Privacy
There are no accounts or emails. Creating a board currently requires a shared phrase known to the operator’s friends; that phrase is checked and not stored. Board URLs do not use it.
A board URL is a capability: anyone who has it can read and edit that board. Treat the link like a secret. Do not put it in a public issue or a crawled page.
Board content is whatever holders of the link typed (source refs, notes, a “who has a copy” string). The operator of the Cloudflare account can read the D1 database, including board ids. Request-path logging is off by default. If it is turned on, URLs contain board ids and are operator-secret.
We do not run third-party analytics on board or API pages.
Client IPs are not stored on board rows.