markdow
TermsPrivacyCookies

Privacy policy

What a hosted Markdow instance processes and why.

1. Controller

Pedro Piñera Buendía
Jessnerstrasse 27a, 10247 Berlin, Germany
Email: [email protected]

This notice covers the hosted instance operated by that provider. A person or organization running a self-hosted instance is responsible for its own deployment and privacy notice.

2. Data we process

  • Account data such as user identifiers, names, and email addresses.
  • Vault data, Markdown note bodies, frontmatter, tags, links, assets, and derived search records.
  • Authentication data such as claim email addresses, hashed credentials, access scopes, expiry times, and security events.
  • Technical data such as Internet Protocol addresses, request times, requested routes, response status, and in-memory abuse-prevention counters.
  • When audience measurement is enabled, anonymous page and named interaction events from the marketing page. No form values, account identifiers, note data, or credentials are attached to these events.

3. Purposes and legal bases

We process account and vault data to provide the service you request and to take steps connected with that service. We process security, request, and rate-limit data for our legitimate interests in protecting Markdow, preventing abuse, diagnosing failures, and keeping the service available. Where consent is legally required for a future feature, we will ask before enabling it.

4. Recipients and transfers

Infrastructure providers may process data only as needed to host the application, database, storage, network, mail relay, and anonymous audience measurement. The marketing page may load smolanalytics from the operator's configured analytics host. The interactive documentation page downloads the Scalar library from jsDelivr; that request exposes the usual network and browser information to jsDelivr and its network providers.

Provider locations depend on the deployed infrastructure. If data is transferred outside the European Economic Area, the operator must use a lawful transfer mechanism and document it here.

5. Retention

Account and vault data are kept while the service is provided and then removed or anonymized when no longer needed, subject to backups, security needs, and legal retention duties. Expired or revoked authentication records and security events are retained only as long as needed for security and accountability. Local Hammer rate-limit counters are held in memory temporarily and are cleaned automatically. Hosting logs may have a separate short retention period set by the deployment operator.

6. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent without affecting earlier processing. You may also complain to a data protection supervisory authority, particularly in the European Union country of your residence, workplace, or the alleged infringement.

Send a request to [email protected]. We may need to verify that the request concerns your account.

7. Automated decisions

Markdow does not make decisions with legal or similarly significant effects through automated processing.

Effective 11 August 2026Return to Markdow