Privacy Policy
Ingrid is built local-first: if you don’t turn on Sync, your notes stay on your device and Tanji Systems does not receive them. An optional AI action exists only in Ingrid Desktop and sends only the subtree you choose directly to OpenAI. This policy explains those boundaries, ordinary service metadata, who processes it, and the control you have over it.
1Who we are
Ingrid is operated by Brian Merriman, an individual sole proprietor doing business as Tanji Systems, based in New York, United States, and is the data controller for the information described here. Contact: hi@tanji.systems.
2The short version
- No Sync → no note collection by us. Used locally, Ingrid stores your content on your device. It isn’t sent to Tanji Systems. As with any web app, the hosting service receives ordinary connection metadata when you load the public site.
- With Sync, we store your email (your account name) and the content you choose to sync, so it stays consistent across your devices.
- Desktop AI is optional. The public web app does not accept API keys. If you choose the Desktop AI action, your key, instruction, and selected tile subtree go directly to OpenAI, not to Tanji Systems.
- We never see your card details — payments are handled by Polar.
- We don’t sell your data, show ads, or run third-party tracking or advertising analytics.
- You can export or delete your data at any time.
3What we collect and why
| Data | Why |
|---|---|
| Email address | It’s your Sync account identifier and how we send your one-time sign-in codes and essential account or billing notices. |
| Content you sync (your notes/documents and their structure) | Stored and transmitted so your work stays in step across your devices. Only what you actually sync; local-only content is never collected. |
| Subscription status (active/lapsed, current period, a payment-provider customer reference) | To grant or end Sync access and to operate billing. We keep this minimal and receive it from our payment provider. |
| Connection and security metadata (such as IP address, time, route, status, and error category) | Cloudflare processes this to deliver and protect the billing endpoint. Our checkout limiter stores only a secret-keyed, opaque network identifier, not the raw IP address, and deletes it at the one-hour boundary. We don’t use this information to profile you. |
| Desktop AI input (only when you choose Generate: your OpenAI key, instruction, and selected tile subtree) | Sent directly from Ingrid Desktop to OpenAI to generate the preview. Tanji Systems and the Ingrid billing service do not receive it. |
We do not collect payment card numbers, and we do not run advertising or third-party behavioural analytics in Ingrid.
4Where your data lives
On your device. Ingrid keeps your content in your browser’s local storage (IndexedDB). Local-only data stays there until you delete it or clear your browser data.
Synced data is stored by Dexie Cloud, our sync provider, which runs on Microsoft Azure infrastructure. Depending on region, this may be processed in the United States or other countries (see International transfers below).
5Who else processes it (subprocessors)
We keep third parties to the minimum needed to run Ingrid:
| Provider | Role | Data |
|---|---|---|
| Polar (merchant of record) | Sells the subscription, processes payments, handles tax | Your billing details and card data — handled entirely by Polar; we receive only a customer reference and subscription status. See Polar’s privacy policy. |
| Dexie Cloud | Cloud storage and synchronization for Sync | Your email and the content you sync. See Dexie Cloud. |
| Cloudflare | Runs the billing Worker, D1 entitlement database, abuse controls, and operational logs | Your authorization request, Dexie user identifier, subscription references/status, connection metadata, and a short-lived HMAC network key. See Cloudflare’s privacy policy. |
| OpenAI (optional, Desktop only) | Generates an AI response when you explicitly choose Generate | Your OpenAI API key, instruction, and selected tile subtree go directly to OpenAI. Ingrid sends store: false, which disables Responses API application-state retention, but OpenAI may retain API content in abuse-monitoring logs for up to 30 days unless approved controls change that. OpenAI does not train on API content by default unless the account opts in. See OpenAI’s API data controls. |
6Payments
When you subscribe, Polar acts as the merchant of record and processes the transaction. Your card information goes directly to Polar and its payment processors; we never receive or store it. We receive a customer reference and your subscription status so we can turn Sync on and off. Your purchase is also subject to Polar’s terms and privacy policy.
7Security
We take reasonable steps to protect your information. Traffic between your device and the sync service is encrypted in transit (HTTPS/TLS), and access to your synced data is tied to your authenticated account — sign-in is by a one-time code sent to your email, so keeping that email secure is what keeps your data secure. We limit third parties to the minimum described above. No online service can promise perfect security, but we work to keep your data safe and will act promptly on any issue we become aware of. Data stored locally on your device is protected by your device and browser — a device passcode and an up-to-date browser help keep it private.
8How long we keep it
Local data stays on your device until you remove it — we have no hand in it. One exception worth knowing if you use Sync: signing out removes the local synced copy from that device (your data stays in your account and returns when you sign back in — Ingrid syncs and offers an export first). A lapsed or cancelled subscription does not do this; only an explicit sign-out does.
Synced data is retained while your account exists so Sync can work. If your subscription lapses, Sync stops but your data is not immediately erased — this lets you resubscribe or sign back in and retrieve it. When you delete your account (or ask us to), we delete the active Dexie Cloud user, synced content, email, and Ingrid entitlement rows.
Billing and security data follows shorter or provider-specific schedules. Opaque checkout network keys are deleted at the one-hour boundary. On the paid plan used for this service, Cloudflare Workers observability logs are retained for up to 7 days, and deleted D1 state may remain recoverable through D1 Time Travel for up to 30 days. Polar may retain transaction records for tax, fraud, chargeback, and accounting obligations. We otherwise keep billing identifiers only while needed to operate the account or meet those obligations.
Desktop AI data is not stored by Ingrid. The API request uses store: false; OpenAI may still retain content in abuse-monitoring logs for up to 30 days, subject to the account’s approved data controls. Closing or refreshing Ingrid Desktop forgets the in-memory API key.
9Your rights and choices
Wherever you live, you can:
- Access & export — export your data from within Ingrid at any time.
- Correct — edit your content directly; contact us to correct account details.
- Delete — delete your account and synced data (see below).
- Withdraw — stop using Sync at any time; local-first use requires no account at all.
Depending on your location (for example the EU/UK under the GDPR, or California under the CCPA/CPRA), you may also have rights to object to or restrict certain processing, to data portability, and to lodge a complaint with your local data-protection authority. We don’t sell personal information or use it for targeted advertising. To exercise any right, email hi@tanji.systems; we’ll respond within the time your law requires.
10Deleting your data
To delete your synced data, email hi@tanji.systems from your account address. We’ll verify the request, remove the active Dexie Cloud account and synced content, remove Ingrid’s D1 entitlement records, and confirm completion. Provider-controlled Cloudflare residuals then expire on the schedules above; Polar keeps only records it is required or permitted to retain as merchant of record. Deleting synced data does not touch the local copy on your device — that’s yours to keep or clear. Before deleting, you can export everything from within the app.
11Cookies & local storage
Ingrid doesn’t use advertising or tracking cookies. It uses your browser’s local storage (IndexedDB and similar) to hold your content and remember your preferences and sign-in session — this is essential to how a local-first app works, not a tracking mechanism.
12Children
Ingrid isn’t directed to children, and Sync isn’t intended for anyone under 13 (or the minimum age in your country). If you believe a child has given us personal data, contact us and we’ll delete it.
13International transfers
We’re based in the United States and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers. By using Sync, you understand your data may be processed outside your home country.
14Changes to this policy
We may update this policy as Ingrid changes. We’ll revise the date above and, for material changes, provide notice where appropriate. Continued use after an update means you accept it.
15Contact
Questions, requests, or concerns about privacy? Email hi@tanji.systems.