Privacy Policy
Last updated: August 2026 · Notedigit is operated by Well Digit ("we", "us").
What we collect
Account data: your name, email address, and password hash, plus two-factor and passkey credentials if you set them up. Team data: team name, member roles, invitations, and per-repository user assignments. Repository configuration: repository names, SSH URLs, branch names, and deploy keys. Billing data is handled by Paddle, our payment processor; we do not store card details.
Audit data: for every MCP session and tool call we record the client, the authenticated user, IP address, tool name, arguments, status, and duration. This log exists so repository owners can see exactly what an AI assistant read.
What we deliberately do not keep
Your note content is not stored on our servers. Repositories are cloned on demand as bare, shallow mirrors for the duration of use and pruned after idle minutes; no copy is held between sessions. Product telemetry that would carry search queries or note paths is disabled.
How we protect what we do keep
Repository names, git URLs, deploy keys, and connection-error output are encrypted at rest. Private SSH keys are never displayed after generation and never written to temporary files; they are passed to git in-memory per operation. Access to a repository over MCP requires OAuth 2.1 sign-in and an explicit per-user assignment, and requests are rate-limited per token and IP.
How we use your data
To operate the service: authenticate you and your MCP clients, serve your Markdown repositories, show your team its audit trail, and manage the subscription. We do not sell personal data and we do not use your notes or audit logs to train models.
Third parties
Paddle processes payments as merchant of record. Your git host is contacted only with the deploy key you attached, to clone the repository you configured. MCP clients such as Claude receive the note content they request through the repository's read-only tools; their handling of that content is governed by their own policies.
Retention and deletion
If your trial ends or you cancel, the account soft-locks and your configuration and audit data are kept so reactivation restores everything. To delete your account and its data, contact us at contact@welldigit.com.
Contact
Questions about this policy: contact@welldigit.com.