Effective 9 August 2026 · Last updated 11 August 2026
Extracted verbatim from the live page at https://adroitpad.com/privacy — legal review still pending (see launch-plan-phases.md and server-architecture.md). Use as source content for the v0 rebuild's `/privacy` page; do not represent it as attorney-reviewed.
AdroitPad is a desktop application. Your notes, captures, credentials and everything else you put into it are stored in an encrypted database on your own computer and are never sent to us. This page explains the small number of exceptions, all of which you control.
The short version
- Your data stays on your machine. We have no copy of it and no way to get one.
- There is no telemetry — no analytics, no crash reporting, no usage tracking.
- The only thing we hold that identifies you is an email address you choose to give us, and only if you tick a box.
- The free trial checks in with us once, sending a one-way hash of a machine identifier — never your name, address or anything about you. If it fails, the app opens anyway.
- We do not sell, rent or share personal data with anyone for their own purposes.
- To leave, use the unsubscribe link in any email, ask us via the form on this page, or write to privacy@adroitpad.com. The row is deleted, not flagged, within 30 days at the latest.
- AdroitPad is not for under-18s, and there is no advertising, tracking or profiling in it for anyone.
1. Who we are
AdroitPad is made by AdroitForge Inc, a sole proprietorship registered in India (GSTIN 09AKQPG4802L1ZT, Udyam UDYAM-UP-28-0230986), based in Greater Noida, Uttar Pradesh. For the purposes of the UK and EU GDPR, AdroitForge Inc is the data controller for the limited personal data described below.
Contact for anything on this page: privacy@adroitpad.com.
2. What stays on your computer
Everything you create in AdroitPad — captures, notes, code, screenshots, logs, design docs, daily statuses, TODOs, reminders and saved credentials — is written to an encrypted SQLite database (SQLCipher) on your own device. On macOS the encryption key is held in the system Keychain.
None of it is transmitted to us, and we could not read it if it were. There is no account, no sign-in, and no server-side copy of your content. If you lose the device and your backups, we cannot recover your data for you — that is the trade-off of the design, and we would rather state it than imply a safety net that does not exist.
Backups you create are encrypted with a passphrase only you know. If you choose to store a backup with a third party — iCloud, Google Drive, Dropbox, Amazon S3, GitHub — that provider's own privacy terms apply to the file you put there. We are not involved in that transfer and cannot see it.
3. Every connection the app can make
AdroitPad makes eight kinds of network request and no others. None of them carries your notes, captures, credentials or any other content. Three of them send something about you rather than about the software: the mailing list, which you opt into and which holds your email address (§4); the trial check, which sends a one-way hash of a machine identifier, and which we cannot connect to your name, your email address or anything else we hold (§5); and a contact form, which sends only what you typed into it, and only when you press send (§5a).
| Connection | When | What is sent |
|---|---|---|
| Contact form | Only when you fill one in and press send | What you typed: your message, and your name and email address if you gave them. Nothing else — no IP address, no install identifier. See §5a. |
| Update check | Periodically, and on request | The current version. No identifier of you or your machine. |
| Licence activation & validation | When you activate or re-check a licence | Your licence key and an anonymous per-install identifier, to Lemon Squeezy. See §6. |
| Developer news | Only when you open it | A public request to the dev.to API. No key, no identifier, nothing stored. |
| AI model download | Only if you choose to download a model | A request to Ollama's public registry. The model then runs entirely on your machine. |
| Your own API requests | When you send one from the API client or dev tools | Exactly what you typed, to exactly where you addressed it. We are not in the path. |
| Product updates | Only if you tick the box in Account | Your email address. Nothing else. See §4. |
| Trial check | Once, shortly after the app is first installed | A one-way hash of your computer's machine identifier, and the app version. No name, email, licence key or profile. See §5. |
Optional AI features (via Ollama) and voice transcription (via whisper) run locally on your machine. Your text and audio are not sent anywhere for processing.
