Privacy Policy

This Privacy Policy explains how Burn Note (“Burn Note,” “we,” “us,” or “our”) handles information when you use burnnote.io, note-api.burnnote.io, api.burnnote.io, and related Burn Note pages and services (collectively, the “Service”). Burn Note is operated from Massachusetts, United States. Privacy questions may be sent to [email protected].

1. Scope and roles

This Policy applies to visitors, note creators and recipients, file senders and recipients, and people who contact us. It does not govern websites or services operated by third parties. For applicable privacy laws, Burn Note generally acts as the controller or business for information used to operate the Service. Infrastructure providers may act as service providers or processors and may also process information under their own legal obligations.

2. Information we process

3. What we do not intentionally collect

4. Encryption and link handling

The current Burn Note frontend encrypts shared note content and file bytes in the browser using the Web Crypto API and AES-256-GCM before upload. For notes without a separate password, the decryption key is included after the # in the share URL. For password-protected notes, the browser derives a key from the password. For files, the key is included in the URL fragment.

Browsers ordinarily do not include URL fragments in HTTP requests. However, anyone with the complete link or password may be able to decrypt the content. Browser extensions, screenshots, clipboard history, messaging previews, malware, recipient behavior, and compromised devices can defeat the practical privacy of a link. Burn Note cannot prevent a recipient from copying or redistributing content.

5. How we use information

Where the GDPR or similar law applies, our legal bases may include performance of a contract or steps requested by you, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is specifically requested.

6. Cookies, analytics, and consent management

Burn Note does not intentionally use Google Analytics, Google Tag Manager, advertising pixels, or behavioral analytics in the current frontend. The Service does not intentionally set first-party analytics cookies or use browser storage to build a user profile.

Cloudflare may set cookies that are strictly necessary for security, traffic management, bot detection, or challenge functionality. Because the intended configuration uses no non-essential cookies or tracking technologies, Burn Note does not currently display a consent-management banner. If we add non-essential analytics, advertising, session replay, personalization, or similar technologies, we will update this Policy and implement consent controls where required before activating them.

7. Service providers and disclosures

Cloudflare provides content delivery, DNS, TLS termination, security, Pages hosting, Workers execution, and data-storage infrastructure. Cloudflare processes technical request data and encrypted application data on our behalf and under its own legal obligations. We may also use an email-routing or email-hosting provider to receive privacy and abuse reports.

We may disclose available information when reasonably necessary to comply with law or valid legal process; protect users, victims, or the public; investigate prohibited activity; enforce the Terms; or protect the Service. We do not promise to notify a user before disclosure where notice is prohibited, impractical, or could create risk.

8. Retention and deletion

“Deleted,” “burned,” and “expired” refer primarily to removal from active application storage. Temporary copies may remain for a limited time in infrastructure logs, caches, backups, security systems, browser storage, or recipient devices. We cannot delete copies made by recipients or third parties.

9. Security

We use technical and organizational safeguards intended to reduce risk, including HTTPS, client-side encryption for shared content, short retention periods, restricted browser permissions, and infrastructure security controls. No service can guarantee absolute confidentiality, availability, integrity, or deletion. Do not use Burn Note as the only copy of important information, as an emergency communication system, or where a failure could cause death, personal injury, financial loss, or legal noncompliance.

10. International processing

Burn Note is operated from the United States and uses Cloudflare’s global network. Information may therefore be processed in the United States and other countries where privacy protections may differ. Where required, service providers may rely on contractual or other lawful transfer mechanisms.

11. Your privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about disclosures, and to appeal certain decisions. You may also have the right to complain to a privacy regulator.

Because Burn Note has no accounts and intentionally collects limited identifying information, we often cannot connect a person to an anonymous note or file. We may be unable to verify or fulfill a request without a relevant identifier, and we will not ask you to disclose a decryption key or plaintext content merely to exercise a privacy right. Send requests to [email protected]. We may request limited information to verify and scope the request.

Burn Note does not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising or consequential profiling. Accordingly, there is ordinarily nothing to opt out of under those categories.

12. Children

The Service is not directed to children and may be used only by people who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has used the Service or submitted personal information, contact [email protected] without sending the child’s sensitive content.

13. Changes to this Policy

We may update this Policy when the Service, providers, security architecture, or legal requirements change. The “last updated” date will identify the current version. Material changes may also be highlighted on the website.

14. Contact

Privacy and data-protection requests: [email protected]
Abuse or safety reports: [email protected]