Privacy Policy
Last updated 2026-09-26
Posteena is a set of private tools that runs entirely in your browser. There is no Posteena server: your notes, passwords and invoices are kept in your own Google Drive, and nobody else — the author of Posteena included — can see them. This policy explains exactly what the app touches and why.
1. In short
- Posteena has no backend and no accounts of its own. It never receives, stores, shares or sells your data.
- Your data lives in your Google Drive and in your browser, nowhere else.
- There are no analytics, no advertising and no tracking cookies.
- You can disconnect Posteena and delete everything it created at any time.
2. Google user data we access
When you sign in with Google, your browser receives an access token directly from Google. Posteena asks only for what its features need:
- Google Drive, files created by this app (drive.file): to create and update the files Posteena makes, all in one “Posteena” folder — notes, the password vault, invoices and what you share. Posteena cannot see any other file in your Drive.
- Google Drive, the app’s own data folder (drive.appdata): a hidden folder only Posteena can read, for your settings, your lock and your sharing key.
- Google Drive, “Open with” (drive.install): adds Posteena to Drive’s “Open with” menu, so a vault group or notes folder someone shared with you can be opened in Posteena. Opening it gives Posteena access to that one file only.
- Gmail, drafts (gmail.compose): requested only when you choose to e-mail an invoice, and used only to create a draft with the invoice attached. Posteena never reads your e-mail and never sends a message — you do, from Gmail.
To show who is signed in, Posteena also reads your name, e-mail address and profile photo from your Google account.
On browsers that support it, signing in can start with the browser’s own account chooser (FedCM). It tells Posteena, inside your browser only, which Google account you picked — its name, e-mail address and photo — so the button can say “Continue as …” and Google can skip its own account list.
3. How we use Google user data
Posteena’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Google user data is used only to provide the features you use, and only inside your browser. It is never transferred to the author of Posteena or to any third party, never used for advertising, never used to train AI models, and never read by a human. Posteena does not use Google Workspace APIs, or any Google user data, to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models.
5. How we store your data
- In your Google Drive, in a folder named “Posteena”: your notes (Markdown files, or encrypted files when protected) in “Notes”, your password vault in “Vault”, the invoice registry with its settings in “Invoices”, your invoices (PDF or DOCX) there as well or in the folder you choose in the invoice settings, the vault groups and notes folders you share in “Shared”, and your saved NFC readings in “NFC”.
- In this browser’s local storage: the Google access token, a copy of your notes and invoices so the app opens quickly and survives short connection drops, and preferences such as theme, language and tool order. If you keep scan history on, your recent QR and barcode scans are stored here too, and nowhere else. The NFC readings you save are kept here as well.
- In the app’s hidden folder in your Drive: your preferences (theme, language, tool order and similar), your Posteena lock (your data key, itself encrypted by your master password or passkey), your sharing key and the list of items shared with you, so they follow you to every device. They contain no passwords or notes, and a backup can include them.
- In this browser’s cache: Posteena’s own app files (code, styles, fonts and icons), so it opens and works offline. The cache holds nothing from Google or any other site and none of your data; clearing the site’s data removes it.
Posteena sets no cookies. Signing out removes the token and the copies of your data from the browser.
6. How we protect your data
- Every connection — to the app and to Google — uses HTTPS.
- Your browser talks to Google directly; no request passes through a server of Posteena’s.
- Access tokens are kept only in this browser and are removed when you sign out.
- The password vault, and notes if you protect them, are encrypted on your device with AES-256-GCM before they are saved, with a key only you can derive.
- Everything else in your Google Drive is protected by Google’s own encryption at rest and account security.
7. Data retention and deletion
Posteena keeps nothing on any server, so it has nothing to retain. Your data stays in your Google Drive for as long as you keep it there. The copy in this browser stays until you sign out, clear the site’s data, or the app replaces it with a newer version from Drive. Google keeps the access grant until you revoke it or it expires.
8. How to delete your data
- Sign out in Settings to remove the access token and cached data from this browser.
- Revoke Posteena’s access at any time: https://myaccount.google.com/permissions
- Delete the Posteena folder in your Google Drive (and any shared files others keep); its hidden app data can be removed in Drive under Settings → Manage apps.
The author holds no copy of your data, so there is nothing else to delete.
9. Vault
The password vault is encrypted on your device before it is saved to Drive. Its key is itself encrypted by your Posteena lock — one key, derived from your master password or passkey, that also opens protected notes, so you unlock once for both. The lock is stored only in encrypted form, in the app’s hidden folder in your Drive; the master password, passkey and every unencrypted key are never stored or sent anywhere, so a lost master password cannot be recovered by anyone.
If you choose "No encryption" when setting up the vault, your passwords are stored as readable text in your Drive.
Two-factor keys you add to an entry are stored inside that entry, encrypted exactly like its password, and the codes are calculated in your browser.
Identity documents (passports, ID cards, visas and residence permits) are read on your device: the camera image or photo you choose is processed in your browser, and its machine-readable zone is recognised by a text recogniser that Posteena serves itself. Nothing about the document, and no request, goes to Google or any other service while it is read. The document’s details and its photos (the page and the portrait you crop) are stored inside your vault, encrypted exactly like your passwords.
