Privacy Policy
Effective date: September 12, 2026
Zabulan LLC ("we", "us", "our") operates the zabnotes.com website and application. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
Account Information
When you register, we collect your email address and a hashed password. We never store your password in plain text. You may optionally upload a profile avatar.
Notes & Content
We store the content you create — notes, kanban boards, mind maps, drawings, charts, plans and calendar events. All of it is encrypted on your device before it reaches us, including titles. What we hold is ciphertext. See section 2 for exactly what that does and does not cover.
Account Encryption
Every workspace in Zab Notes is end-to-end encrypted. This is not an optional vault you switch on for selected notes — it covers notes, kanban boards, mind maps, drawings, charts, the project planner and calendar events, titles included.
- Content is encrypted in your browser with XChaCha20-Poly1305 (IETF) before it is sent to us.
- Your password is never transmitted. It is put through Argon2id key derivation on your device, and only a derived value is sent, which we then hash again with bcrypt. We never see the password you type.
- A random account key encrypts your content. We store it only in wrapped form — once under a key derived from your password, once under your recovery key.
- At sign-up you are shown a 24-word recovery key, once. It is the only way back in if you forget your password.
- We cannot read, decrypt, or recover your content, and there is no password reset that restores it. If you lose both your password and your recovery words, your library is permanently unreadable — by you, by us, or by anyone who compels us.
What encryption does not cover: your email address, account and billing records, when you sign in, how much you store and when it changed, and your folder and tag structure. Files you upload — images and audio — are stored as uploaded and are not covered by the content encryption above. The older per-note vault remains available as an optional second lock on individual notes.
Activity Data
We log user actions (e.g., creating, editing, or deleting items) to power the dashboard activity heatmap and recent activity feed. Duplicate actions within 5 minutes are throttled.
File Uploads
Uploaded files (images, audio recordings, avatars) are stored in user-specific directories and are accessible only to the authenticated user who uploaded them. Unlike your notes, uploaded files are stored as uploaded and are not end-to-end encrypted.
Version History
We keep previous versions of your notes so you can restore earlier drafts, up to 150 versions per note, after which the oldest are pruned. Versions are encrypted exactly as the note itself is.
Diagnostic Records
When you submit a support ticket, we record the IP address and browser user-agent with it. If the application hits an error, our error log may record the error, the page URL, your email address, your IP address and your user-agent so we can diagnose it. We do not record IP addresses or user-agents at account creation.
2. How We Use Your Information
- Provide the service — store, sync, and display your notes and content across your devices
- Authentication — verify your identity when you log in
- Two-Factor Authentication — send one-time verification codes to your email when unlocking a vault-locked note
- Activity features — power the dashboard heatmap, recent activity, and calendar views
- Theme & settings — remember your preferences across sessions
3. Cookies & Sessions
We use a session cookie to keep you logged in. This cookie contains only a session identifier — no personal data. We also store UI preferences (panel widths, folder collapse states) in your browser's localStorage. We do not use third-party tracking cookies or analytics services.
4. Third-Party Services
- Hostinger — hosting, database and outbound email for this service, and DNS for our domains.
- Cloudflare — R2 object storage only: media you upload, and off-site copies of our nightly database backups, which are encrypted before they leave our server. Cloudflare does not provide our DNS and no traffic is proxied through it.
- Stripe — payment processing, if and when paid plans are enabled. Card details go directly to Stripe and never reach our servers.
- GitHub — source code hosting and automated deployment.
- Google Fonts — We load fonts from
fonts.googleapis.com. Google may log font requests per their Privacy Policy. - CDN Libraries — JavaScript libraries loaded from
cdn.jsdelivr.net,cdnjs.cloudflare.comandcdn.quilljs.com. These providers receive your IP address and browser details when your browser fetches those files, as any third-party resource does. They are not used to track you.
5. Data Security
- All connections use HTTPS
- Passwords are hashed using bcrypt (12 salt rounds)
- CSRF protection on all API endpoints
- Rate limiting on login and registration
- Content Security Policy (CSP) headers
- All content encrypted on your device with XChaCha20-Poly1305 (IETF), keys derived with Argon2id
- Nightly database backups encrypted with AES-256-GCM before they are written, and verified by decrypting them
- Server access by SSH key only; password authentication is disabled
6. Administrative Access
Designated administrators may view limited account metadata for the purpose of customer support, billing, security, and abuse prevention. Specifically, administrators may see:
- Your username, email address, and account creation date
- Your subscription status and trial dates
- Your last-active timestamp and a derived "online" indicator (active in the last 5 minutes)
- Aggregate counts of items you've created (number of notes, mind maps, drawings, etc.) — never the items themselves
- Total storage used by your notes (size in bytes of the stored ciphertext), without access to the contents
- Aggregate activity statistics, including how often and at what hours you use the app
- The IP address and user-agent recorded when you submit a support ticket, and those recorded in our error log if the application faults while you are using it
Administrators cannot view note titles, note contents, search terms, or specific items you are working on. This is not a policy promise — it is a property of the system: your content is encrypted on your device and we hold no key that can decrypt it, so even an administrator with full database access sees only ciphertext. Uploaded files are the exception: they are not end-to-end encrypted, and an administrator with server access could open them.
All administrative access actions are recorded in an internal audit log with timestamp, the administrator's identity, and the nature of the access. If you wish to know what administrative access has occurred against your account, contact contact@zabulan.com.
7. Data Retention
Your data is retained as long as your account is active. Deleted notes are soft-deleted (moved to Trash) and can be restored. Permanently deleting a note removes it from the database.
Account deletion is handled on request — email us and we will remove your data from active systems within 30 days. It then ages out of our encrypted backups within approximately six months, on a 7-daily / 4-weekly / 6-monthly retention cycle. There is no self-service delete button yet; building one is on our roadmap, and until it exists a request by email is the way.
8. Your Rights
- Access & Export — Export any note as HTML, Markdown or PDF. The Local Folder feature mirrors your whole library to a folder on your own computer — every note as
.htmland.md, every board, map, drawing and chart as.json, plus a complete_library.json, all written in readable form - Correction — Edit your content and profile at any time
- Deletion — Delete individual notes, or request full account deletion by email (section 7)
- Disconnect — Disconnect third-party integrations at any time
9. Children's Privacy
Zab Notes is not directed at children under 13, and we do not knowingly collect information from children under 13. You must be at least 13 to create an account. If you are between 13 and 18, you may use Zab Notes only with the involvement and consent of a parent or guardian. If you believe a child under 13 has provided us personal information, contact contact@zabulan.com and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
11. Contact
Questions about this Privacy Policy:
contact@zabulan.com