Privacy Policy for Poznote

Last updated: July 24, 2026

Introduction

Poznote is a self-hosted, open-source note-taking application. This Privacy Policy explains how information is handled when you sign in to a Poznote instance using Sign in with Google (Google OIDC / OAuth 2.0).

Because Poznote is self-hosted, each instance is operated independently by the person or organization that installed it (the "instance operator"). This policy describes the data practices of the Poznote software itself. The instance operator is the data controller for your data.

Information We Access Through Google Sign-In

When you choose to sign in with Google, Google shares a limited set of information with the Poznote instance:

Poznote requests only the minimum scopes needed to authenticate you (openid, email, and profile). Poznote does not request access to your Gmail, Google Drive, contacts, calendar, or any other Google service.

How This Information Is Used

The information obtained through Google Sign-In is used solely to:

Poznote does not use this information for advertising, profiling, or marketing, and does not sell or share it with third parties.

Where Your Data Is Stored

All data, including your account information and your notes, is stored on the server operated by the instance operator. Poznote is self-hosted, so no data is sent to the Poznote project maintainers or any centralized Poznote service.

Your authentication data is exchanged directly between your browser, Google, and the Poznote instance you are connecting to.

Data Retention

Your account and associated data are retained for as long as your account exists on the instance. You may request deletion of your account and data by contacting the operator of the instance you use.

Data Sharing

Poznote does not share your personal information with third parties, except:

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. Because Poznote is self-hosted, these requests should be directed to the operator of the specific instance you use.

Security

Poznote uses standard OAuth 2.0 / OpenID Connect protocols for authentication. Instance operators are responsible for securing their own servers, including the use of HTTPS and appropriate access controls.

Changes to This Policy

This Privacy Policy may be updated from time to time. The "Last updated" date at the top of this page reflects the most recent revision.

Contact

For questions about this Privacy Policy or the Poznote project, please visit the project repository: github.com/timothepoznanski/poznote or contact us at tim.poznanski@gmail.com

For questions about a specific Poznote instance and your data on it, please contact that instance's operator.