Privacy Policy
Draft, version 0 · Last changed 2026-09-25
This is a draft. It describes what the service actually stores and who can see it, taken from how the software is built. The operator's legal name and the law that applies are not yet stated. Nothing below is a promise beyond what the software does.
What is stored, and why
- Your account
- Your email address, a display name you choose, and a hash of your password (never the password). The address is how you sign in and how other people can share a shelf with you. A per-account counter changes when you reset your password, which signs out every other device.
- Your writing
- Notes, their properties, files you attach, and the folders, libraries, views and arrangements you build. Every change is kept as history so a note can be walked back and so two devices editing the same words keep both versions. History is kept for 180 days by default.
- Sharing
- Which accounts hold which shelf and with what access. People you share a shelf with see your display name and address in its members list.
- Where you have been
- Which notes you opened recently and what you pinned, kept per person so each device shows the same Recent and Pins.
- Security records
- The source address of signup, sign-in and reset attempts, kept briefly (about fifteen minutes) to limit repeated attempts. Service logs at the hosting provider that include request metadata.
- Email delivery
- When the service emails you (address verification, password reset, a password-changed notice), the delivery outcome is recorded so a bouncing address is not written to again.
- Support
- What you write to support@conceptspace.app, kept in the support mailbox.
What is not collected
No analytics, advertising or tracking scripts, on this site or in the app. No cookies beyond the ones the service needs to work.
One exception, on three forms only: the contact form here, and the signup and forgot-password pages in the app, run Cloudflare Turnstile to tell people from automated abuse. It loads a script from Cloudflare and sends it signals about your browser; it does not identify you to us and we get back only pass or fail. Cloudflare's privacy policy covers what it keeps.
Cookies and local storage
Signing in sets one session cookie for the app, its API and its file service. Opening a shelf's files sets short-lived cookies that let the file service answer for that shelf. The app keeps a full copy of your shelf in your browser's storage on every device you use, so it works offline; signing out removes the app's session on that device, and only an explicit sign-out clears its local copy.
Who can see your writing
You, and the people you share a shelf with. The operator can technically access stored content, because sync merges edits on the server and the service is not end-to-end encrypted; the operator does not read it except to fix a specific problem you have reported, and does not disclose it unless the law requires.
Where it is hosted
The service runs on Amazon Web Services. Account data, notes and files are stored in the Asia Pacific (Singapore) region. The website, the app's static files and file downloads are served through Amazon's content delivery network, which caches them near you. Account emails are sent through Amazon SES. The support mailbox is hosted by Purelymail.
Deleting things
A note you trash is restorable until you delete it for good; a shelf you delete can be restored for 30 days and is then removed. Deleting content removes it from the service; copies in the service's operational backups age out on their own schedule, and copies other people made, such as a download or a shared reader's own device, are theirs.
To close your account, write to support@conceptspace.app from the account's address. The operator confirms the request with you, then removes the account and the shelves it owns; shelves you only read stay with their owners. Automatic account deletion from inside the app is not yet built.
Your rights
You can download everything you wrote at any time from inside the app. You can ask what the service holds about you, ask for it to be corrected, or ask for it to be deleted, by writing to support@conceptspace.app. Requests about a shared shelf are answered to its owner.
Changes
The version and date at the top change when this policy does, and a change that matters is announced in the app.