Privacy Policy
Plain-language summary. Burn Note does not require an account, run advertising, sell personal information, or use behavioral analytics. Password generation and image compression stay in your browser. Shared notes and files are encrypted in your browser before upload, but limited metadata and network information are still processed to operate and protect the service. Temporary does not mean risk-free: recipients can copy content, links can be forwarded, and infrastructure or legal obligations may delay complete deletion.
This Privacy Policy explains how Burn Note (“Burn Note,” “we,” “us,” or “our”) handles information when you use burnnote.io, note-api.burnnote.io, api.burnnote.io, and related Burn Note pages and services (collectively, the “Service”). Burn Note is operated from Massachusetts, United States. Privacy questions may be sent to [email protected].
1. Scope and roles
This Policy applies to visitors, note creators and recipients, file senders and recipients, and people who contact us. It does not govern websites or services operated by third parties. For applicable privacy laws, Burn Note generally acts as the controller or business for information used to operate the Service. Infrastructure providers may act as service providers or processors and may also process information under their own legal obligations.
2. Information we process
| Category | What it includes | Why it is processed |
|---|---|---|
| Network and security data | IP address, request time, requested hostname and path, HTTP headers, browser or device information, approximate region, TLS and security signals, error information, and challenge or rate-limit events. Much of this is processed by Cloudflare at the network edge. | Deliver pages and API responses, prevent abuse, rate-limit attacks, troubleshoot failures, and comply with law. |
| Temporary note data | Client-side encrypted note ciphertext, note identifier, expiry type and value, and operational status such as remaining retrievals. For password-protected notes, the password is used locally to derive the encryption key and is not intentionally sent to the note API by the current frontend. | Create, store, retrieve, and expire temporary notes. |
| Temporary file data | Client-side encrypted file bytes, initialization vector, one-time token, original filename, original size, acceptance of the Terms, and retrieval status. The file decryption key is placed in the URL fragment and is not intentionally sent to the file API by the current frontend. | Store and deliver a one-time encrypted file and enforce size, expiry, and abuse controls. |
| Local tool data | Passwords generated by the Password Generator and images handled by the Image Compressor. | These tools ordinarily process data in your browser. Nothing is intentionally uploaded unless you choose a separate sharing function. |
| Communications | Your email address, message, supporting evidence, and any information you voluntarily provide in privacy, legal, security, or abuse reports. | Respond to requests, investigate abuse, protect users, and maintain records. |
Do not send us plaintext secrets, decryption keys, complete private links, or unlawful content in an email or abuse report. Provide only the minimum identifier and context needed for us to investigate.
3. What we do not intentionally collect
- No Burn Note user account, profile, contact list, payment card, or subscription information.
- No advertising identifiers, cross-site behavioral profiles, or data-broker enrichment.
- No intentional sale or sharing of personal information for cross-context behavioral advertising.
- No intentional access to locally generated passwords or locally compressed images unless you choose to share or send them.
4. Encryption and link handling
The current Burn Note frontend encrypts shared note content and file bytes in the browser using the Web Crypto API and AES-256-GCM before upload. For notes without a separate password, the decryption key is included after the # in the share URL. For password-protected notes, the browser derives a key from the password. For files, the key is included in the URL fragment.
Browsers ordinarily do not include URL fragments in HTTP requests. However, anyone with the complete link or password may be able to decrypt the content. Browser extensions, screenshots, clipboard history, messaging previews, malware, recipient behavior, and compromised devices can defeat the practical privacy of a link. Burn Note cannot prevent a recipient from copying or redistributing content.
5. How we use information
- Provide, maintain, secure, and troubleshoot the Service.
- Apply expiry, retrieval, file-size, rate-limit, and anti-abuse rules.
- Investigate reports of malware, fraud, exploitation, infringement, threats, or other prohibited use.
- Respond to privacy, security, legal, and support communications.
- Comply with valid legal process and protect rights, safety, and the integrity of the Service.
Where the GDPR or similar law applies, our legal bases may include performance of a contract or steps requested by you, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is specifically requested.
6. Cookies, analytics, and consent management
Burn Note does not intentionally use Google Analytics, Google Tag Manager, advertising pixels, or behavioral analytics in the current frontend. The Service does not intentionally set first-party analytics cookies or use browser storage to build a user profile.
Cloudflare may set cookies that are strictly necessary for security, traffic management, bot detection, or challenge functionality. Because the intended configuration uses no non-essential cookies or tracking technologies, Burn Note does not currently display a consent-management banner. If we add non-essential analytics, advertising, session replay, personalization, or similar technologies, we will update this Policy and implement consent controls where required before activating them.
7. Service providers and disclosures
Cloudflare provides content delivery, DNS, TLS termination, security, Pages hosting, Workers execution, and data-storage infrastructure. Cloudflare processes technical request data and encrypted application data on our behalf and under its own legal obligations. We may also use an email-routing or email-hosting provider to receive privacy and abuse reports.
We may disclose available information when reasonably necessary to comply with law or valid legal process; protect users, victims, or the public; investigate prohibited activity; enforce the Terms; or protect the Service. We do not promise to notify a user before disclosure where notice is prohibited, impractical, or could create risk.
8. Retention and deletion
- Notes: retained in active application storage until the selected time limit, retrieval limit, or earlier deletion event. Available settings currently range up to 30 days.
- Files: retained in active application storage until the first valid retrieval or approximately 24 hours, whichever occurs first.
- Local tools: generated passwords and compressed images are not intentionally retained by Burn Note unless you choose a sharing feature.
- Technical and security data: retained according to Cloudflare configuration, operational need, security investigations, and legal obligations. This data may outlast temporary content.
- Communications and abuse records: retained as reasonably necessary to respond, document actions, prevent repeat abuse, or comply with law.
“Deleted,” “burned,” and “expired” refer primarily to removal from active application storage. Temporary copies may remain for a limited time in infrastructure logs, caches, backups, security systems, browser storage, or recipient devices. We cannot delete copies made by recipients or third parties.
9. Security
We use technical and organizational safeguards intended to reduce risk, including HTTPS, client-side encryption for shared content, short retention periods, restricted browser permissions, and infrastructure security controls. No service can guarantee absolute confidentiality, availability, integrity, or deletion. Do not use Burn Note as the only copy of important information, as an emergency communication system, or where a failure could cause death, personal injury, financial loss, or legal noncompliance.
10. International processing
Burn Note is operated from the United States and uses Cloudflare’s global network. Information may therefore be processed in the United States and other countries where privacy protections may differ. Where required, service providers may rely on contractual or other lawful transfer mechanisms.
11. Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about disclosures, and to appeal certain decisions. You may also have the right to complain to a privacy regulator.
Because Burn Note has no accounts and intentionally collects limited identifying information, we often cannot connect a person to an anonymous note or file. We may be unable to verify or fulfill a request without a relevant identifier, and we will not ask you to disclose a decryption key or plaintext content merely to exercise a privacy right. Send requests to [email protected]. We may request limited information to verify and scope the request.
Burn Note does not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising or consequential profiling. Accordingly, there is ordinarily nothing to opt out of under those categories.
12. Children
The Service is not directed to children and may be used only by people who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has used the Service or submitted personal information, contact [email protected] without sending the child’s sensitive content.
13. Changes to this Policy
We may update this Policy when the Service, providers, security architecture, or legal requirements change. The “last updated” date will identify the current version. Material changes may also be highlighted on the website.
14. Contact
Privacy and data-protection requests: [email protected]
Abuse or safety reports: [email protected]