Effective: January 2026 | Last updated: April 2026
Notedrop is built with a strong focus on privacy and data minimization. This policy explains what data is collected, why it is collected, and how it is handled in compliance with the General Data Protection Regulation (GDPR).
Controller: Bartosz Krawczyk (individual developer, Poland)
Contact:
We do not publicly list a personal home address for privacy reasons. Additional contact details may be provided upon request where legally required.
We are not required to appoint a Data Protection Officer under Article 37 GDPR.
We collect only minimal technical data required to operate the service:
| Data | Purpose | Legal Basis |
|---|---|---|
| Account data | Provide login and account access | Contract (Art. 6(1)(b)) |
| Notes/content | Provide core functionality | Contract (Art. 6(1)(b)) |
| Minimal logs | Ensure stability and security | Legitimate interest (Art. 6(1)(f)) |
| Support emails | Respond to inquiries | Legitimate interest (Art. 6(1)(f)) |
We may also process personal data where necessary to:
Legitimate interest justification: We process only minimal technical data strictly necessary to ensure service functionality and security. We have assessed that our legitimate interests are not overridden by your rights and freedoms, given the limited scope of data processing and absence of tracking or profiling.
Notedrop provides optional AI-powered features that run entirely locally in your browser.
AI features are activated only when you explicitly use them.
Notedrop supports optional end-to-end encryption (E2EE) for private notes.
For public notes:
For end-to-end encrypted data, we may be unable to provide access to plaintext content in response to data access requests, as we do not possess the decryption keys.
We do not sell or share your data for marketing or advertising.
We only share data with:
We implement appropriate technical and organizational measures to protect your data:
Content is processed automatically by our systems and is not accessed in human-readable form except where strictly necessary, such as for security incidents, abuse prevention, or compliance with legal obligations.
Data is hosted within the European Economic Area (EEA), specifically in data centers located in the Netherlands.
No system is completely secure, but we follow industry best practices to minimize risks.
We primarily store and process data within the European Economic Area (EEA).
If any processing involves transfers outside the EEA, appropriate safeguards such as Standard Contractual Clauses (SCCs) are used.
When you delete your account:
You have the right to:
To exercise your rights:
We respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority within the EU. In Poland, this is UODO.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on users within the meaning of Article 22 GDPR.
We use only strictly necessary cookies:
These cookies are essential for the operation of the service and do not require consent under applicable EU regulations.
The Service is not intended for the storage of highly sensitive personal data, such as health information, financial credentials, or other categories of data requiring enhanced protection. Users are responsible for determining the appropriateness of the Service for their specific use cases.
Notedrop is intended only for users aged 16 or older.
We do not knowingly collect data from individuals under 16. Age is self-declared at registration. If we identify or are notified that an account belongs to someone under 16, we will delete that account and its associated data promptly. If you believe an underage account exists, please contact [email protected].
If you self-host Notedrop:
Because Notedrop is free and open source software, self-hosters retain full access to the codebase and can operate their instances independently of this service.
Notedrop is developed and maintained by an individual developer. In the event that the hosted service at notedrop.app is discontinued:
Because Notedrop is free and open source software, the codebase remains publicly available for anyone to self-host or fork, ensuring long-term continuity of the project independent of this hosted instance.
In the event of a personal data breach, we will:
If you have questions about this policy: