---
title: "Privacy policy"
---

Effective 2026-09-12.

**The short version:** Mimir keeps your notes on your device. If you turn
on Cloud Sync, your notes are encrypted before they leave your device, and
I can't read them. I don't run ads, don't use analytics or tracking, and
don't sell or share your notes with anyone. The rest of this page says
exactly what that means, and names every third party involved so there's
nothing left to discover later.

Mimir is built and run by one person, Geffrey van der Bos, based in the
Netherlands. Email [geffrey@justmimir.com](mailto:geffrey@justmimir.com)
for anything this page doesn't answer.

## What stays on your device

Mimir stores your notes in a database on your own device. See
[Where your notes live](/where-your-notes-live) for the
exact location on each platform. That database never leaves your device
unless you turn on Cloud Sync or publish a page — both are things you
choose to do, not things that happen by default.

I don't run analytics, don't track how you use the app, and Mimir doesn't
contact any server on a normal day of writing notes.

## Cloud Sync (optional, paid)

Turning on Cloud Sync gives you eight words, as described in
[Turning on Cloud Sync](/sync-across-devices#turning-on-cloud-sync). There's
no email address, no password, and no account beyond those eight words.

Those eight words derive an encryption key on your device. Every note is
encrypted with that key before it's sent anywhere. The server that relays
your notes between your devices can see when an edit happened and roughly
what it touched — the ids of the affected notes, which note sits under
which, and their order — but never the words you wrote or a note's title.
That's not a policy choice I could reverse: the server is never given the
key needed to read it.

If you lose the eight words and don't have a device still signed in,
nobody — including me — can recover your notes from the cloud. A device
that already has the notes keeps them regardless.

Cloudflare, whose network routes the encrypted connection to that server,
sees the IP address and timing of your connection, since it has to in
order to deliver the traffic. It never sees the traffic's content, because
that's already encrypted by the time it leaves your device. See
[Cloudflare's privacy policy](https://www.cloudflare.com/privacypolicy/)
for what it does with that.

## Publishing a page

Turning a page into a public link, described in
[Publishing a page](/publishing-a-page), is a separate, explicit action
from Cloud Sync. Once you publish
a page, its content is readable by anyone with the link, in plain form —
publishing takes it out of the encryption Cloud Sync otherwise gives it,
because the point is for other people to read it.

Published pages aren't submitted to search engines, and crawlers are asked
to stay away, but I can't guarantee no one else archives a page you've
shared the link to. Unpublishing takes the page down. It can't undo a copy
someone else already made while it was up.

If someone has published something that shouldn't be public, email
[abuse@justmimir.com](mailto:abuse@justmimir.com).

## Rich embeds

Turning on a rich embed for a pasted link, as described in
[Rich embeds](/rich-embeds), fetches a preview from that link's provider —
YouTube, Vimeo, and so on. That fetch happens only after you turn the
embed on, and only once the block is close to being visible. It tells that
provider that someone looked at that link, from that IP address, at that
time. I never see it: the cache Mimir keeps for an embed stays on your
device and is never part of Cloud Sync.

Some providers are recognized without a network request at all, using a
list bundled with the app.

## Crash diagnostics

If Mimir crashes, it writes a log to your device. That log stays there.
Nothing is sent anywhere automatically. Getting it off the device — viewing
it, exporting it, or emailing it to me — is something only you can choose
to do, from the prompt Mimir shows after a crash.

## Paying for Cloud Sync

Cloud Sync is bought through [Polar](https://polar.sh), who acts as the
seller for that purchase. I never see your card details. Polar collects
what it needs to process the payment — billing email address and payment
method — under
[Polar's own privacy policy](https://polar.sh/legal/privacy).

## Mimir Highlighter

The browser extension copies the text you select to your clipboard, on
your device. It doesn't talk to any server, mine or anyone else's.

## What I don't do

No ads. No ad trackers. No analytics SDK of any kind. I don't sell, rent,
or share your notes or any personal data with anyone, for any reason, and
I don't read your notes myself.

## Deleting your data

Deleting the app and its local database removes everything stored on that
device. To delete a Cloud Sync vault entirely, email
[support@justmimir.com](mailto:support@justmimir.com) from the address you
used to buy Cloud Sync, or with your license key, and I'll remove it.
Deleting a vault stops it syncing everywhere — a device that already
downloaded your notes keeps its own copy until you delete them there too.

## Your rights

There's no account and no profile to request access to beyond your notes
themselves, which is already yours: [Exporting your notes](/exporting-your-notes)
gives you everything, in full, any time, without asking. For anything held
on the relay under Cloud Sync, email
[support@justmimir.com](mailto:support@justmimir.com) to ask what's there
or to have it deleted, and I'll act on it directly — see "Deleting your
data" above.

## Children

Mimir isn't directed at children, and I don't knowingly collect
information from anyone under 16.

## Changes to this page

This page carries the date it last changed at the top. If it changes in a
way that matters to how Cloud Sync or publishing works, that'll be said
plainly rather than quietly reworded.

## Contact

[geffrey@justmimir.com](mailto:geffrey@justmimir.com) — general questions,
answered personally.
[support@justmimir.com](mailto:support@justmimir.com) — account and data
requests.
[abuse@justmimir.com](mailto:abuse@justmimir.com) — a published page that
shouldn't be public.