4. The mailing list — the only thing we hold that identifies you
What we collect.* If you tick "Email me product updates" in AdroitPad's Account panel, AdroitPad sends your email address to a server we run, which emails that address a link asking you to confirm. Nothing is stored unless you click it. Once you do, three fields are stored: the address, the time it was confirmed, and the word "app" to record that it came from the desktop application rather than the website. If the link is never clicked, the address is never added anywhere.
Nothing links that address to anything else. We do not send your name, your install identifier, your licence key, your operating system, your version, or any information about your captures. We do not store your IP address — the connection necessarily has one, and we neither log it nor retain it. The list cannot be joined to your use of the app because there is nothing in it to join on.
In particular it cannot be joined to the trial record in §5. That row holds a hash of a machine identifier and a date; this one holds an address and a date. They live in separate tables with no field in common, and neither contains anything that could be used to match a row in one to a row in the other.
Why, and on what basis.* To email you occasionally about AdroitPad — new versions and significant changes, never more than monthly. Nothing else, ever. The legal basis is your consent, given by ticking a box that is unticked by default and disabled until you have entered an address, and confirmed a second time by clicking the link we send. That second step ("double opt-in") exists so the address on the list is provably one its owner asked to be there, not one someone else typed into the box.
Where it is stored.* In Amazon DynamoDB in AWS's Europe (Stockholm) region, eu-north-1, encrypted at rest. The request is made over HTTPS.
Our AWS account is administered from India, so this data is stored outside India and is accessible from outside the EEA. Where the UK or EU GDPR applies, that transfer relies on your consent and on the safeguards in our agreement with AWS. Where India's Digital Personal Data Protection Act, 2023 applies, we may process and store this data outside India, subject to any restrictions the Central Government notifies under that Act.
How long we keep it.* While you are subscribed, and no longer than 30 days after that. Concretely: if you unsubscribe, withdraw consent, or ask us to delete the address, the row is removed — immediately in the case of an unsubscribe link, and within 30 days in every other case. We also delete the whole list if we stop publishing updates. There is no "inactive" state and no suppression list: the row goes, and we keep no record that you were ever on it.
Unticking the box does not delete it — and we would rather say so.* Unticking "Email me product updates" stops the app from sending your address again. It cannot reach into our database and remove the row that is already there; a desktop app that could delete arbitrary records on request would be a way to unsubscribe other people. So the app tells you plainly when we still hold an address you have withdrawn consent for, and names it. There are two ways to remove it:
- The unsubscribe link in any email we send. One click, no reply needed, no page asking you to reconsider. It also works as a one-click control inside Gmail and similar clients. The link is signed, so it removes your address and only yours.
- Email privacy@adroitpad.com from the address in question, or use the delete-my-address form on the live page.
Either way deletion is immediate and permanent — the row is removed from the table, not flagged as inactive. We keep no record that you were ever on the list.
5. The trial check
AdroitPad has a free trial. Shortly after you first install it, the app asks our server one question — has this computer started a trial before? — so that the trial is the same length for everyone and cannot be restarted by reinstalling. It happens once per installation, not once per launch.
What is sent.* Two things: a one-way hash derived from your computer's machine identifier, and the app's version number. Nothing else — no email address, no licence key, no install ID, no computer name, no username, no list of what is installed.
The hash is computed on your machine before anything is sent, using a formula specific to AdroitPad. Two consequences follow, and both are the point of doing it that way: we cannot reverse it to learn your machine identifier, and nobody else can match it — another company hashing the same identifier would get a completely different value, so our record cannot be lined up against theirs.
What is stored.* One row: that hash, and the date the trial started. That is the entire record. There is no column for anything else, which is a more reliable promise than an intention not to fill one in. We do not store your IP address — the connection necessarily has one, and we neither log it nor retain it.
The row cannot be connected to the mailing list, to a licence, or to a person. It is held in a separate table from the mailing list for exactly that reason.
