Privacy Policy
FileLoveNote (filelovenote.com) — last updated 1 September 2026.
This policy describes what FileLoveNote stores about you, where it is stored, which third parties are involved, and what you can ask for. It describes how the service actually works rather than covering every hypothetical.
1. Who is responsible
FileLoveNote is run by Ernst van Megen, an individual based in the Netherlands, who is the controller of the personal data described here. For any privacy question or request, write to mail@ern.st.
2. What we collect
Account data. You sign in with Google or with a one-time code sent to your email address. Either way we store your email address, your display name and profile picture URL if your provider supplies them, which sign-in method you used, an internal account identifier, and the date the account was created. No account passwords are stored. Email sign-in codes are short-lived, limited to a few attempts, and discarded once used or expired.
Content you create. Notes, documents, canvases, folders, uploaded files and media, saved links, thumbnails generated from your media, and transcripts generated from your audio and video. Storing this is the purpose of the service.
Diagnostic logs. Private technical records of errors and warnings in your own workspace, used only to troubleshoot the service.
Technical data. The server and its reverse proxy process ordinary request data (IP address, path, timestamp, user agent) to serve and secure the site.
There is no third-party analytics, no advertising, no tracking pixels and no behavioural profiling. Your content is never sold, and we do not use it to train machine-learning models.
3. Cookies and local storage
One cookie is used: a signed session cookie that keeps you logged in. It is HttpOnly, SameSite=Lax and marked Secure over HTTPS, and the session identifier is rotated when you sign in. It is strictly necessary for the service to work, so no consent banner is shown; there are no analytics or advertising cookies. Your browser also keeps your theme preference in local storage and may cache recently viewed pages in a service worker so they stay available offline. That data never leaves your device.
4. Third parties
- Google Sign-In — if you sign in with Google. Only the openid, email and profile scopes are requested.
- Google Drive — only if you connect it. The app can list files you choose and store new uploads and Markdown notes in its dedicated FileLoveNote folder. You can revoke access at any time in your Google account settings.
- Google Gemini — when you use AI search or content structuring, your request and the content it concerns are sent to Google's Generative Language API to produce a response.
- YouTube — your search terms reach the YouTube Data API. Playback uses the privacy-enhanced youtube-nocookie.com player.
- Hetzner Storage Box — if remote file storage is configured, the files and media you keep there.
- Email delivery — your address and the sign-in code, so the message can be sent.
- Google Fonts and the jsDelivr CDN — your browser's IP address and user agent, as with any static asset request.
Each provider handles what it receives under its own privacy policy. Transcription of audio and video runs on our own server; media is not sent to an external transcription service.
5. Where data is stored
Application data and a working copy of documents live on a virtual server rented by us, with periodic backups on that server. When you make Google Drive the primary note storage, the Markdown source files live in your Google account. Files uploaded to Google Drive also stay there; optional legacy remote file storage uses a Hetzner Storage Box. These providers may process data outside the EU under their own transfer safeguards.
6. Why we process it
- To provide the service — storing and returning your content, keeping you signed in, running the features you invoke. Legal basis: performance of our contract with you.
- To keep the service working and secure — server logs, backups, abuse prevention. Legal basis: legitimate interest.
- To send you service messages such as sign-in codes. Legal basis: performance of our contract with you.
There is no marketing email, no profiling and no automated decision-making that produces legal effects for you.
7. How long we keep it
Your content is kept until you delete it or ask for your account to be removed. Deleted items go to the in-app trash first and are removed permanently when the trash is emptied. Backups are retained for a limited period, so deleted content may survive briefly in a backup. Sign-in codes expire within minutes, and sessions expire after a period of inactivity.
8. Your rights
Under the GDPR you can access, correct, delete, restrict or object to the processing of your personal data, and receive a copy of it in a portable form. Much of this you can do yourself: content can be edited, exported and deleted in the app, and the settings screen offers a full account reset or lets you permanently delete your account. For anything else, write to mail@ern.st; we answer within one month. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in your own country of residence.
9. Security
Traffic is served over HTTPS, sessions use signed HttpOnly cookies, and access to the server is restricted to the operator. No system is perfectly secure, and this is a personal project run without a dedicated security team, so keep your own copies of anything you cannot afford to lose.
10. Children
The service is not directed at children under 16, and accounts should not be created by them.
11. Changes to this policy
This policy may change as the service changes. The date at the top shows the current version, and material changes will be announced in the app.
12. Contact
Ernst van Megen — mail@ern.st. See also our Terms of Service.
← Back to FileLoveNote