1.Overview
This Privacy Policy explains what information Markdown Writer (“we”, “us”) collects when you use markdownwriter.com and related services (the “Service”), how we use it, and the choices you have. It applies alongside our Terms of Service.
The design principle is simple: the editor works without an account and keeps your writing on your device. We only receive your documents if you turn on sync, upload images, or publish something.
2.Data that stays in your browser
When you use the editor without signing in, your documents, settings and editor state are stored locally in your browser (IndexedDB and localStorage). They are not transmitted to us. Clearing your browser data deletes them, so export anything important.
The conversion tools (Markdown to HTML, PDF, DOCX, and so on) run in your browser. The files you convert are not uploaded to our servers.
3.Information we collect
Account information. When you sign in with GitHub, Google or Microsoft, we receive your name, email address, profile picture URL and the provider’s account identifier. If you sign in with a passkey we store the passkey’s public key and credential ID (never the private key, which stays on your device). We do not receive your password for any of these providers, and we do not request access to your repositories, files, calendar or mailbox.
Synced content (Pro). If you enable sync, the documents you choose to sync — title, body and metadata such as timestamps — are stored on our servers so they can be delivered to your other devices.
Uploaded images (Pro). Images you upload are stored and served through Cloudflare Images. We keep a record of the image ID, the owning account and the document it belongs to.
Published documents. When you publish a document we store its content and serve it at a public URL. Anyone with the link can read it and it may be indexed by search engines.
Billing. Payments are handled by Stripe. Stripe collects your payment details directly; we never see your full card number. We store your Stripe customer ID, subscription plan, status and billing-period dates so we can tell whether your account is Pro.
Usage and device data. Like most websites we receive standard server logs (IP address, browser type, referring page, pages requested, timestamps) and aggregate analytics about how the site is used — see Analytics and cookies.
Communications. If you email us, we keep the correspondence so we can respond and keep a record of the conversation.
4.How we use information
We use the information above to:
- provide, maintain and secure the Service — signing you in, syncing documents, serving images and published pages, and processing subscriptions;
- communicate with you about your account, billing, security and changes to the Service;
- understand how the Service is used so we can improve it, in aggregate wherever possible;
- detect and prevent abuse, fraud and security incidents;
- comply with legal obligations.
We do not sell your personal information, we do not show third-party advertising, and we do not use your documents or images to train machine-learning models.
5.Analytics and cookies
We use Google Analytics to understand traffic to the marketing pages and tools (for example which pages are visited and from where). Google Analytics sets cookies and collects information such as your IP address (which Google truncates), device and browser details, and the pages you view. You can opt out with the Google Analytics opt-out browser add-on or by blocking third-party scripts.
When you sign in we set a session cookie so you stay signed in. It is strictly necessary for the account features to work and is removed when you sign out or it expires. We do not use advertising or cross-site tracking cookies.
7.Data retention
- Account data and synced content are kept for as long as your account exists.
- When you delete a document, it is removed from sync storage promptly; when you unpublish a document, its public URL stops serving it.
- When you delete your account, your profile, synced documents, images and session data are deleted from our systems within 30 days, except for copies in routine backups (retained for up to 90 days) and billing records we must keep for tax and accounting purposes (typically 7 years).
- Server logs are retained for a short period (generally under 30 days) for security and debugging.
8.Security
All traffic to the Service is encrypted with TLS, data is encrypted at rest by our hosting provider, and access to production systems is limited to those who need it. No system is perfectly secure, though; if we become aware of a breach affecting your personal data we will notify you as required by law.
9.Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal information, to object to certain processing, and to lodge a complaint with a supervisory authority. You can exercise most of these directly:
- Export your documents at any time from the editor (Markdown, HTML, PDF, DOCX).
- Delete individual documents or images from within the Service.
- Delete your account from account settings, which removes your data as described under Data retention.
- Manage or cancel your subscription from account settings (via the Stripe billing portal).
For anything else, email hello@markdownwriter.com and we will respond within 30 days. We may need to verify your identity before acting on a request.
Legal bases (EEA/UK). We process account and content data to perform our contract with you; analytics, security and product-improvement data under our legitimate interests (which we balance against your rights); and billing records to meet legal obligations. Where we rely on consent — for example for non-essential cookies where required — you can withdraw it at any time.
10.International transfers
We are based in the United States and our providers operate globally, so your information may be processed in the U.S. and other countries whose data-protection laws differ from your own. Where required we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the EU–U.S. Data Privacy Framework (to which Cloudflare, Stripe and Google are certified).
11.Children
The Service is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
12.Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top shows when it last changed. For material changes we will give notice in the Service or by email before they take effect.
13.Contact
Markdown Writer · hello@markdownwriter.com
Questions? Email hello@markdownwriter.com. See also our Terms of Service and Privacy Policy.