Privacy
Last updated 29 August 2026
Editpad is local-first. Without encrypted sync, your note titles and contents stay in this browser's IndexedDB storage and are not sent to Editpad. While you type, one emergency draft is also kept in this browser's local storage and cleared after a confirmed database save.
Google sign-in
If you sign in, Editpad receives your Google account identifier and email address to create your account. It also keeps a coarse browser label and session activity times so you can review and revoke signed-in browsers. It does not retain Google access or refresh tokens.
Optional encrypted sync
Sync is off until you explicitly enable it. Synced note titles, bodies, and organisation data are encrypted in your browser. The service stores encrypted envelopes and operational metadata such as opaque note identifiers, revisions, and timestamps. Your recovery passphrase is never sent to the service.
Logs and tracking
Editpad has no advertising, third-party analytics, or note-content telemetry. Cloudflare may process ordinary network metadata to deliver and protect the service.
Retention and deletion
Local Notes, Archive, and Trash do not expire automatically. You control local deletion. Signed-in users can delete their encrypted cloud vault or account. Security rate-limit records expire by design and contain hashed identifiers.
Contact
Privacy questions can be sent to macklpgr@gmail.com.