Privacy Policy
Last updated: 24 August 2026
Fyrien is a local-first app. Your notes, tasks and other content are plain files on your own device, and they stay there unless you turn on Sync. When you do turn on Sync, they are encrypted on your device before they are uploaded, and we cannot read them.
Who is responsible for your data
Fyrien is operated by Ross Wheatley as an individual sole trader ("Fyrien", "we", "us"). If you have a question about this policy or about your data, contact [email protected].
What we collect
Vault content — your notes, tasks, events and files
We do not collect it. Your vault lives on your device as markdown files. If you enable Sync, each file is encrypted on your device with a key derived from your sync passphrase, and only the resulting ciphertext is uploaded. Your sync passphrase and the keys derived from it are never transmitted to us and never stored on our servers. We can see how much encrypted data you store and when it changed; we cannot see what any of it says. This also means that if you lose your sync passphrase and your recovery key, we cannot recover your content — not as a policy choice, but because the ability does not exist.
Account information
If you create a Sync account we store your email address, a hash of your password (never the password itself), and your subscription status. We use these to sign you in, to operate your subscription, and to contact you about the service.
Technical and diagnostic information
Our servers keep short-lived operational logs — timestamps, request outcomes and error information — needed to run and secure the service. Diagnostics you generate inside the app stay on your device unless you choose to send them to us.
Payment information
Paid subscriptions are processed by Stripe. Card details go directly to Stripe and are never received or stored by us; we keep only the subscription identifiers needed to know whether your account is active.
Google user data
Connecting Google Calendar is entirely optional. Fyrien works fully without it, and nothing below applies unless you choose to connect your Google account.
What we request, and why
Fyrien requests two scopes, and no others:
-
https://www.googleapis.com/auth/calendar.events— access to the events on your calendars. The integration is two-way and needs both halves: reading events, so your calendar appears alongside your tasks in Fyrien's Home and calendar views and changes you make in Google reach the linked note; and creating, updating and cancelling events on the one calendar you nominate as the write target, so items created in Fyrien appear on your calendar. A read-only scope would disable the second half entirely. -
https://www.googleapis.com/auth/calendar.calendarlist.readonly— the list of calendars you are subscribed to, so you can choose which ones Fyrien reads from and which one it writes to. This is read-only and covers the list itself, not the contents. Without it the integration cannot be configured at all.
We do not request access to your Google profile, contacts, mail, files, calendar sharing permissions, or calendar settings.
How it is used and stored
Event data retrieved from Google is held in memory on your device to render your calendar views. It is written to disk only for events you explicitly save into your vault, and in that case it becomes an ordinary markdown file on your device, subject to the same end-to-end encryption as the rest of your vault if Sync is enabled. Your Google Calendar event data is not stored on Fyrien's servers. When you use Fyrien in a browser, our server refreshes your access to Google on your behalf, but the events themselves are fetched by your device, not by us.
Where the credential that lets Fyrien refresh access to your calendar is stored depends on how you use Fyrien:
- Desktop app — in your operating system's secure credential store (Keychain on macOS, DPAPI on Windows, libsecret on Linux), on your device only. It is never sent to us.
- Browser and mobile — held by us, encrypted at rest with a key that is not stored alongside it. A browser cannot complete Google's sign-in on its own, so our server completes it and refreshes access on your behalf. This credential is not covered by the end-to-end encryption described above , which applies to your vault content. It grants access to your calendar events and nothing else, and you can revoke it at any time.
Limited Use
Fyrien's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not sell Google user data, we do not use it for advertising, we do not use it to train generalised artificial intelligence or machine learning models, and we do not transfer it to third parties except as necessary to provide the feature you asked for, to comply with applicable law, or as part of a merger or acquisition. No human at Fyrien reads your Google user data.
Withdrawing access
You can disconnect Google Calendar at any time in Fyrien under Settings → Google Calendar, which deletes the stored credential — from your device on desktop, and from our servers when you connected through a browser. You can also revoke Fyrien's access from your Google Account permissions page. Disconnecting does not delete any notes or events already saved into your vault — they are yours, and they stay.
Who else processes your data
We keep this list short deliberately. Each of these providers processes data on our behalf, for the purpose named and no other:
- Cloudflare — hosting, and storage of your encrypted vault data.
- Stripe — payment processing for paid subscriptions.
- Google — only if you connect Google Calendar.
- Pushover — only if you enable push reminders, and only for the reminders you choose to send.
We do not use advertising networks or third-party analytics trackers.
Retention and deletion
We keep your account information for as long as your account exists. You can delete your account from within the app or by contacting us; doing so removes your account record and permanently deletes the encrypted vault data held on our servers. Content stored locally on your own devices is under your control and is not affected. Backups and operational logs are retained for a limited period and then expire.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal information, and to object to or restrict certain processing. Because vault content is encrypted with keys only you hold, an export of what we store is necessarily ciphertext — the readable copy is the one already on your device. To exercise any of these rights, contact [email protected].
Security
Vault content is encrypted on your device before upload. Passphrases are put through a deliberately slow key-derivation function, and passwords are stored only as hashes. Data is encrypted in transit. No system is perfectly secure, but the design goal is that a breach of our servers would expose ciphertext and account metadata, not your content.
Children
Fyrien is not directed at children under 13, and we do not knowingly collect their personal information.
Changes to this policy
If we change this policy we will update the date at the top of this page, and for material changes affecting how your data is handled we will notify account holders by email.
Contact
Questions, requests or complaints: [email protected].