Privacy Policy
We store your notes so they can reach your other devices. We can read them. We don’t.
That is the whole of it, and the rest of this page is detail. We would rather say it plainly than write something that sounds stronger and turns out, on inspection, to mean less.
Why there is an account at all
CoreNotes used to work with no account, keeping everything in one browser. That was a good promise and a bad experience: switch laptops and your notes were stranded, clear your browsing data and they were gone for good.
So there is an account now. Signing in is what tells us which notes are yours.
We looked hard at locking your notes with a passphrase only you knew, so that we could not read them even if we wanted to. We built it, and then took it out. It meant a second secret on top of your login, re-entered every session, with no way to recover it — and a student who loses it loses everything, with nobody able to help. The protection was real; the cost was a product people would get locked out of. We decided honesty about a simpler design beats a stronger claim that people trip over.
If that trade is not one you want, Settings → Your data → Download a backup gives you a copy that is yours alone, at any time, in a plain format nothing locks you out of.
What we hold
| We hold | Why |
|---|---|
| Your email address | So we know which notes are yours, and can reach you if something breaks |
| Which provider you signed in with | Same |
| Your notes, notebooks, cues, summaries and tags | So they can reach your other devices |
| Your vocabulary, review dates and schedule | Same |
| When each was last changed | It is how two devices work out which copy is newer |
We do not sell it, share it, publish it, or train anything on it. There is no advertising and no tracking anywhere in the product.
What we don’t collect
Nothing beyond the above. No analytics, no telemetry, no error reporting, no tracking cookies, no third-party scripts — on the app or on this site. That has never been true of CoreNotes and never will be.
One cookie is set when you sign in: a session cookie that says you are you. It is HttpOnly, it is not readable by scripts, and it is not used to follow you anywhere.
The only other outbound request either the app or this site makes is for fonts, from Bunny Fonts — a GDPR-compliant host that logs no IP addresses and sets no cookies.
Your notes are still on your device
This has not changed and is not a detail. Every note is written to your browser first and syncs afterwards, which is why CoreNotes keeps working on a bad school connection, on a train, or on a plane. The server is where your notes go so that your other devices can have them — it is not where they live while you work.
On a shared or school computer
Signing out syncs your notes and then clears them from that machine. If you sign in as someone else, the previous account’s notes are removed before the app opens. Neither of these is optional, because a notes app that leaves your coursework in a school browser is not doing its job.
Deleting everything
Account → Delete my account removes your notes and your email address from the server for good, and clears the device you are on. It is immediate and it cannot be undone, so take a backup first if you want to keep anything.
You do not have to ask us, and you do not have to explain why.
What is stored on your device
| Store | What it holds |
|---|---|
groups, notebooks, noteGroups |
Your library structure — names, ordering, pinning |
notes |
Note titles, cues, body text, summaries and tags |
vocab |
Vocabulary entries and the notes they came from |
reviews |
Spaced-review due dates and progress, per note |
schedule |
Weekly planner blocks and their recurrence rules |
settings |
Your preferences — theme, fonts, sizes, layout. These stay on the device and are not synced |
log, auditLog |
Your own edit history, which is what undo and Activity Log read. Not synced |
Service Worker
The app installs a service worker so it works offline. It stores copies of app files — and, since it also covers this site, copies of a handful of pages here including this one — in your browser’s cache. Code and pages only: it never reads, copies or transmits your notes.
Where it runs
Cloudflare Pages serves the site; a Cloudflare Worker and a D1 database hold your account. Cloudflare processes data on our behalf and does not use it for anything else.
Contact
If you have questions, open an issue on the project repository.
Last updated: August 2026.