Dash Notes — Privacy Policy

Last updated: 12 May 2026

Dash Notes (“Dash”, “the app”, “we”) is a privacy-first, offline-first note-taking application. This policy explains what data the app handles, where it lives, and what we do — and don’t do — with it.

The short version

What stays on your device

All notes, folders, tags, attachments, version history, and settings are stored locally on the device you create them on:

Per-page encryption (passphrase-based) and app-level lock (passphrase + biometric) are performed entirely on-device using WebCrypto (PBKDF2 + AES-GCM). Decryption keys never leave the device.

Optional sync — and what the server sees

You can optionally pair two or more of your own devices to sync notes between them. Sync is opt-in, off by default, and end-to-end encrypted:

Sync infrastructure is hosted on Deno Deploy. The relay does not transmit data to any third party.

Permissions Dash may request

None of these permissions transmit data anywhere.

Dash Sync (paid subscription)

Dash Sync is an optional subscription that keeps your notes in sync across devices. You can use the app indefinitely without it. When you subscribe, the following third parties handle billing or sign-in on our behalf:

The sync vault itself is end-to-end encrypted as described above — none of these third parties (or we) can read your notes.

Analytics, tracking, advertising

We do not use any analytics, telemetry, crash reporting, advertising SDK, or third-party tracker. Dash makes no network calls except: to the optional sync relay (only when sync is enabled, and only with end-to-end encrypted blobs); to Stripe/RevenueCat/Resend solely for the paid Dash Sync subscription described above; and, on macOS/Windows/Linux, to GitHub Releases for app update checks.

Data we collect

None, in the analytics sense. We do not collect personally identifiable information, advertising identifiers, contacts, location, or device identifiers. The only server-side data is the encrypted sync envelope described above (visible to us only as ciphertext) for users who opt in to sync.

Data deletion

Because there are no accounts, you delete your data simply by deleting notes within the app, or by uninstalling the app. If you have used sync, disabling sync on the last paired device automatically purges your encrypted vault from the server. To request manual purge of any residual server data, email the address below.

Children

Dash is not directed at children under 13. We do not knowingly collect data from children. The app contains no advertising and no third-party content.

Changes to this policy

If this policy changes materially, we will update the “Last updated” date at the top of this page and note the change in the app’s What’s New screen.

Contact

Questions about this policy: efesop@gmail.com
Source code: github.com/Efesop/rich-text-editor

Filmshape Ltd. © 2026.