Privacy policy

Last updated: September 18, 2026

The short version

littlenote is built to know as little about you as possible. We never ask for your email address, phone number, or real name. Your address book is encrypted before it reaches our database. There are no ads, no analytics trackers, and no third parties receiving your data. You can export or permanently delete everything at any time.

Who is responsible

littlenote is an independently operated service. Every right this policy describes — accessing, exporting, and erasing your data — is built directly into the app, so you can exercise them yourself without contacting anyone. For anything else, signed-in users can reach us through the feature request form in the account menu.

Data we store

When you create an account:

  • Username and display name. Your only identifiers. We never collect an email address — the internal email field required by our authentication library is filled with a synthetic placeholder that cannot receive mail.
  • Password and recovery code. Stored only as one-way scrypt hashes. We cannot read either, which is also why a lost password can only be reset with your recovery code.
  • Plan information. Whether your account is on the Free or Pro plan.

When you use the app:

  • Your address book — the names, crypto addresses, and notes you save. These are encrypted with AES-256-GCM before they are written to the database; the database never contains them in readable form.
  • Tags you create (tag names and colors), and which addresses they are attached to.
  • Share links you create: the link token, its expiry, and which fields you chose to make visible.
  • Feature requests you submit, encrypted at rest like your address book.
  • Session data — a session record including your IP address and browser user-agent string, kept for security and expired after 7 days.
  • Rate-limiting counters — short-lived per-IP counters that protect sign-in and account recovery against brute-force attacks.

We do not process payments today, so no payment data is collected.

What we use it for

Only to run littlenote: authenticating you, storing and serving your address book, enforcing plan limits, keeping the service secure, and reading the feedback you send us. Where the GDPR applies, our legal bases are performance of a contract (providing the service you signed up for) and legitimate interests (keeping the service secure). We do not sell data, show ads, build profiles, or share data with third parties. We disclose data only if legally compelled to — and because your address book is encrypted and we hold no email or real name, there is very little to disclose.

Cookies

littlenote sets exactly one cookie: a first-party, HttpOnly session cookie that keeps you signed in. There are no analytics, advertising, or third-party cookies.

Share links

When you create a share link, the fields you opted into (always the address and its chain; optionally its name, tags, and notes) become visible to anyone who has the link, until it expires or is deleted. Share links use unguessable random tokens, are excluded from search engines, and are revoked automatically when you delete the address or your account.

Where your data lives

All data is stored on our own server infrastructure — no third-party analytics, storage, or processing services are involved. Connections are encrypted with TLS, and address-book contents are additionally encrypted at rest.

Retention and deletion

Your data is kept for as long as your account exists. Sessions expire after 7 days; rate-limiting counters are overwritten within minutes; expired share links are deleted when accessed. You can export your full address book as CSV or JSON from Settings at any time. Deleting your account (Settings → Danger zone) permanently and immediately erases your profile and every saved address, tag, note, share link, and feature request — in line with the GDPR's right to erasure. There is no grace period and no soft delete.

Your rights

Where the GDPR or similar laws apply, you have the right to access, correct, export, and erase your data, to restrict or object to processing, and to lodge a complaint with a supervisory authority. Access, export, and erasure are built into the app itself; for anything else, reach us through the feature request form.

Changes

If we change this policy, we will update this page and the date at the top. Material changes will be announced in the app.