Skip to content
Back home

Privacy notice

Your information, in your space.

This notice describes how the current version of my sticky online handles your information.

Updated October 9, 2026

Your account and sign-in

When you create an account, the app stores your name, email address, account identifier, and account creation information. Passwords and private recovery codes are stored as hashes, rather than readable credentials. Your recovery code is shown to you when it is created.

If you choose Google sign-in, the app receives your Google account identifier, name, email address, and verified email status. A short-lived Google identity token is used to verify your sign-in. The app does not request access to Gmail or Google Drive.

Session records let you stay signed in. Request information, including your IP address, is used to limit abusive sign-in attempts; the app stores hashed rate-limit identifiers, attempt counts, and expiry times.

Your boards and notes

Saved board titles, notes, colors, positions, groups, checklists, and update information are stored in Cloudflare D1 and linked to your account. Other account holders cannot open your saved boards through the app. Public sharing and live collaboration are not available in this version.

Development, staging, and production use separate databases. An account or board created in one environment does not automatically appear in another.

Information on your device

The app uses necessary session and short-lived Google sign-in cookies. On HTTPS, session cookies are restricted to the current host, use Secure and HttpOnly, and are not shared between staging and production.

Your chosen language and theme are stored in your browser. Local drafts of edited boards may also be stored there to help preserve changes. Clear this site's browser storage to remove local preferences and drafts from that device.

The app does not add advertising or analytics trackers. Google sign-in and Cloudflare services handle information under their own policies when you use them.

Account emails

Cloudflare Email Sending is used for transactional messages, such as a welcome email after account creation and eligible account security notices. Messages do not include your passwords, recovery codes, or board content.

The app stores the recipient address, message type, language, sending status, and related delivery information so it can manage these messages. Cloudflare may retain its own delivery records. Staging sends only to the configured test recipient.

Services used to run the app

Cloudflare hosts the app, stores saved data in D1, and sends account emails. Google provides sign-in when you choose that option. These providers process information needed to deliver and protect their services, including request and delivery information.

Your choices and requests

You can export each board as JSON and delete notes or boards in the app. Archiving a note keeps it in your board; it does not delete it. Saved boards remain associated with your account until you delete them or request their removal.

For requests to access, correct, or delete account data, contact the address below. Account deletion is handled by request in this version. You may be asked to verify that you own the account before a request is processed.

Deleting app data does not automatically clear local drafts on your devices or a provider's delivery history and backups. Provider-held records are handled separately under that provider's policies.

Privacy questions

Contact Calin Vlasin about your information or this notice.

calinvlasin@netmirror.tech

This notice may change as the app develops. The update date above shows when it was last revised.