Privacy Policy
Last updated 26 September 2026
1. Who is responsible
Ripenote (“we”, “us”, “our”) is responsible for this policy. Email contact@ripenote.com, or see the contact page.
2. What we collect: nothing personal
Using Ripenote — writing, sealing, sharing and opening — does not send personal data to us. We have no database, no user accounts and no email list.
3. Your sealed content never reaches us
Encryption happens in your browser. The sealed message, the unlock date, and any names or title you add are placed in the fragment of the link — the part after #. Browsers do not send the fragment to web servers, so when someone opens a capsule link, our server only sees a request for /o. We also send a Referrer-Policy: no-referrer header so links aren't leaked to other sites. Cards, keepsake PDFs and .seal files are generated on your device.
Before opening a capsule, your browser checks a short list of disabled capsules that ships with the app (see Report a link). The check runs on your device; nothing is sent to us.
4. Hosting and request logs
Ripenote is hosted by Vercel. Like any web host, Vercel automatically records basic information about each request — your IP address, user agent, the requested path and query string, and the time — to deliver the site, keep it secure and debug problems. These logs are kept by Vercel under its privacy policy. We don't add any logging of our own, and our code never logs license keys or capsule content.
5. The only other network requests Ripenote makes
a) drand relays (to open capsules and show the clock)
To open a capsule, your browser fetches one public beacon for the capsule's round from a drand relay. The home page also fetches the latest round number to show the live clock. We try these relays, in order:
https://api.drand.shhttps://api2.drand.shhttps://api3.drand.shhttps://drand.cloudflare.com
These relays are operated by drand / Protocol Labs and Cloudflare, not by us. Like any website, they receive your IP address and basic request information (such as your browser's user agent) and may keep standard server logs under their own policies. The request contains only a round number — never your message.
b) License routes (only if you use a paid key)
When you activate, validate or deactivate a key, your browser sends the key, the license instance ID and a randomly generated device label (for example “Ripenote iPhone 3f2a”) to our /api/license/* routes. These requests pass through Vercel (see section 4) and are forwarded to Dodo Payments, which answers whether the key is valid and which product it belongs to. Our routes store nothing, add no logging, and pass back only the instance ID and product ID — not the name or email address Dodo holds for the buyer. Vercel may also process your IP address transiently to apply a short-lived, in-memory rate limit.
6. Payments
Purchases are processed by Dodo Payments, which acts as the Merchant of Record: it is the seller of record, handles your payment details, tax and receipts, and emails you your license key. Dodo Payments processes your name, email address, billing details and payment information under its own privacy policy. We don't receive your card details.
After checkout, Dodo returns you to /thanks and adds your key, a payment ID, the payment status and your email address to the address. Because that is part of the request, it can appear in Vercel's request logs (section 4); we don't read or keep it. The page uses the key to activate this device and then immediately removes all of these values from the address bar and the browser history entry.
7. What's stored in your browser
ripenote.licenses.v2(localStorage): each key you activate, with its instance ID, device label, product and last validation time — only if you activate a key.ripenote.theme(localStorage): light or dark mode, if you choose one.ripenote.campaign.dismissed(localStorage): which seasonal note you closed, so it stays closed.ripenote.code(sessionStorage, cleared when you close the tab): a discount code from a link you followed, so we can remind you to use it at checkout.- A service worker cache of the app's own files, so Ripenote works offline.
None of this is sent to us except as described in section 5(b). To clear it, use your browser's “clear site data” option for ripenote.com, or deactivate your device on the Your keys page first to free its slot.
8. No cookies, no trackers, no analytics, no data sales
Ripenote sets no cookies and loads no third-party scripts: no analytics, advertising pixels, chat widgets or social embeds. Fonts are self-hosted. Discount and partner codes are handled entirely in your browser — nothing records who referred you. We never sell or share data. If we ever add analytics, it will be cookieless and privacy-preserving, and we'll update this page before doing so.
9. Your rights (GDPR, UK GDPR, CCPA and similar laws)
You have rights to access, correct, delete and port your personal data, to object to or restrict processing, and — in California — to know what's collected and to opt out of its sale (we don't sell or share data). Because Ripenote holds no personal data about you, there is nothing for us to access, correct or delete. Requests about purchases — your name, email or payment record — should go to Dodo Payments, which holds that data as Merchant of Record. We're happy to help you reach them: contact@ripenote.com. You may also complain to your local data-protection authority.
10. Children
Ripenote is not directed at children under 13 (16 in the EEA and UK) and does not knowingly collect data from anyone — including children. When a teacher or parent runs Ripenote for younger children, nothing about the children is sent to us; class batches are generated on the teacher's device, and student names are off by default.
11. Changes
We'll update the “Last updated” date when this policy changes, and note significant changes on the home page.