Privacy Policy
Last updated: September 21, 2026 · Applies to https://piratebots.in/notepad-x
LiveNote is built to forget you as much as a shared notepad allows. This policy explains, in plain language, what is stored, what is never read, and how to get anything deleted. Fields marked […_REQUIRED] are placeholders for real-world details the operator must fill in — none are invented.
1. What we store
- Notes you create — titles, content, and files you upload. Signed-in notes are linked to your account; anonymous notes are linked only to a random cookie in your browser.
- Account data (optional) — email address, display name, avatar, hashed password, and optionally a two-factor secret if you enable 2FA.
- Security metadata — salted hashes of IP addresses and user-agent strings, kept only to rate-limit abuse and show you your own login activity. Raw IP addresses of ordinary browsing are not stored long-term.
- Operational data — share links and their settings, and audit-log entries required to run and secure the service.
2. End-to-end encrypted notes
A note locked with end-to-end encryption is encrypted in your browser (AES-256-GCM with a key derived from your passphrase). The server stores only ciphertext and cannot read these notes — not us, not anyone who compels us. The flip side is honest: lose the passphrase and the content is unrecoverable, by anyone.
3. AI features and third-party processors
LiveNote uses a small number of third parties, each doing one job:
- AI features (optional) — when you explicitly invoke an AI action (summarize, rewrite, translate…), the selected note text is sent to our AI provider (Z.ai, GLM models) to generate the result. Nothing is sent unless you invoke an action. Avoid AI features on notes you would not hand to that provider.
- Image hosting — uploaded images are stored on our image host (PixEdge) and served from it. Deleting a note deletes its images.
- GIF search — GIF picks are re-hosted through our image pipeline; your searches go through our server, and the GIF provider’s key never touches your browser.
- Google sign-in (optional) — if you use it, Google shares your email, name, and avatar with us. Google also receives the fact that you signed in, under its own privacy policy.
No other third parties receive your note content.
4. Cookies and local storage
LiveNote sets strictly necessary cookies only — no analytics trackers, no cross-site advertising cookies of our own. Everything below is required for the feature it serves:
| Cookie | Purpose | Why |
|---|---|---|
| nx_owner | Links your anonymous notes to your browser so only you can edit them. | Needed for anonymous notes to work |
| nx_session | Keeps you signed in (if you sign in). | Needed for accounts |
| nx_csrf | Protects state-changing requests against cross-site request forgery. | Needed for security |
| nx-viewer-name | The display name you type once for live presence on shared pages. | Needed for the collaboration feature |
| nx-unlock:<note> | Marks a password-protected note as unlocked so you are not re-prompted every visit. | Needed for password gates |
| nx_oauth_state | One-time state token during Google sign-in. | Needed for sign-in security |
Local storage on your device keeps your theme choice and an anonymous presence identifier that never leaves your browser’s relationship with the notes you already have open. You can clear both any time in your browser settings.
5. Analytics
LiveNote runs no third-party analytics. We look at aggregate server health (error rates, response times) to keep the service working, and note-level view counts that you can see yourself in each note’s analytics dialog. We do not build advertising or behavior profiles from your notes.
6. Advertising and Google AdSense
LiveNote may display advertisements served by Google AdSense to support the free service. When ads are active:
- Google and its partners may use cookies or device identifiers to serve and measure ads, subject to Google’s policies and your consent where required.
- Where consent is legally required (for example in the EEA/UK), Google’s certified consent management — available through AdSense’s Privacy & messaging tools — is used to collect it before personalized ads are served.
- You can opt out of personalized advertising in Google’s Ads Settings (adssettings.google.com) and via your device’s ad controls.
- Your note content is not used to target ads. Ads are confined to clearly labeled areas of the application shell — never inside the content of your notes.
7. Data retention and deletion
- Notes exist until you delete them (or until an expiry you set). Deletion is immediate and permanent, including shared links to that note.
- Version-history snapshots are deleted along with their note.
- Deleting your account (Settings → Danger zone) permanently removes your account record and your notes.
- Anonymous notes stay until deleted or until the expiry you set; a browser cookie loss makes them orphaned, and routine cleanup eventually removes abandoned notes.
- Hashed security metadata (rate limiting) rotates out on short windows.
8. Security
Passwords are hashed with argon2id. Traffic is served over HTTPS with modern security headers (CSP, HSTS). State-changing requests are CSRF-protected and rate-limited, and rich content is sanitized before it is stored. Encrypted notes are unreadable to us by design. No system is perfect; if you believe you have found a security issue, please report it via the contact page.
9. Your rights and choices
You can view, export, correct, and delete your notes at any time from the app. You can delete your account and its data from Settings. For anything else — a copy of your data, a deletion request for an account you lost access to, or a question about this policy — email us and we will help. If you are in the EEA/UK, you additionally have rights to object to or restrict processing and to lodge a complaint with your local data protection authority.
10. Children
LiveNote is not directed at children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.
11. Changes to this policy
The “last updated” date at the top changes whenever this policy does. Material changes (like advertising going live) will be reflected here before ad units ship.
12. Contact
Questions, deletion requests, and reports: email [email protected].
Operator: [LEGAL_NAME_REQUIRED], [COMPANY_ADDRESS_IF_APPLICABLE] (to be completed by the operator; no address is published because none applies today).