Privacy Policy

Effective 2026-08-11

Stickypad is a local-first whiteboard. By default everything you create lives in your own browser and never leaves your device — unless you choose a feature that sends data off your device. The optional Cloud and Cloud Pro subscriptions sync your boards across your devices through our infrastructure. This policy explains our limited product analytics and access logs, what cloud sync and sharing send, how we use that data, who we share it with, and your rights.

What we collect

Free tier (no account). Your boards, notes, files, and preferences live entirely in your browser’s IndexedDB and localStorage — that content stays on your device and we cannot read it, unless you choose to use a sharing feature such as a board copy, which sends only the notes you pick (see “Sharing features”). When you explicitly copy a filename, section, whole document, code-block body, or Document section link, Stickypad writes that text only to your browser or operating-system clipboard and does not send it to Stickypad analytics or servers. A Document section link contains only opaque board, note, revision, and heading-position identifiers; it contains no heading, title, or note text and is resolved locally. We also collect content-free product analytics: a random device and session id, the app version, your device type (desktop / tablet / mobile), your plan tier (free or paid), a timestamp, and the names of in-app events (for example “app opened” or “note created”), plus coarse buckets such as an error category. The random device and session ids are pseudonymous identifiers; they are not your name, email address, account identifier, or a browser fingerprint, although cloud features can associate the device id with an account or board as an advisory device/origin marker. We do not collect your note text, board content, file contents, or file paths in analytics. You can turn analytics off any time in Settings → Data & privacy → Usage analytics, and we honor your browser’s Do Not Track and Global Privacy Control signals. We use no advertising or third-party tracking cookies.

Access logs for all visitors. CloudFront access logs for every site visitor record the raw IP address, requested URL (including analytics-beacon query fields when a beacon fires), user agent, and response details. We use these logs for site delivery, security investigation, and aggregate product analytics. They are retained for up to 90 days and then deleted; we do not use them for advertising or individual profiling.

Cloud and Cloud Pro subscribers. When you subscribe and sign in, we collect:

  • Email address — used to identify your account and to send sign-in links.
  • Board content you choose to sync — the notes, containers, file references, and metadata on the boards you sync. Linked files are handled in two ways. For linked text files (such as .md, .txt, or source files), a snapshot of the text content is synced to the cloud along with the file path — that content may include source code, and absolute paths can reveal your project structure. For linked binary files (images, PDFs, audio, video), the bytes never leave your device — only the file path is synced, and your other devices show a placeholder until you grant them access to the same file.
  • Subscription status — whether your subscription is active, the plan you chose (monthly or yearly), and the date it next renews.
  • API operational logs — API operational logs record the raw IP address for rate limiting and security investigation, along with the request path and response code. They are kept for up to 90 days. We do not log raw email addresses, raw tokens, or the contents of your boards.

We do not collect: payment card numbers (Stripe handles those directly), your real name, your phone number, your location, or any data from third-party trackers.

How we use it

  • Provide the service. Sync your boards across your devices, send sign-in links, process subscription billing.
  • Keep the service running. Detect and prevent abuse, fix bugs, monitor uptime.
  • Communicate about your account. Send transactional email (sign-in links, payment receipts, account deletion confirmations). We do not send marketing email.

We do not sell your data, share it with advertisers, use it to train AI models, or profile you for targeting.

Sharing features

Stickypad has optional sharing features. They only ever transmit the content you explicitly choose to share, when you choose to share it — nothing is shared automatically. The Terms of Service describe how each one works; here is what each means for your data:

  • Public Hub (paid). Notes you publish are made publicly readable at your Hub address and can be copied by anyone with the link. Only notes you explicitly publish are exposed; unpublished notes stay private. Unpublishing removes the public copy.
  • Board copies (free). Creating a copy link stores a notes-only snapshot of that board on our infrastructure so recipients can import it. The link is anonymous (no account needed to open it) and stops serving when it expires (a sender-chosen period of 24, 48, or 72 hours) or after 10 open attempts, whichever comes first — attempts count even if a download doesn’t complete. The snapshot payload is removed by a short automatic storage-lifecycle rule; bounded link metadata and a small preview may be retained for up to 30 days for abuse investigation, then deleted.
  • Shared boards (paid). Notes on a board you share are visible to the collaborators you invite, and the board records basic activity attribution (which member last changed a note). To invite someone you provide their email address. We use it to send the invitation, to verify the account that accepts it, and to show the pending or accepted member to you, the board owner. Unaccepted invitations expire after 14 days; member records persist while that person remains on the board. Shared boards are never public.

Sub-processors

We use a small set of third-party providers to operate Stickypad. Their agreements and service terms govern how they process data for us.

  • Amazon Web Services (AWS) — hosting and infrastructure (Cognito for accounts, S3 for board storage, Lambda for the API, CloudFront for the CDN). United States.
  • Stripe — subscription billing and payment processing. Stripe receives your email address and the payment information you enter on their hosted checkout page. United States.
  • Resend — transactional email delivery (sign-in links, account notifications). Resend receives your email address and the message body. United States.
  • Cloudflare — provider of the TURN/WebRTC relay for Cross-Device Live Links. Cloudflare receives peer IP addresses and relayed connection data needed to route those live links. United States.
  • Sentry — error monitoring. For signed-in users — and only if you have not opted out via Do Not Track, Global Privacy Control, or the in-app analytics setting — Sentry receives pseudonymous error reports: an error code, the original error type, sanitized stack-frame filenames and function names, the app surface, a frozen-state indicator, allowlisted coarse dimensions, and an 8-character one-way hash of your account identifier. It does not receive your board content, raw error messages, email address, or IP address. United States.

