Skip to content
Ingrid Back to Ingrid

Privacy Policy

Effective July 21, 2026 · Last updated August 21, 2026

Ingrid is built local-first: if you don’t turn on Sync, your notes stay on your device and Tanji Systems does not receive them. An optional AI action exists only in Ingrid Desktop and sends only the subtree you choose directly to OpenAI. This policy explains those boundaries, ordinary service metadata, who processes it, and the control you have over it.

1Who we are

Ingrid is operated by Brian Merriman, an individual sole proprietor doing business as Tanji Systems, based in New York, United States, and is the data controller for the information described here. Contact: .

2The short version

3What we collect and why

DataWhy
Email addressIt’s your Sync account identifier and how we send your one-time sign-in codes and essential account or billing notices.
Content you sync (your notes/documents and their structure)Stored and transmitted so your work stays in step across your devices. Only what you actually sync; local-only content is never collected.
Subscription status (active/lapsed, current period, a payment-provider customer reference)To grant or end Sync access and to operate billing. We keep this minimal and receive it from our payment provider.
Connection and security metadata (such as IP address, time, route, status, and error category)Cloudflare processes this to deliver and protect the billing endpoint. Our checkout limiter stores only a secret-keyed, opaque network identifier, not the raw IP address, and deletes it at the one-hour boundary. We don’t use this information to profile you.
Desktop AI input (only when you choose Generate: your OpenAI key, instruction, and selected tile subtree)Sent directly from Ingrid Desktop to OpenAI to generate the preview. Tanji Systems and the Ingrid billing service do not receive it.

We do not collect payment card numbers, and we do not run advertising or third-party behavioural analytics in Ingrid.

4Where your data lives

On your device. Ingrid keeps your content in your browser’s local storage (IndexedDB). Local-only data stays there until you delete it or clear your browser data.

Synced data is stored by Dexie Cloud, our sync provider, which runs on Microsoft Azure infrastructure. Depending on region, this may be processed in the United States or other countries (see International transfers below).

5Who else processes it (subprocessors)

We keep third parties to the minimum needed to run Ingrid:

ProviderRoleData
Polar (merchant of record)Sells the subscription, processes payments, handles taxYour billing details and card data — handled entirely by Polar; we receive only a customer reference and subscription status. See Polar’s privacy policy.
Dexie CloudCloud storage and synchronization for SyncYour email and the content you sync. See Dexie Cloud.
CloudflareRuns the billing Worker, D1 entitlement database, abuse controls, and operational logsYour authorization request, Dexie user identifier, subscription references/status, connection metadata, and a short-lived HMAC network key. See Cloudflare’s privacy policy.
OpenAI (optional, Desktop only)Generates an AI response when you explicitly choose GenerateYour OpenAI API key, instruction, and selected tile subtree go directly to OpenAI. Ingrid sends store: false, which disables Responses API application-state retention, but OpenAI may retain API content in abuse-monitoring logs for up to 30 days unless approved controls change that. OpenAI does not train on API content by default unless the account opts in. See OpenAI’s API data controls.

6Payments

When you subscribe, Polar acts as the merchant of record and processes the transaction. Your card information goes directly to Polar and its payment processors; we never receive or store it. We receive a customer reference and your subscription status so we can turn Sync on and off. Your purchase is also subject to Polar’s terms and privacy policy.

7Security

We take reasonable steps to protect your information. Traffic between your device and the sync service is encrypted in transit (HTTPS/TLS), and access to your synced data is tied to your authenticated account — sign-in is by a one-time code sent to your email, so keeping that email secure is what keeps your data secure. We limit third parties to the minimum described above. No online service can promise perfect security, but we work to keep your data safe and will act promptly on any issue we become aware of. Data stored locally on your device is protected by your device and browser — a device passcode and an up-to-date browser help keep it private.

8How long we keep it

Local data stays on your device until you remove it — we have no hand in it. One exception worth knowing if you use Sync: signing out removes the local synced copy from that device (your data stays in your account and returns when you sign back in — Ingrid syncs and offers an export first). A lapsed or cancelled subscription does not do this; only an explicit sign-out does.

Synced data is retained while your account exists so Sync can work. If your subscription lapses, Sync stops but your data is not immediately erased — this lets you resubscribe or sign back in and retrieve it. When you delete your account (or ask us to), we delete the active Dexie Cloud user, synced content, email, and Ingrid entitlement rows.

Billing and security data follows shorter or provider-specific schedules. Opaque checkout network keys are deleted at the one-hour boundary. On the paid plan used for this service, Cloudflare Workers observability logs are retained for up to 7 days, and deleted D1 state may remain recoverable through D1 Time Travel for up to 30 days. Polar may retain transaction records for tax, fraud, chargeback, and accounting obligations. We otherwise keep billing identifiers only while needed to operate the account or meet those obligations.

Desktop AI data is not stored by Ingrid. The API request uses store: false; OpenAI may still retain content in abuse-monitoring logs for up to 30 days, subject to the account’s approved data controls. Closing or refreshing Ingrid Desktop forgets the in-memory API key.

9Your rights and choices

Wherever you live, you can:

Depending on your location (for example the EU/UK under the GDPR, or California under the CCPA/CPRA), you may also have rights to object to or restrict certain processing, to data portability, and to lodge a complaint with your local data-protection authority. We don’t sell personal information or use it for targeted advertising. To exercise any right, email ; we’ll respond within the time your law requires.

10Deleting your data

To delete your synced data, email from your account address. We’ll verify the request, remove the active Dexie Cloud account and synced content, remove Ingrid’s D1 entitlement records, and confirm completion. Provider-controlled Cloudflare residuals then expire on the schedules above; Polar keeps only records it is required or permitted to retain as merchant of record. Deleting synced data does not touch the local copy on your device — that’s yours to keep or clear. Before deleting, you can export everything from within the app.

11Cookies & local storage

Ingrid doesn’t use advertising or tracking cookies. It uses your browser’s local storage (IndexedDB and similar) to hold your content and remember your preferences and sign-in session — this is essential to how a local-first app works, not a tracking mechanism.

12Children

Ingrid isn’t directed to children, and Sync isn’t intended for anyone under 13 (or the minimum age in your country). If you believe a child has given us personal data, contact us and we’ll delete it.

13International transfers

We’re based in the United States and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers. By using Sync, you understand your data may be processed outside your home country.

14Changes to this policy

We may update this policy as Ingrid changes. We’ll revise the date above and, for material changes, provide notice where appropriate. Continued use after an update means you accept it.

15Contact

Questions, requests, or concerns about privacy? Email .