Privacy policy
Effective 2026-09-12.
The short version: Mimir keeps your notes on your device. If you turn on Cloud Sync, your notes are encrypted before they leave your device, and I can’t read them. I don’t run ads, don’t use analytics or tracking, and don’t sell or share your notes with anyone. The rest of this page says exactly what that means, and names every third party involved so there’s nothing left to discover later.
Mimir is built and run by one person, Geffrey van der Bos, based in the Netherlands. Email geffrey@justmimir.com for anything this page doesn’t answer.
What stays on your device
Mimir stores your notes in a database on your own device. See Where your notes live for the exact location on each platform. That database never leaves your device unless you turn on Cloud Sync or publish a page — both are things you choose to do, not things that happen by default.
I don’t run analytics, don’t track how you use the app, and Mimir doesn’t contact any server on a normal day of writing notes.
Cloud Sync (optional, paid)
Turning on Cloud Sync gives you eight words, as described in Turning on Cloud Sync. There’s no email address, no password, and no account beyond those eight words.
Those eight words derive an encryption key on your device. Every note is encrypted with that key before it’s sent anywhere. The server that relays your notes between your devices can see when an edit happened and roughly what it touched — the ids of the affected notes, which note sits under which, and their order — but never the words you wrote or a note’s title. That’s not a policy choice I could reverse: the server is never given the key needed to read it.
If you lose the eight words and don’t have a device still signed in, nobody — including me — can recover your notes from the cloud. A device that already has the notes keeps them regardless.
Cloudflare, whose network routes the encrypted connection to that server, sees the IP address and timing of your connection, since it has to in order to deliver the traffic. It never sees the traffic’s content, because that’s already encrypted by the time it leaves your device. See Cloudflare’s privacy policy for what it does with that.
Publishing a page
Turning a page into a public link, described in Publishing a page, is a separate, explicit action from Cloud Sync. Once you publish a page, its content is readable by anyone with the link, in plain form — publishing takes it out of the encryption Cloud Sync otherwise gives it, because the point is for other people to read it.
Published pages aren’t submitted to search engines, and crawlers are asked to stay away, but I can’t guarantee no one else archives a page you’ve shared the link to. Unpublishing takes the page down. It can’t undo a copy someone else already made while it was up.
If someone has published something that shouldn’t be public, email abuse@justmimir.com.
Rich embeds
Turning on a rich embed for a pasted link, as described in Rich embeds, fetches a preview from that link’s provider — YouTube, Vimeo, and so on. That fetch happens only after you turn the embed on, and only once the block is close to being visible. It tells that provider that someone looked at that link, from that IP address, at that time. I never see it: the cache Mimir keeps for an embed stays on your device and is never part of Cloud Sync.
Some providers are recognized without a network request at all, using a list bundled with the app.
Crash diagnostics
If Mimir crashes, it writes a log to your device. That log stays there. Nothing is sent anywhere automatically. Getting it off the device — viewing it, exporting it, or emailing it to me — is something only you can choose to do, from the prompt Mimir shows after a crash.
Paying for Cloud Sync
Cloud Sync is bought through Polar, who acts as the seller for that purchase. I never see your card details. Polar collects what it needs to process the payment — billing email address and payment method — under Polar’s own privacy policy.
Mimir Highlighter
The browser extension copies the text you select to your clipboard, on your device. It doesn’t talk to any server, mine or anyone else’s.
What I don’t do
No ads. No ad trackers. No analytics SDK of any kind. I don’t sell, rent, or share your notes or any personal data with anyone, for any reason, and I don’t read your notes myself.
Deleting your data
Deleting the app and its local database removes everything stored on that device. To delete a Cloud Sync vault entirely, email support@justmimir.com from the address you used to buy Cloud Sync, or with your license key, and I’ll remove it. Deleting a vault stops it syncing everywhere — a device that already downloaded your notes keeps its own copy until you delete them there too.
Your rights
There’s no account and no profile to request access to beyond your notes themselves, which is already yours: Exporting your notes gives you everything, in full, any time, without asking. For anything held on the relay under Cloud Sync, email support@justmimir.com to ask what’s there or to have it deleted, and I’ll act on it directly — see “Deleting your data” above.
Children
Mimir isn’t directed at children, and I don’t knowingly collect information from anyone under 16.
Changes to this page
This page carries the date it last changed at the top. If it changes in a way that matters to how Cloud Sync or publishing works, that’ll be said plainly rather than quietly reworded.
Contact
geffrey@justmimir.com — general questions, answered personally. support@justmimir.com — account and data requests. abuse@justmimir.com — a published page that shouldn’t be public.