What this value is, precisely.* We describe it as a one-way hashed, pseudonymous device identifier rather than as anonymous data, because that is the more accurate description. It is a persistent value that distinguishes one device from another over time, and we would rather say so than claim more than the design delivers. What we cannot do is reverse it, connect it to your name or email address, or match it against any other company's hash of the same computer.
Why, and on what basis.* To run a time-limited free trial fairly, and for nothing else.
Where the UK or EU GDPR applies, the legal basis is our legitimate interest (Article 6(1)(f)) in offering a trial that is not trivially resettable — balanced against a design that collects the least it possibly can, cannot identify you from what it keeps, and does not prevent you using the app if you block it.
Where India's Digital Personal Data Protection Act, 2023 applies, the position is different and we would rather set it out plainly than borrow European wording. That Act has no general legitimate-interest ground. Our position is that this processing falls within Section 7(a) — processing for the specified purpose for which you have voluntarily provided the data — because you choose to install the application and start a trial, and we tell you before and during that this check happens, what is sent, what is stored and how to have it removed.
It is not consent-based, and we would rather be straightforward about why: a trial check you could decline would not be a trial check. If you would prefer not to make the request at all, blocking it is fine — see below.
You can block it, and nothing breaks.* If the request fails for any reason — you are offline, a firewall blocks it, our server is down, or the reply is not one the app trusts — AdroitPad starts your trial locally and carries on. It never prevents the app from opening. This is deliberate: an outage on our side must never stop you using software on your own computer.
Where it is stored, and for how long.* In Amazon DynamoDB in AWS's Europe (Stockholm) region, eu-north-1, encrypted at rest, over HTTPS. Our AWS account is administered from India, so the data is accessible from outside the EEA.
Kept for as long as we run a trial, because a record that expired would hand out a second trial to the same machine and defeat its only purpose. If you want the row for your machine removed, write to privacy@adroitpad.com — we can only find it if you send us the hash, which AdroitPad can show you, since we have no other way to look you up.
5a. Contact forms
When you fill in a contact, support, feature-request or waitlist form — in the app or on this site — we receive what you typed and nothing else: your message, plus your name and email address if you chose to give them.
We do not record your IP address, your install identifier, or anything that would link a message to your copy of AdroitPad. There is no field for them in the table the message is stored in. Your email address, if you give one, is used to reply to you and for nothing else — it is not added to the mailing list, which you can only join by ticking the box in §4.
Where it goes.* The message is delivered to our own mailbox by our email delivery provider — currently Resend, sending from EU infrastructure in Ireland (eu-west-1), with Postmark as an automatic backup if Resend is unavailable — and a copy is stored in Amazon DynamoDB in Europe (Stockholm, eu-north-1) so that a delivery failure does not lose what you wrote. The delivery provider handles the message in transit for the sole purpose of delivering it to us. Nothing is shared with anyone else.
How long we keep it.* 90 days, then it is deleted automatically. Long enough to resolve a support thread; short enough that this never becomes an archive of everything anyone has ever asked us. If a conversation continues by email, that email lives in our mailbox under the same terms as any other correspondence.
Lawful basis.* Under the UK/EU GDPR, Article 6(1)(b) — steps taken at your request before or during a contract — or 6(1)(f), our legitimate interest in answering people who write to us. Under India's DPDP Act 2023, Section 7(a): you provided it voluntarily, for the specified purpose of us replying. Unlike the trial check in §5, there is nothing strained about that reading here — you typed it and pressed send.
You can always email us instead. Every form sits beside the plain address it writes to, and if a form fails your text stays on screen with the address next to it. We would rather you reached us by any route than lose the message.
6. Buying a licence
Purchases are not handled by us. Lemon Squeezy (Lemon Squeezy LLC, USA) is the merchant of record: they are the seller, they take the payment, and they issue your invoice. Your card details, billing address and purchase email go to them, under their privacy policy, and we never see them. Payment processing and payouts involve Stripe as their processor.
We do not receive your name or email address when you buy. What AdroitPad sends when you activate a licence is your licence key and a label for the machine, so that activations can be counted against the seats you paid for and so you can tell your devices apart when releasing one.
