Skip to content
xNotePadAI

Privacy Policy

Last updated: August 2026

What we collect

Without AI enabled (default):

Local only. All notes are stored exclusively in your browser's localStorage. No data leaves your device unless you explicitly enable AI features, cloud sync, or sharing.

With AI features enabled (opt-in):

When you enable AI in Settings, the following data is transmitted to our servers:

  • Note content (excluding sections marked 🔒 Confidential) is synced to a Cloudflare D1 database for AI querying
  • Text chunks are embedded and stored in Cloudflare Vectorize for semantic search
  • AI chat queries are processed by Cloudflare Workers AI (Llama 3.3 70B) — queries are not stored
  • MCP access logs record: method, tool name, tenant ID, IP address, and user agent

All server-side data is isolated by your tenant ID. You can disable AI at any time — this stops all server transmission. Deletion of server-side data can be requested via the contact page.

Anonymous product analytics (always active):

We collect anonymous milestone events to understand how the product is used. This data cannot identify you:

  • What's collected: A SHA-256 hash of a random ID (not your identity), a milestone name (e.g. "first_note"), and a date bucket (e.g. "2026-08-23")
  • What's NOT collected: No IP address, no user agent, no note content, no search queries, no cookies, no device info, no page views, no click paths
  • Deduplication: Each milestone is recorded only once per user (e.g. "first note created" fires once, ever)
  • Auto-deletion: All records are automatically purged after 90 days

This helps us understand which features are used (e.g. "do people use AI chat?") without knowing who you are or what you write. The anonymous ID is generated locally and never leaves your browser in readable form — only the SHA-256 hash is stored server-side.

Cookies

We do not use cookies. Your preferences (theme, font size) are stored in localStorage alongside your notes.

Third parties

We do not load any third-party scripts, analytics, tracking pixels, or advertising networks. The page loads zero external resources.

Data deletion

Clear your browser's localStorage or use the delete button within xNotePadAI to remove local notes. If you have used cloud sync or sharing, contact us via the contact page to request server-side deletion.

Impact of disabling storage

xNotePadAI uses localStorage (not cookies) to function. If your browser blocks localStorage — for example in private/incognito mode or with strict privacy settings — the following will be affected:

  • Notes cannot be saved — all content is lost when you close the tab
  • Preferences reset — theme, font size, and line height revert to defaults each visit
  • Version history unavailable — no snapshots are stored
  • Encryption cannot be enabled — requires storing the salt and verifier
  • AI features disabled — chunks and tenant ID cannot be stored

We do not use cookies at all. xNotePadAI will still load and function as a basic text editor without localStorage — you simply cannot save between sessions.

Contact

Questions about privacy? Contact xSoft Ltd.