Privacy Policy
Last updated: August 2026 · Notedigit is operated by Well Digit ("we", "us").
What we collect
Account data: your name, email address, and password hash, plus two-factor and passkey credentials if you set them up. Team data: team name, member roles, invitations, and per-repository user assignments. Repository configuration: repository names, SSH URLs, branch names, and deploy keys. Billing data is handled by Paddle, our payment processor; we do not store card details.
Audit data: for every MCP session and tool call we record the client, the authenticated user, IP address, tool name, arguments, status, and duration. This log exists so repository owners can see exactly what an AI assistant read.
What we deliberately do not keep
Your note content is not stored on our servers. Repositories are cloned on demand as bare, shallow mirrors for the duration of use and pruned after idle minutes; no copy is held between sessions. Product telemetry that would carry search queries or note paths is disabled.
How we protect what we do keep
Repository names, git URLs, deploy keys, connection-error output, and audit-log arguments are encrypted at rest under two independent keys, so a database copy alone cannot read them. Private SSH keys are never displayed after generation. In the default deployment, keys are passed in-memory per operation; self-hosted fallback mode writes keys transiently to RAM-backed storage only. Access to a repository over MCP requires OAuth 2.1 sign-in and an explicit per-user assignment, and requests are rate-limited per token and IP.
How we use your data
To operate the service: authenticate you and your MCP clients, serve your Markdown repositories, show your team its audit trail, and manage the subscription. We do not sell personal data and we do not use your notes or audit logs to train models.
Third parties
Paddle processes payments as merchant of record. Your git host is contacted only with the deploy key you attached, to clone the repository you configured. MCP clients such as Claude receive the note content they request through the repository's read-only tools; their handling of that content is governed by their own policies.
Retention and deletion
If your trial ends or you cancel, the account soft-locks and your configuration and audit data are kept so reactivation restores everything. To delete your account and its data, contact us at contact@welldigit.com.
Contact
Questions about this policy: contact@welldigit.com.