes stay locked. An AI sees only their titles, never their text.
- You choose Read Only or Read and Edit for each one.
- Every change an AI makes keeps the previous version, so you can see what changed and restore it.
- Disconnect any AI app in Settings → Connect an AI. It loses access at once.
- What an AI app reads becomes part of your conversation with it, and the company behind it handles that under its own privacy policy.
Limits#
- AI requests. While an AI you connected works, our server handles the text it asks for. A changed server could copy it. Disconnecting ends this at once.
- The recovery key in the browser. Approving on ambernotes.app with your recovery key runs our code in your browser. It never stores or sends the key, but a changed page could read it. When you can, approve from your iPhone or Mac instead.
- No key rotation yet. Your notes' key stays the same for the life of your account. Disconnecting an AI deletes its copy of the key, but you can't change the key itself yet.
- The database. Someone running the database can't read your notes, but could roll a note back to an earlier encrypted version, or hide notes from your devices.
Who can see what#
- You, on every iPhone and Mac you sign in on, once it has your key.
- Us. As the people running the database (that's Emil, who makes Amber Notes), we see the encrypted copies and the details listed under what stays readable. We can't read your notes.
- AI apps you approve, for the notes they ask for, until you disconnect them. They never see the text of locked notes.
- Anyone with the link to a note you share, until you stop sharing it. Your device publishes a readable copy for the link, and it's deleted when you stop. Shared pages are hidden from search engines.
No ads, no tracking in the app#
There are no ads, and there never will be. The apps have no tracking, no third-party analytics and no crash-reporting tools. We never sell or share your data.
This website counts page views and where visitors came from with Vercel Web Analytics, and which links and buttons are clicked, where on a page people click and how far pages are scrolled with PostHog, in the EU. These are counted across all visitors; no visit is recorded. Neither keeps a profile of you, and neither runs on shared notes or the connect pages. PostHog uses a cookie only if you choose Accept on the cookie banner, to recognise your return visits for up to a year; Cookie settings at the bottom of the page changes your answer. It also counts Mac downloads as daily totals. None of this touches your notes or your computer.
The apps count a few things on our own server, so we can tell whether Amber Notes works for people. Kept for 12 months, never shared:
- How many notes an AI connection changed on each day.
- Which days you used the app, to ask once, after a week, whether you'd like to share it.
- Which tips were shown and whether the feature was then used.
- Which first-run setup steps you've done.
- How you heard about Amber Notes, if you answer that one question after sign-up.
- A random id for each installation and whether it's an iPhone or a Mac, to count devices.
Every log, and how long it's kept#
We don't write the text of your notes, email addresses, access tokens or IP addresses into any log of our own. Our hosts log the requests that reach them; we can't turn that off, but they keep it briefly.
| Log | What's in it | Kept |
|---|---|---|
| Supabase request logs | Each request to our server: the time, the address it asked for, the IP address and device type, and a rough location from the IP address. | 1 day |
| Supabase sign-in logs | Each sign-in and sign-out: the time, the email address and the IP address. | 1 day |
| Supabase function and database logs | When each server function ran and what it was asked for, and errors, with names, addresses and ids blanked out. | 1 day |
| Sign-in records in our database | Each sign-in: the time, the email address and the IP address, to keep your account secure. | 30 days |
| Vercel request logs | Each request to this website: the time, the page, the IP address and device type, and whether it worked. | 1 hour |
| Rate limits | A one-way hash of the IP address, made with a key that changes every day, to stop floods of sign-in attempts. | 2 hours |
Our hosting plan keeps no backups of the database, so what you delete is gone. If that changes, a backup would hold only the encrypted copies and the locked copies of your key, for as long as this page and the privacy policy say.
Your data, your choice#
- Export: Settings → Privacy & Security → Export Your Notes makes a zip on your device with every note as Markdown in its folder, with its files. We can't read your notes, so the export can only be made there. For everything else we keep about you, write to us.
- Delete: Settings → Delete Account deletes your account and everything in it from our server at once: notes, files, versions, AI connections, share links and usage counts.
- Deleted notes stay in Recently Deleted for 30 days, then they're gone for good.
- You can also ask us to correct, restrict or stop using your data, or object to the usage counts. Write to hello@ambernotes.app; we answer within a month. You can complain to the Swedish Authority for Privacy Protection (IMY).
Open source, so you can check#
Everything above is in the code, and the code is on GitHub: the apps, the server and this website. Found a security problem? Write to hello@ambernotes.app, not a public issue.
The legal details are in the privacy policy.