Privacy Policy
Last updated: May 24, 2026
1. Who we are
MarkdownHQ (“we”, “our”, “us”) is a self-hosted collaborative Markdown workspace operated by Vincent Kindermann, based in the Netherlands. You can reach us at privacy@vinz4it.nl.
2. What data we collect
When you create an account and use MarkdownHQ we collect and store:
- •Account data: your email address, display name, and (optionally) a profile avatar.
- •Authentication data: a hashed password (argon2) or OAuth provider identifiers (Google, GitHub, Microsoft). We never store your plaintext password or OAuth tokens beyond what is necessary for authentication.
- •Workspace & note content: all notes, folder structures, attachments, and version history you create inside the application.
- •Billing data: if you subscribe to a paid plan, your payment is processed by Stripe. We store a Stripe customer ID and subscription status only. We never handle or store full card numbers.
- •AI API keys: if you add your own OpenAI, Anthropic, or Groq API key, it is encrypted at rest using AES-256-GCM. We never transmit your API key to any third party other than the AI provider you select when making a request.
- •Usage & technical data: server logs (IP address, request path, timestamp) retained for up to 30 days for security and debugging purposes.
3. How we use your data
We use your data only to:
- •Provide and improve the MarkdownHQ service.
- •Send transactional emails (account verification, password resets, workspace invites, payment receipts).
- •Enforce plan limits and process subscription billing via Stripe.
- •Detect and prevent abuse, fraud, and security incidents.
We do not sell your data to third parties, use your note content to train AI models, or send marketing emails without your explicit consent.
4. Data storage & location
MarkdownHQ is self-hosted on servers located in the Netherlands (EU). All data — including your notes, attachments, and account information — is stored within the EU. File attachments are stored in a private MinIO object store; objects are never publicly accessible and are served only via short-lived authenticated presigned URLs.
5. Third-party processors
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing & subscription management | Email, name, billing address, payment instrument |
| SMTP relay (configured by operator) | Transactional email delivery | Email address, name |
| OpenAI / Anthropic / Groq (optional) | AI features (only when you actively use them) | Note content sent in the request |
6. Cookies
We use a single session cookie (httpOnly, Secure, SameSite=Lax) to keep you logged in. No advertising or analytics cookies are set. The cookie consent banner allows you to decline non-essential cookies; functional session cookies are always required for the app to work.
7. Your rights (GDPR)
As a user in the EU you have the following rights under GDPR:
- •Access: Request a copy of all data we hold about you.
- •Portability (Art. 20): Download your notes as a Markdown ZIP archive from Workspace Settings → Export.
- •Rectification: Update your name or email from Account Settings → Profile.
- •Erasure: Delete your account from Account Settings → Danger Zone. All personal data is wiped within 30 days.
- •Objection: Contact us at privacy@vinz4it.nl.
8. Data retention
- •Active accounts: data retained while your account exists.
- •Soft-deleted notes: permanently purged after 7 days (Free), 30 days (Pro), or 90 days (Team).
- •Deleted accounts: all personal data purged within 30 days; anonymised audit records may be retained for legal compliance.
- •Server logs: retained for 30 days then automatically deleted.
9. Security
We protect your data with TLS in transit, argon2 password hashing, AES-256-GCM encryption for API keys, private (non-public) MinIO object storage, JWT expiry of 15 minutes, and httpOnly refresh cookies. Despite these measures, no system is 100% secure. Please report security vulnerabilities to security@vinz4it.nl.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the “Last updated” date above and, for material changes, notify you by email or an in-app announcement banner.
11. Contact
Questions about this policy? Email us at privacy@vinz4it.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).