Privacy Policy
Last updated: July 20, 2026
No time to read all this? The short version:
We believe a privacy policy should be readable by humans. Here is everything that matters, in plain language:
- No accounts, no sign-ups. We recognize you by your IP address — that's it.
- Everything you type is encrypted in our database. Even we can't read it.
- Secret notes are encrypted in your browser before they reach us — the key never touches our servers, and every note is permanently deleted within 30 days, opened or not.
- Uploaded files are deleted automatically after 7 days.
- You can permanently delete everything we have about you, anytime, from the Debug page.
- We show Google ads to keep the service free — and you can turn them off in Settings.
What we collect
We never ask for an email address, username, or password to use Simple.Savr. What we store:
- Your IP address — it's how we know which content is yours.
- The text you type, encrypted in our database using your IP and a random key (or an encryption text you choose).
- Files you upload, stored on secure storage and synced to your linked devices.
- Basic device information (browser user agent) for the devices you link.
- Standard server logs (IP, browser type, date/time, referring pages) — routine for any website, used only to run and protect the service, and never linked to your content.
How we use it
Your data is used for exactly one thing: syncing your text and files between your devices. We do not sell it, share it, or mine it for advertising. Nobody outside your network can see your content, and neither can we.
Security & encryption
All text content is encrypted at rest in our database. You can optionally set your own encryption text for extra protection, and lock your space behind a password so others on your network can't open it.
Self-Destructing Notes
Secret notes use zero-knowledge, end-to-end encryption. Your note is encrypted in your browser before it is sent, and the decryption key lives only in the share link (the part after the “#”), which browsers never transmit to our servers. This means:
- We only ever store unreadable ciphertext. We cannot read your notes — and neither can anyone who obtains a copy of our database.
- The decryption key never reaches our servers. If the link is lost, the note is unrecoverable, even by us.
- File attachments follow the same rules: each file is encrypted in your browser with its own key before it uploads, so the file contents — and even its filename — reach us only as ciphertext. Attached files are deleted when their note is destroyed or expires (after a burn-on-read, the reader has a short window to download them before they are wiped).
- Notes self-destruct after they are read or when they expire — and every note is permanently deleted within 30 days of creation, opened or not. You can also destroy a note yourself at any time. Destroyed notes are wiped from our storage.
- We keep only minimal metadata (creation and read times, plus a notification email if you add one). The email and all sensitive fields are wiped when the note is destroyed; a small record of when it was destroyed and how many times it was opened remains for up to 1 year so the link can report the note's fate, then the entire record is deleted. Notification emails never contain the note or its link.
How long things live
Nothing sticks around forever. Our automatic cleanup schedule:
- Uploaded files: deleted automatically after 7 days.
- Secret notes: destroyed the moment they're read (burn mode) or when their timer expires, and never later than 30 days after creation, even if nobody ever opens them. After a note is destroyed, we keep a tiny record (when it was destroyed and how many times it was opened, never the content) for up to 1 year so its link can tell you what happened to it. Then that record is deleted too.
- Zip archives you generate: deleted right after download, or within 24 hours at the latest.
- Backups: anything you delete is also purged from our backup systems within 60 days.
Deleting your data
Unlike most services, we let you destroy everything we have stored about you — your text, files, linked devices, secret notes, and IP record — instantly, from the Debug page. No requests, no waiting, no questions.
Cookies & advertising
We keep Simple.Savr free by showing ads through Google AdSense. Google (as a third-party ad partner) may use cookies and web beacons to personalize the ads you see. If you'd rather not see ads at all, flip the switch in Settings — that turns them off on every device and cuts all communication with ad partners.
Our privacy policy does not cover third-party advertisers. For details on their practices and how to opt out, consult their privacy policies directly, or disable cookies in your browser settings.
Children's privacy
We do not knowingly collect any personally identifiable information from children under 13. If you believe a child has used the service, the data can be deleted immediately from the Debug page, or contact us and we'll take care of it.
Consent & changes
By using Simple.Savr, you consent to this privacy policy. If we change it in a meaningful way, we'll update the date at the top of this page.
Questions?
For any privacy concerns or questions, reach out via our contact page — a human will read it.