Privacy Policy

Last updated: 2026-05-03

This Privacy Policy describes how Anotas.online ("we", "us") collects, uses and protects information when you use our website. By using the site, you agree to this policy. We have deliberately designed the service to handle the minimum amount of personal information possible. If you can use a calculator on a website without giving up data, you should be able to share a note the same way.

1. Information we collect

We are a no-account service. The only information we handle is:

  • Note content — the text you type into a note is stored in our database in plain text so it can be read back when you or your recipient open the link. If you set a password, the password itself is never stored: only a one-way bcrypt hash (cost 12) of it is kept, which means even we cannot recover or read it.
  • Technical data — when your browser makes a request to our servers, we receive your IP address, user agent, and request timestamp. We never store the IP in plain text: it is immediately hashed with SHA-256 and only the hash is recorded, used exclusively for rate limiting and abuse prevention. The hash cannot be reversed to identify you.
  • Cookies — see our Cookie Policy for the complete list. We use a small set of cookies: one for language preference (set by our site) and a few set by Google AdSense on public pages only. Note-reading and note-editing pages do not display ads and do not set advertising cookies.

2. What we DO NOT collect

  • We do not require — or even ask for — an email address.
  • We do not require a phone number or any other identifier.
  • We do not link your notes to a profile, a user ID, or a browser fingerprint.
  • We do not sell your data. There is no data product to sell because we have not built a profile of you in the first place.

3. Advertising

We show ads on public-facing pages (homepage, blog, the About/Contact/Privacy/Cookies pages) using Google AdSense to keep the service free for everyone. Ads are NEVER shown on the note-creation, note-locked, or note-reading pages — those flows are completely ad-free. Google may use cookies to personalize ads based on your interests across the web. You can opt out of personalized ads at https://adssettings.google.com and learn more about Google's data practices at https://policies.google.com/technologies/ads.

4. Children

Anotas.online is not directed to children under 13 and we do not knowingly collect information from them. If you are a parent or guardian and believe a child under 13 has used the service, contact us at privacy@anotas.online and we will promptly remove their content. Because we have no account system, no email and no profile of any user, we cannot proactively identify the age of someone using the service.

5. Data retention

Notes are retained until they are deleted or until they have been inactive for a long period of time (one year). Rate-limit records (hashed IPs) are automatically deleted after two hours. If you delete a note manually, it is removed immediately from our active database; backups are rotated every few weeks. We do not keep any logs of the content of deleted notes.

6. Your rights

Depending on your jurisdiction (GDPR in Europe, CCPA in California, similar laws elsewhere), you have rights including access to your data, correction, deletion, portability, and the right to lodge a complaint with a supervisory authority. Because we do not maintain accounts, exercising these rights is straightforward: you can delete a note directly using the editor (if you remember the password), or contact us at privacy@anotas.online with the slug of your note and we will help. We do not have a way to identify "all your notes" because we have no concept of "you" as a user — we only know individual notes by slug.

7. Contact

For privacy questions, data deletion requests, or any other privacy-related concern, write to privacy@anotas.online. We typically reply within 2-3 business days.