Privacy policy
The short version
Your tasks are encrypted on your device before they reach us. We store them without being able to read them. We keep the little we need to run your account and sync your devices, we don’t track you, we don’t sell anything, and there are no ads or analytics.
Who is responsible
Yigit Ozdamar, Rashid Behbudov 104, AZ1014 Baku, Azerbaijan, “we”. Contact: privacy@sahife.app.
What we can’t see
The content of your tasks, projects, areas, headings, checklists, tags, notes, dates, reminders and repeating rules is end-to-end encrypted. The key never leaves your devices unencrypted; we only hold it locked by your Recovery Key or your passkeys, which we don’t have. We can’t read your tasks, show them to anyone, or recover them for you.
What we store and why
| Data | Why |
|---|---|
| Your email address, when your account was created, the versions of these documents you accepted | Your account: sign-in codes, security notices, proof of what you agreed to |
| During the private alpha: email addresses left on our website’s waitlist, and when | Inviting you when there’s a place. We send nothing else to it, and we don’t check it’s yours, so we write only once, with the invitation |
| During the private alpha: the email addresses we’ve invited | Letting only invited people create an account. An address leaves the list when its account is created, or when you ask us to remove it |
| Signed-in devices: when each signed in and was last active, the app and version (e.g. “web/1.0.0”), whether it is a shared computer | Keeping you signed in; the device list in Settings, where you can sign devices out |
| Passkeys: their public keys, the authenticator’s model identifier, when they were added and last used | Signing in with a passkey |
| Encrypted data, with record identifiers, sizes, times and counts | Syncing your devices and your storage quota (50 MB on the free plan) |
| A security log of account events (sign-ins, new passkeys, email changes, new Recovery Keys) | Showing you what happened to your account; spotting abuse |
| Error reports: the kind of error and where in our code it happened, the app version and screen name — never messages, task content or anything you typed | Fixing bugs. On by default; turn it off in Settings → Data |
| Server logs: request times, routes, status codes, account and session identifiers | Running and securing the service |
Your IP address is used for rate limiting while a request is handled and is not stored in our database or logs. We use one cookie, to keep you signed in; on a shared computer a second one marks the browser session so the app can clear your data from that browser. Your device also keeps your tasks locally so the app works offline.
Legal bases
Providing Sahife to you (your account, sync, sign-in and security emails) is necessary for our contract with you (GDPR Art. 6(1)(b)); keeping an invited address until you sign up is a step you asked for before that contract (same article). A waitlist address is kept with your consent (Art. 6(1)(a)), which you can withdraw at any time by writing to us. Security logs, abuse prevention and content-free error reports are based on our legitimate interest in a secure, working service (Art. 6(1)(f)); you can object to error reports by turning them off.
Where your data is, and who handles it
Scaleway SAS hosts Sahife’s servers, database, backups, logs and email in France (Paris region), as our processor. We share your data with no one else, unless the law requires it — and then there is no task content we could hand over.
We are based in Azerbaijan, outside the European Union, and run Sahife from there. Doing so, we may access limited account and administrative information from Azerbaijan, such as email addresses, the invite list and waitlist, the security log and server logs. Maintaining the database or restoring a backup can also involve your encrypted data as stored; we can’t decrypt it, so the content of your tasks stays unreadable to us wherever we are.
This access is a transfer of personal data outside the European Economic Area. The European Commission has not adopted an adequacy decision for Azerbaijan, and we have not yet put another GDPR transfer safeguard in place for it. We are reviewing this with legal advice before Sahife opens beyond its current invite-only alpha. Questions: privacy@sahife.app.
How long we keep it
- Account data: until you delete your account.
- A waitlist address: until we invite you, you sign up, or you ask us to remove it — and no longer than the private alpha.
- An invited address: until its account is created or you ask us to remove it.
- Deleting your account removes your encrypted data and keys immediately and your account record after 7 days (signing in during those days keeps an empty account).
- Backups age out within 30 days, so deleted data can remain in backups for up to 30 days.
- Server logs: 30 days. Expired sign-in codes: removed within a day.
Your rights
You can access and export your data (Settings → Data → Export), correct your email address, delete your account (Settings → Account), and object to error reports. You can also ask us at privacy@sahife.app for a copy of the account data we hold, and complain to a data-protection authority, such as the one where you live. Because your tasks are encrypted, only your own export can contain them.
Children
Sahife is not intended for children under 16.
Changes
If this policy changes in a way that matters, we tell you in the app or by email before it takes effect. The version you accepted is recorded with your account.