To show an entry’s website icon, your browser asks that website — and only that website — for its icon (the file favicon.ico), without saying which page you came from. The website therefore learns that someone requested its icon; it learns nothing else, and no other service is contacted. Each icon is kept on your device so it is asked for once, and the kept icons are removed when you sign out. You can turn website icons off in Settings.
You can share a password group or a notes folder with other people. To do so, Posteena gives you a sharing key pair: its public half is part of your sharing ID, which you send yourself to the person who shares with you; its private half is stored in the app’s hidden Drive folder, encrypted by your Posteena lock. If you share without a Posteena lock, that private half is stored there unencrypted, and Posteena warns you: anyone who can read your Drive’s app data — including Google — could then open what is shared with you; setting up a lock later encrypts it. A shared group or folder is encrypted with its own key — a shared notes folder always, even if your own notes are not — and that key is encrypted separately for each person it is shared with, so only their own sharing key opens it. Sharing a notes folder moves it, with everything in it, out of your own notes into its shared file. Posteena shares the file through Google Drive, and Google e-mails the person about it. Removing someone takes away their Drive access and gives the group or folder a new key, so nothing saved afterwards opens for them — but what they saw or copied while they had access stays with them. Shared groups and folders are left out of backups and exports.
Importing and exporting passwords happens entirely in your browser: an imported file is read on your device and its entries are saved only to your own vault; an export is created on your device and downloaded straight to it. An encrypted export is sealed with an export password you choose, which is never stored. Exports for other password managers (CSV, Bitwarden JSON and KeePass XML) are not encrypted, and Posteena asks you to confirm before creating one; they leave identity documents out, except KeePass XML, which includes their details but not their photos.
10. Encrypted notes
You can optionally protect your notes. Their titles, text and folder names are then encrypted on your device with a key protected by your Posteena lock — the same master password or passkey as the password vault — and stored in Drive as encrypted files that can no longer be read as Markdown. The key is never stored or sent anywhere, so a lost master password cannot be recovered. While your notes are unlocked, the readable copy exists only in the open page; this browser keeps only an encrypted copy.
11. Camera, scanning and NFC
The Codes tool reads and creates QR codes and barcodes entirely on your device, and the password vault reads identity documents the same way; images and scans are never uploaded. The camera is used only while you are scanning, after your browser asks for permission, and it stops when you leave the page or switch away from it. A scanned link or location opens only when you choose to open it.
NFC tags are read and written only on your device, and only after you start reading or writing; the phone stops listening when you leave the page or switch away from it. Readings you save are stored on this device and, when you are signed in, in the Posteena folder in your Google Drive, so you can see them on your other devices. Deleting a reading removes it from both.
12. Dev Tools
Dev Tools works entirely on your device. Everything you paste, type or drop into it — JSON, tokens, secrets, keys, files and text — is processed in your browser and is never uploaded, stored or sent anywhere, and nothing you enter is kept after you leave the page. Hashes, signatures and key pairs are made with your browser’s own cryptography; generated private keys exist only on the page until you copy them. The API client is the one exception: it sends the requests and messages you build there, from your browser straight to the address you enter and nowhere else, and forgets them when you leave the page.
13. Assistant
The Assistant runs an AI language model entirely inside your browser, on your own device. The model is downloaded once, when you choose to, from Hugging Face (huggingface.co), with the code that runs it from GitHub (raw.githubusercontent.com); those services see only that request, such as your IP address — never what you ask. The model and your chats are stored only in this browser: nothing you type is sent to the author of Posteena, to Google or to anyone else, and the Assistant never reads your notes, vault, invoices or any Google user data. You can delete downloaded models in the Assistant and chats one by one; clearing the site’s data in your browser removes both.
14. Backups
Backups are created and read entirely in your browser and downloaded straight to your device; they are never uploaded anywhere. Passwords in a backup are always encrypted, and you can choose to encrypt the whole backup, with a password you pick. That password is never stored or sent anywhere, so a backup cannot be restored without it. Restoring writes into your own Drive through the same path as the app itself, so protected notes and your vault stay encrypted.
15. Other services
- Google provides sign-in, Drive and Gmail. Its privacy policy applies to what Google itself processes: https://policies.google.com/privacy
- Cloudflare Pages hosts the app. Like any web host it may log technical data, such as your IP address, when the app is loaded: https://www.cloudflare.com/privacypolicy/
- Hugging Face (huggingface.co) and GitHub (raw.githubusercontent.com) serve the Assistant’s AI models when you download one. They receive only the download request.
- ipify (api.ipify.org) is asked for your public IP address only when you open Digital Footprint, so the page can show it to you. Nothing else is sent to it.
Everything else Digital Footprint shows is read inside your browser and goes nowhere unless you copy the report yourself.
16. Children
Posteena is not directed at children under 13, or under the minimum age for a Google account in their country.
17. Changes
If this policy changes, the new version is published on this page with a new date, and Posteena shows everyone who uses it a notice about the update, with a link to this page, the next time they open the app. If Posteena ever changes how it uses Google user data, that is described here before the change takes effect. Posteena will never start collecting your data without a new version of this policy that says so.
18. Contact
For any question about privacy or your data, write to support@posteena.com.