Privacy

Last updated September 21, 2026

Who is responsible

Filed (filednotes.com) is the controller for the personal data described on this page. Operator: Alexander Nordin Davidsson (sole trader), Sweden.

The short version

Your notes are stored as plain markdown files in your own vault. We don't sell data, we don't run ads, and you can export or permanently delete everything yourself, at any time. The rest of this page explains exactly what is stored where and who processes what.

What we store

Website performance analytics

We use Cloudflare Web Analytics and Real User Measurements to understand page views and whether Filed loads quickly and reliably. Cloudflare's beacon reads temporary browser performance measurements, does not use cookies or browser storage, and does not store visitors' IP addresses in its analytics databases. We use this information to improve the app, not to build advertising profiles.

AI processing

Filed's whole job is a librarian that files and answers from your notes, so your journal text and questions are sent to the AI providers that power this:

Send only what you're comfortable having processed by these services. We don't use your notes to train anything, and we don't share them with anyone else.

Getting your data out — or gone

Retention

Notes and versions live until you delete them. Deleted notes move to a trash folder and are purged after 30 days. Deleting your account erases the vault and index. Sessions and verification records are kept until they expire. Minimal billing records (plan, Stripe ids, invoice status — no note content) are kept for seven years, as accounting law requires.

Your rights (GDPR)

If you are in the EU/EEA (or anywhere similar rights apply), you can, free of charge:

Legal bases, briefly: providing the app you signed up for (contract); keeping the service secure and understanding page performance (legitimate interest); sending transactional email (contract). We don't profile you or make automated decisions about you.

Where a provider processes data outside the EU/EEA — primarily the United States — we rely on the EU–US Data Privacy Framework where the provider is certified, and contractual safeguards otherwise. Each provider above is engaged under a data-processing agreement and handles data only on our instructions. The current list of processors and sub-processors is available from privacy@filednotes.com.

Contact

Questions or requests: support@filednotes.com (privacy matters: privacy@filednotes.com).