# Privacy policy

> What personal data the hosted slivingdoc.dev service stores, why, who processes it, how long it is kept, and how to exercise your rights.

Canonical URL: https://www.slivingdoc.dev/privacy/

Full site index: https://www.slivingdoc.dev/llms.txt

Last updated: 2026-09-29.

This policy covers the hosted service at slivingdoc.dev and api.slivingdoc.dev.
The open-source CLI and MCP server, run against your own bucket, send nothing
to us. Terms of use are in the [terms of service](/terms/).

## Who is responsible

[OPERATOR NAME], [OPERATOR ADDRESS AND BUSINESS ID] ("we") is the controller of
the personal data described here. Contact for privacy questions and requests:
[LEGAL CONTACT EMAIL].

## What we store and why

| Data                  | What it is                                                                                                                                                                                                                                                                                              | Why                                                                                                | Basis                           |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ------------------------------- |
| Account               | A random id, your email address as verified by GitHub or Google, and the provider's user id. We store no name or picture.                                                                                                                                                                               | To create and recognize your account, contact you about it, and link sign-ins with the same email. | Contract                        |
| Sessions and cookies  | A session cookie of 30 days (we store only a hash of its value). A 10-minute cookie during sign-in. A 60-second cookie that shows a new token once.                                                                                                                                                     | To keep you signed in and complete sign-in safely.                                                 | Contract, and necessary cookies |
| Tokens and CLI logins | A hash of each token, your label for it, its space, role, expiry and last-used time.                                                                                                                                                                                                                    | To let your tools reach your spaces, and to revoke them.                                           | Contract                        |
| Spaces and sharing    | The name you give a space, who is a member and with what role, and invite links (stored as hashes).                                                                                                                                                                                                     | To run your spaces and sharing.                                                                    | Contract                        |
| Members' emails       | Members of a space see the email of the owner and of each other member of that space, and owners see who made a commit.                                                                                                                                                                                 | So people who share a space know who they share it with.                                           | Contract                        |
| Invitees              | If an owner emails an invite link, the address goes to our email provider to send it. We keep only an unsalted SHA-256 hash of it, for daily invite limits. That is not anonymous: someone who already knows an address can check it.                                                                   | To deliver the invitation the owner asked for.                                                     | Legitimate interest             |
| Your notes            | The UTF-8 text you commit, stored in a storage bucket for your space as compacted packs, not as separate files.                                                                                                                                                                                         | To provide the service.                                                                            | Contract                        |
| Usage                 | Stored bytes and a request count per month for your account, and a write log of each commit or delete (who, which space, the object key, the size, when). Note names are not in the log.                                                                                                                | To enforce limits, bill correctly, show your activity, and investigate abuse.                      | Contract, legitimate interest   |
| Account events        | A log of sign-ins, token and member changes, billing events, admin actions on your account, and support activity.                                                                                                                                                                                       | For your account history, security and support.                                                    | Legitimate interest             |
| Billing               | Your Stripe customer id, subscription state, and the steps you bought. Card details go to Stripe and never reach us.                                                                                                                                                                                    | To bill you and apply what you bought.                                                             | Contract, legal obligation      |
| Support               | The messages you write in the support chat, their subject, and the answers.                                                                                                                                                                                                                             | To answer you.                                                                                     | Contract, legitimate interest   |
| Sign-in from the CLI  | A hash of the network address that started a CLI login, its country, and a label for the client. The login record, with the address hash, is kept about 10 minutes, and the hash can be reversed by brute force while it exists. The country and client label are also recorded in your account events. | To show you where a login came from and to limit abuse.                                            | Legitimate interest             |
| Server logs           | Cloudflare Workers logs of requests, including the request URL (which can hold a sign-in callback or an invite code) and IP address, and error messages that can include account ids.                                                                                                                   | To operate and secure the service.                                                                 | Legitimate interest             |

We do not use advertising or analytics trackers, and we set no third-party
cookies. Your browser stores your theme choice locally, and, during a CLI
sign-in, the login code in session storage until it is used. The pages load no
third-party scripts or fonts. Providing an email through GitHub or Google is
required to have an account.

We make no decisions about you by automated means that have legal effect. The
support assistant is automated and can cancel a subscription only when you ask;
suspensions and deletions by us are decided by a person; the limits of your
plan are applied automatically.

## Who receives it

We use these processors and services. Each processes data only to provide its
part of the service to us.

| Provider                                                                                        | For what                                                                                                 | Data                                                                                                                                                                                                                                                                                                                                                                        |
| ----------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cloudflare                                                                                      | Hosting (Workers), database (D1), storage of your notes (R2), request counting, logs, and outgoing email | Everything above, since the whole service runs there                                                                                                                                                                                                                                                                                                                        |
| Stripe                                                                                          | Payments, subscriptions, invoices and tax                                                                | Your email, account id, subscription details and payment data                                                                                                                                                                                                                                                                                                               |
| GitHub and Google                                                                               | Sign-in                                                                                                  | They tell us your id and verified email when you sign in                                                                                                                                                                                                                                                                                                                    |
| An AI model provider, through OpenRouter (the model, and so the provider behind it, can change) | The support assistant's answers                                                                          | The whole support conversation, which can contain anything you type, and facts about your account: space names, ids and roles, token labels and dates, limits, subscription state, usage totals and recent event types. Never your email, your notes, bucket names, token ids or Stripe ids. We ask the provider not to store it, but we cannot guarantee how it handles it |

Some of these providers process data outside the European Economic Area,
including in the United States. Where that is so, we rely on the safeguards
they offer, such as the EU Standard Contractual Clauses.

We do not sell personal data, and we do not share it with anyone else except
where the law requires it.

## Your notes

Notes are not end-to-end encrypted. Nothing in our admin or support tools
opens a note, and the assistant never receives note contents. Members you
invite to a space can read it. We may access stored data only if the law
requires it or to investigate abuse, a security incident, or a request from you.

## How long we keep it

- Account data, sessions, tokens, spaces, billing and support data: until you
  delete your account.
- Notes and their history: until you delete the space or your account, plus the
  short time the background erasure takes to finish.
- Usage and account event logs: until you delete your account. The write log
  of a space is deleted with that space.
- Payment records: Stripe keeps its own payment, invoice and tax records as
  the law requires, under its own privacy policy.
- Server logs: for the period Cloudflare keeps them, which we do not control.
- Expired sessions are not cleaned up until you sign out or delete your
  account; they hold only a hash.

When you delete your account, it is removed from our database in one step and
your spaces are emptied and deleted in the background. Data that must remain
is limited to a record that an account was deleted under a random id, and to
that same random id where you acted in another person's space (for example its
commit log, or the fact that you left it), or answered a support ticket.
Signing in again with the same email creates a new, empty account. Cloudflare
may keep database recovery copies for a limited time as part of its platform.

## Your rights

Under the GDPR and similar laws, you can ask us to give you access to your
data, correct it, delete it, restrict or object to how we use it, and give you
a copy in a portable form. You can pull your notes yourself at any time with
the CLI. You can delete your account from your account page. For anything
else, write to [LEGAL CONTACT EMAIL]. We answer within one month. You can also
complain to your local data protection authority.

## Children

The service is not for anyone under 16 and we do not knowingly collect their
data.

## Security

Access to spaces goes through one API that checks every request against your
tokens and space membership. Tokens and invite links are stored as hashes.
Notes are transported over HTTPS. No system is perfectly secure; where the law
requires it, we will notify you and the authority of a breach that affects you.

## Changes

If we change this policy in a way that matters, we will tell you before it
applies, by email or on your account page.
