noted.do

Privacy

This page explains what noted.do stores, why, and for how long. It describes how this software works; if you run the site, read it and change anything that differs for your setup.

Reading blogs

  • No tracking cookies. Readers get no cookies at all. There are no ads and no third-party analytics.
  • View counts. When you open a post, the site stores a one-way code made from your network address, your browser name and the date, so each reader counts once per day. The code can't be turned back into your address. These records are deleted after 90 days; only the total count per post is kept.
  • Fonts and embeds. Pages load fonts from Google Fonts, so Google receives your network address. If an author embeds a video or other content, that service may collect data when you play it (YouTube embeds use its privacy-enhanced mode).
  • Server logs. Like most websites, the web server keeps technical logs (address, time, page requested) for security and troubleshooting, for 14 days.

Reacting and commenting

  • Reactions store the same kind of one-way code as view counts, so each reader can react once. They're kept while the post exists.
  • Comments store the name, optional website and text you enter, plus a one-way code of your address to fight spam. Comments are public once the author approves them and are kept until the author or you ask for removal. Comments flagged as spam are deleted after 30 days.
  • Replies from the fediverse (Mastodon and similar) are stored with your public profile name and link.

Email subscriptions

  • We store your email address, when you subscribed and when you confirmed.
  • Unconfirmed sign-ups are deleted after 7 days. Unsubscribing (a link is in every email) deletes your address from that blog's list.
  • If an email bounces or is reported as spam, the address is added to a block list so nothing more is sent to it. That list is kept so we don't email you again.
  • Emails are sent through our email provider (smtp.protonmail.ch). Authors can download their own subscriber list.

Writing on noted.do

  • Account: username, blog name, bio, links, and an optional email address for notices. Your sign-in token and recovery code are stored only in scrambled (hashed) form.
  • Posts and pictures: what you publish. Location and camera details are removed from pictures when you upload them. Earlier versions of posts are kept (the last 30) so you can restore them.
  • Security records: sign-in attempts and sign-up limits use your network address for up to 7 days. Actions by site admins are logged for a year.
  • Fediverse: if your blog can be followed from Mastodon, public posts are sent to followers' servers. Unpublishing sends a delete request, but other servers control their own copies.
  • Payments: Stripe or Ko-fi handle card details; we never see them. We keep a record of the payment (your username, plan, amount and the email the payment service gives us).

Backups

The database and pictures are backed up every night. Copies are kept for 14 days and then deleted, so removed information disappears from backups after that time.

Your choices

  • Download everything you've published from your account page, at any time.
  • Delete your account from your account page. Your posts, pictures, comments on your posts and subscriber list are removed right away.
  • Ask about or remove anything else: contact admin@noted.do.

We don't sell or share personal information, and we only give it to others when the law requires it.