Duly Noted is currently in a limited, invitation-only beta. This policy describes how the service handles your data today. It will be revisited before any public launch, and you'll be notified of material changes.
Who runs this
Duly Noted is operated by Kevin Knoll. For any question about this policy or your data, contact support@knollitall.com.
Account information
To create an account we collect your email address, a password, and an optional display name. Passwords are never stored in plain text — they're hashed with bcrypt before being saved. Registration during the beta also requires a one-time activation code.
Sign-in issues a short-lived access token and a refresh token; only a hash of the refresh token is stored server-side.
Content you create
Most of what you add to Duly Noted — notes, journal entries, contacts, recipes, to-dos, travel plans, car-maintenance records, and wiki pages — is stored as plain text on our servers. This is what lets it sync across your devices, appear in search, and be shown back to you in the app. It is not end-to-end encrypted.
Passwords and vault files are different. Entries in the Passwords tool and files you upload to the Vault are encrypted on your own device before they're ever sent to us, using a key derived from your master password. We store only the encrypted bytes and cannot read their contents.
Search
To power in-app search, a copy of your plain-text content (not your Passwords or Vault items, which we can't read) is indexed in a search database alongside your other data. It's used only to serve your own search results back to you.
Payment information
Paid plans are billed through Stripe. We never see or store your full card number — Stripe handles checkout and payment directly. We keep your Stripe customer and subscription IDs and your plan status (e.g. active, past due) so the app can reflect what you're entitled to.
Deleted content
When you delete an item, it's held for 7 days (free plan) or 30 days (paid plan) before being permanently and irreversibly removed from our systems. This window exists in case a deletion was accidental.
What we don't do
We don't run analytics or advertising trackers, and we don't sell or share your data with third parties for marketing purposes. The only outside parties who touch your data are Stripe (payments) and our email provider (account and password-reset emails).
Security
All traffic to Duly Noted is encrypted in transit (HTTPS). Passwords and Vault contents are additionally encrypted at rest with a key only you hold. As with any beta software, treat this as a work in progress rather than an audited, production-hardened system.
Your data, your requests
To request a copy of your data or the deletion of your account, email support@knollitall.com. There is no self-service account deletion yet — during this beta, deletion requests are handled manually.
Children's privacy
Duly Noted is not directed at, and should not be used by, anyone under the age of 16.
Changes to this policy
If this policy changes in a way that materially affects how your data is handled, we'll update the date above and notify active testers by email.