That label is the word "AdroitPad" followed by the first eight characters of your install ID — a random number generated on your computer the first time AdroitPad ran. It is not derived from your name, your computer's name, or any hardware address; two copies of AdroitPad on the same machine get different ones. You can read the full ID in Settings → Licence to work out which row is which device.
Until 11 August 2026 this label was your computer's hostname instead, which on many machines contains the owner's name. We changed it because a product that promises nothing about you leaves your machine should not make an exception it has to apologise for. If you activated before that date, the older label remains against that activation in Lemon Squeezy until you release and re-activate the device.
7. Your rights
Where the UK or EU GDPR applies to you, you have the right to access, correct, delete, restrict or object to our processing of your personal data, to withdraw consent at any time, and to receive your data in a portable form. India's Digital Personal Data Protection Act, 2023 provides comparable rights.
In practice, for the one thing we hold, this is short: write to privacy@adroitpad.com from the address in question and tell us what you want — or, if what you want is deletion, use the delete-my-address form in §4. We will answer within 30 days and normally within a few days. There is no charge and we will not ask you to create an account to exercise a right.
If you are in the UK or EEA and are unhappy with how we have handled a request, you may complain to your national data protection authority.
8. Children
AdroitPad is a tool for professional software developers. It is not directed to anyone under 18, and we do not knowingly process the personal data of anyone under 18.
We use 18 rather than 16 deliberately. India's Digital Personal Data Protection Act, 2023 defines a child as anyone who has not completed 18 years, requires verifiable parental consent before processing a child's data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rather than apply one age in India and another elsewhere, we apply the stricter one everywhere.
We do none of the things that provision is aimed at — there is no advertising in AdroitPad, no behavioural tracking and no profiling of anyone, of any age. If you believe a child's personal data has nevertheless reached us, write to privacy@adroitpad.com and it will be deleted.
9. Security
Your content is encrypted on your device and never leaves it. The mailing-list server runs on AWS Lambda with permission to do exactly one thing — add a row — and no permission to read the list, search it, or delete from it. Responses are deliberately identical whether or not an address is already on the list, so the endpoint cannot be used to test whether a particular person uses AdroitPad.
No system is perfectly secure. If you find a vulnerability, please report it to privacy@adroitpad.com and we will respond.
If personal data is ever breached.* If we become aware of a breach affecting personal data we hold, we will act to contain and remediate it, and we will notify you and the relevant supervisory authorities as required by law — in India, the Data Protection Board under the Digital Personal Data Protection Act, 2023 and its Rules; elsewhere, the authority that applies to you.
Any notice we send you will say, in plain language, what happened, what data was involved, what we have done about it, what you can do, and who to contact with questions.
Worth stating what a breach here could and could not expose. Your notes, captures and credentials are encrypted on your own machine and we have no copy, so they cannot be part of it. What we hold is an email address if you gave us one, and a hashed device identifier if you started a trial — two small tables in separate places with no field in common.
10. Changes to this policy
If we change what we collect or why, we will update this page and change the date at the top. If a change is material — a new kind of data, or a new purpose — we will say so in the app's release notes rather than relying on you to re-read this page.
11. Contact and complaints
AdroitForge Inc
Greater Noida, Uttar Pradesh, India
For any question about this policy, to exercise a right, or to complain: Rishabh Gupta, proprietor — the person who answers these, and the only person with access to the data described above.
privacy@adroitpad.com
We answer within 30 days and usually within a few days. If you are not satisfied with how we handle a request, you may complain to the Data Protection Board of India, or — if you are in the UK or EEA — to your national data protection authority.
AdroitForge Inc is a one-person business, so there is no Data Protection Officer: that requirement applies to Significant Data Fiduciaries designated under section 10 of the Digital Personal Data Protection Act, 2023, which we are not. The named contact above is the route for everything.
© 2026 AdroitForge Inc. All rights reserved.