Privacy policy
Last updated: September 14, 2026.
Who operates MagNotes?
MagNotes is published by Adrian Guichard, reachable at contact@adrianguichard.dev. The service uses dedicated server infrastructure with a MongoDB database and Firebase Hosting (Google) for public static pages.
What data is collected?
- Account: email address and password. The password is never stored in plain text, only as a hash.
- Your content: boards, cards, checklists, connections, and images you add.
- Feedback: messages sent through the app's feedback form are associated with your account.
- Session: a technical HttpOnly cookie used to keep you signed in, not an advertising cookie.
- Technical logs: IP address and request timestamps retained briefly for security and abuse prevention, without creating a marketing profile.
Audience measurement
MagNotes uses self-hosted Umami analytics without cookies and
with IP anonymisation. It is active on the landing page, in the
application (/app/) and template gallery
(/templates/). No analytics data is shared with an
advertising provider.
Why is this data used?
- To create and secure your account.
- To send service emails: address verification, password reset, and due-card reminders only when you explicitly enable them.
- To understand and address feedback you submit.
- To prevent abuse through request rate limiting.
Who receives this data?
Your data is neither sold nor purchased. Two technical providers have limited access solely to operate the service:
- Brevo: transactional email delivery.
- Firebase Hosting (Google): hosting of the public static pages and application code. Board content remains on our own server.
How long is data retained?
- While your account exists, unless you delete it.
- Accounts that are created but never verified by email are automatically removed after a few days.
- Encrypted database backups are retained for 14 days.
Your rights
From the application menu, you can at any time:
- Export all your data as JSON.
- Permanently delete your account and all associated data after confirming your password.
For any other access, correction, or objection request, email contact@adrianguichard.dev.
Changes to this policy
If this policy changes significantly, the update date at the top of this page will be changed.