How long we keep it

  • Active subscribers: board content and account data are kept as long as your subscription is active.
  • If your subscription lapses or you cancel (but keep your account): your synced board content becomes read-only and is retained for 90 days so you can re-subscribe and resume where you left off, or export it. We send reminder emails before anything is removed (including at 60 days and in the final week), and the removal date is shown when you sign in. After 90 days the cloud copies are deleted; the boards on your own devices are never touched. Public and shared visibility ends about a week after the subscription ends. To remove your data sooner, delete your account (below).
  • After you delete your account: a 30-day soft-delete grace period lets you restore the account by signing in again with the same email. After 30 days the account, your synced board content, and our internal subscription/customer mapping row are permanently deleted (Stripe retains its own billing records, as described in the “Billing records” item below). Your local board copies on your own device are untouched by account deletion; deleting the account does not erase your browser storage. If you need deletion sooner than the grace period, email support to ask whether earlier deletion is available.
  • Retained after account deletion (limited records): several categories of pseudonymized record can persist. A one-way hashed fingerprint of a released email address (a one-way keyed hash, never the address itself) is kept permanently whenever an email is freed — both when you delete your account and when you change your email (the old address is tombstoned) — to prevent that freed address from being re-registered by someone who later gains control of it. An append-only account-lifecycle ledger keeps bounded event records indefinitely, including after account deletion — an internal account identifier (your Cognito subject id), the event type, a timestamp, and bounded metadata such as a cancellation reason or one-way keyed hashes of email addresses — never your board content and never your raw email. The email tombstone also stores that internal account identifier. Other residues can remain: contributions you made to shared boards you did not own stay on those boards with your identity removed (shown as “Deleted user”); and if you published a public Hub profile, a short-lived handle-release marker is kept (about seven days) to stop someone else immediately claiming your handle, while a small deletion marker file may also remain in public Hub storage indefinitely. We retain these limited pseudonymized records to resolve support inquiries about historical account state, investigate billing disputes, detect fraud, and maintain a reliable account-lifecycle audit trail; deletion rights are not absolute where records like these are necessary for account security or legal claims.
  • Operational logs: retained for up to 90 days for security investigation, then deleted.
  • Shared content: a board-copy snapshot is removed by a short storage-lifecycle rule once the link stops serving (the sender-chosen expiry of 24, 48, or 72 hours, or its 10-open-attempt limit); bounded copy-link metadata and a small preview may persist up to 30 days for abuse investigation. Shared-board membership records persist while a member remains on the board, and unaccepted invitations expire after 14 days. Notes you publish to a public Hub stay public until you unpublish them or your subscription lapses.
  • Billing records: Stripe retains transaction records for as long as their own retention policy and applicable tax law require, which may be indefinite. We retain only the customer-id mapping needed to process renewals and refunds.
  • Transactional email logs: the emails we send (sign-in links, receipts, account notices) are retained by our email provider under its own retention policy, which we do not control.

Your rights

Depending on where you live (GDPR if you’re in the EU/UK, CCPA if you’re in California, similar rights elsewhere), you have the right to:

  • Access the data we hold about you. Email support@stickypad.io to submit an access request.
  • Correct inaccurate data. Most fields are user-editable directly in the app.
  • Delete your account and its associated data, subject to the limited retained records described in “How long we keep it” above.
  • Export your boards. Stickypad has built-in board export controls in Settings → Data & privacy; for cloud-side data that isn’t in your local copy, email support.
  • Object to or restrict processing where applicable law provides that right. Email support to discuss your case.
  • Withdraw consent for Usage analytics at any time in Settings → Data & privacy. For other processing, email support; cancelling your subscription and deleting your account stops the associated subscription and account processing, subject to the limited retention described above.

Email support to exercise one of these rights. We will acknowledge and handle your request without undue delay and within the period required by applicable law. We may need to verify your identity; applicable law may permit an extension or a reasonable fee in limited circumstances.

Cookies and similar storage

Stickypad uses your browser’s localStorage, IndexedDB, and Cache Storage — not cookies — to run:

  • localStorage holds your preferences (theme, view options), a session marker for Cloud Sync subscribers so you stay signed in, and a pseudonymous device identifier (stickypad:device-id). That identifier de-duplicates usage events and is exposed by the account-read command. Cloud features also use it as an advisory origin for linked HTML state and when checking whether a local board should be adopted on first sync. Opting out of analytics stops analytics events and clears the identifier; one of those non-analytics features may create a new one while you use it.
  • IndexedDB stores your boards and their content, on your device.
  • Cache Storage, populated by a Service Worker, holds Stickypad’s own static files so the app loads and works offline. It never stores your board content.

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Clearing your browser’s site data for Stickypad removes all of the above.

Stripe’s checkout page may set its own cookies for fraud prevention; that’s governed by Stripe’s privacy policy.

Children

Stickypad is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has subscribed, email support@stickypad.io and we will delete the account and any associated data.

Security

We use industry-standard security: encrypted connections (TLS 1.2+), encryption at rest for stored board data (AWS-managed keys), per-user access isolation in our API, scoped IAM permissions on every server-side action, and minimal logging of sensitive fields. No system is perfectly secure; if we discover a security incident affecting your account we will notify you by email without undue delay.

International transfers

Our infrastructure is hosted in the United States. If you access Stickypad from outside the US, your data is transferred to and processed there. Our agreements and service terms with providers govern how they process data for us.

Changes to this policy

If we change this policy in a way that materially affects how we handle your data, we will email subscribers at least 30 days before the change takes effect. Smaller changes (clarifications, contact details) update the effective date at the top.

Questions about this policy? Email support@stickypad.io.