Privacy Policy
Last updated: December 30, 2024
Pubit is operated by Joakim Lindqvist. This policy explains how your information is collected and used when you use Pubit to publish your Obsidian notes.
What We Collect
Account Information
When you create an account, we collect your email address through our authentication provider (Clerk). This is used solely to identify your account and allow you to log in.
Published Content
When you sync notes with publish: true in frontmatter, we store:
- The content of your published notes
- Images referenced in your published notes
- Note titles and folder structure
- Content hashes (to detect changes for syncing)
What We Don't Collect
- Notes you haven't marked for publishing
- Any files outside your Obsidian vault
- Analytics or tracking data
- Usage patterns or behavior data
How We Use Your Data
Your data is used exclusively to provide the Pubit service:
- Publishing your notes to your public website
- Rendering your notes as web pages
- Optimizing and serving your images
- Authenticating your account
We do not sell, share, or use your content for any other purpose.
Where Your Data Is Stored
Your data is stored on Cloudflare's infrastructure:
- Cloudflare D1 - Database for account and note metadata
- Cloudflare R2 - Storage for note content and images
- Cloudflare Workers - Serverless compute for the API
- Cloudflare Images - Image optimization and delivery
Authentication is handled by Clerk, a third-party authentication provider. See Clerk's Privacy Policy for details on how they handle your data.
Data Retention
Your published content remains stored as long as your account exists. When you:
- Remove publish: true from frontmatter - The note is deleted from your site on next sync
- Disconnect your vault - Your site remains online but no new syncs occur
- Delete your site - All content and data for that site is permanently deleted
Your Rights
You can:
- Access your published content at any time via your site
- Delete individual notes by removing publish: true from frontmatter and syncing
- Delete your entire site and all associated data via the dashboard
- Request a copy of your data by contacting us
Security
We take reasonable measures to protect your data:
- All connections use HTTPS encryption
- API tokens are stored as SHA-256 hashes
- Authentication is handled by Clerk's secure infrastructure
Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via the website or email.
Contact
If you have questions about this privacy policy or your data, contact us at: