← Back to Editor

Privacy Policy

Last Updated: August 4, 2026

1. Introduction

Welcome to MarkFlow ("we," "our," or "us"). MarkFlow is a minimalist, privacy-focused markdown editor designed to operate client-side directly within your web browser. We are fully committed to respecting your privacy and protecting your personal information.

This Privacy Policy explains how information is handled when you use MarkFlow, including our integration with Google OAuth, Google Drive, and AI services.

2. Information We Handle

We prioritize data minimization. MarkFlow operates zero backend database servers, meaning your documents and credentials remain on your device or in your personal cloud storage.

  • Google OAuth Profile Data: When you sign in with Google, we receive basic user profile information (openid, email, profile). This data is used solely to display your profile picture, name, and email locally in your user card.
  • Google Drive Data (drive.file): When you grant Google Drive permission, MarkFlow accesses ONLY files created by MarkFlow or files you explicitly select to open. We cannot view, read, or alter any other files in your Google Drive.
  • Local Documents & Encryption: All markdown notes, folders, and templates are stored locally in your browser's LocalStorage/IndexedDB. Sensitive notes encrypted with a Master Password or WebAuthn Passkeys use client-side AES-256-GCM encryption. Your password never leaves your browser.
  • API Keys: If you manually configure custom AI provider keys (such as OpenAI or Anthropic), they are saved securely in your browser's LocalStorage and are never sent to any MarkFlow server.

3. Google API Services User Data Policy Compliance

MarkFlow strictly adheres to Google's API policies to ensure your data remains protected and private.

Google Limited Use Requirement

MarkFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Use Your Information

The limited data processed by MarkFlow is used exclusively for:

  • Authenticating your session with Google services (Gemini AI & Google Drive sync).
  • Opening and saving markdown files to your personal Google Drive upon your explicit request.
  • Generating, converting, or refining markdown text when you invoke AI features.
  • Saving your editor preferences and documents locally on your device.

5. Third-Party AI Services

When you use MarkFlow's AI features (such as Prompt-to-Markdown or Template Generation), the prompt text you submit is sent directly to Google Gemini API (or configured custom LLM providers). We encourage you to review their respective privacy policies:

6. Data Security, Ownership & Revocation

You retain 100% ownership of your documents and data. Because MarkFlow does not store your notes on central servers:

  • You can export a full backup of all your notes and folders anytime via Settings → Data.
  • You can disconnect your Google account from within MarkFlow or revoke access directly in your Google Account Permissions.
  • Clearing your browser cache/storage will delete local data unless you have backed it up or saved it to Google Drive.

7. Contact Us

If you have any questions or feedback regarding this Privacy Policy or our data practices, please visit our GitHub Repository.

© 2026 MarkFlow. All rights reserved.