Your data
Privacy Policy
Last updated 24 September 2026
This policy explains how Thortiq handles data when you use our website, Thortiq Outline, Thortiq Markdown, and their optional connected services. Contact support@thortiq.com with privacy questions or requests.
Local files and optional accounts
You can use local features without connecting a Thortiq account. Markdown notes live in a folder you choose; Outline keeps its local workspace on your device. Your browser or device may also store settings and other app state.
If you create an account, we process your email address, authentication and security records, and the information needed to operate the connected features you choose. The account service stores password hashes and session records. Optional vault sync sends encrypted revisions to the sync service; the service is not intended to read your note plaintext. Sharing makes selected content available to people you authorize.
Google Calendar and Microsoft Calendar
Calendar connection is optional. When you connect Google Calendar, Thortiq requests the https://www.googleapis.com/auth/calendar.readonly permission. This lets Thortiq view calendars and events you can access. Thortiq does not ask Google for permission to create, edit, or delete your Google Calendar events. The Microsoft Calendar connection is also read-only.
We use this access to show available calendars, import events from calendars you select into your Thortiq workspace, and keep those imports up to date. Imported event details can include titles, times, locations, descriptions, attendee information, links, and calendar names. The account server processes this data to provide the feature and stores provider tokens and normalized event records in encrypted form. The imported event notes are kept in your vault and may be included in optional encrypted sync or sharing you enable.
Thortiq refreshes connected calendars in the background and receives provider change notifications. We do not sell Google Calendar data, use it for advertising, or use it to train AI models. Use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect a calendar provider in Thortiq Settings or revoke Thortiq's access in your Google or Microsoft account. Disconnecting removes the stored provider connection and stops future reads. Previously imported event notes and account-side feed history are not automatically erased by disconnecting; you can remove imported notes from your vault or contact us about account data deletion.
Other services you choose
If you choose an AI provider and supply its credentials, content you submit to an AI feature may be sent to that provider to answer your request. That content can include notes or imported calendar information you choose to use in the request. The provider's own privacy terms also apply. Opening external links or connecting other integrations likewise sends information to those services as needed for the action you choose.
Website and service operation
Our website and servers receive ordinary request information, such as an IP address, browser details, requested URL, and time of access. We use operational and security information to run, protect, and troubleshoot the service. We share information with infrastructure providers only as needed to host and deliver Thortiq, and when required by law.
Storage, choices, and changes
Local files remain under your control. Connected-service data is kept while needed to provide the feature, support account recovery and security, or meet legal obligations. Removing an account starts the account deletion process; some minimal audit or deletion records may remain. Contact support@thortiq.com to request access, correction, or deletion of account data.
We will update this page when our data practices change and show the revised date above. If we change how we use Google user data, we will notify affected users and seek consent before using it for a new purpose.