# Privacy Policy

## What Hjarni is

Hjarni is a personal knowledge management service. You create notes, organize them into containers (folders), and tag them. Hjarni includes an MCP server so AI assistants like Claude can read and manage your notes on your behalf.

## Data we collect

- **Account information:** your email address and password (stored securely using one-way hashing).
- **Content you create:** notes, folders, tags, file attachments, and AI instructions.
- **Payment information:** payment details are processed by Stripe, or by Apple or Google for a subscription bought inside the iOS or Android app. We never see or store your card number.
- **Access tokens:** tokens you generate to connect AI assistants or other apps.
- **Basic request logs:** IP addresses and timestamps for security purposes. These are not stored long-term.

## Legal basis for processing (GDPR)

We process your personal data on the following legal grounds:

- **Performance of a contract:** processing your account information and content is necessary to provide the Hjarni service to you.
- **Legitimate interest:** we process basic request logs (IP addresses, timestamps) for security, fraud prevention, and service stability.

## How we use your data

Your data is used solely to provide the Hjarni service. We do **not** use your notes, content, or any user data for training AI models, analytics, advertising, or any purpose other than showing it back to you (and to AI assistants you connect via MCP or the API).

## MCP data flow

When you connect an AI assistant (such as Claude) via MCP, the following happens:

- The AI assistant sends requests to the Hjarni MCP server using an access token you provide.
- Hjarni processes these requests and returns your data (notes, folders, tags) to the assistant.
- We do **not** store or log the content of AI conversations. We only process the specific data requests made through the MCP protocol.
- The AI assistant's provider (e.g., Anthropic) may process the data according to their own privacy policy. We encourage you to review the privacy policy of any AI assistant you connect.

## Email capture

On a paid plan you can create capture addresses at `in.hjarni.com` and email notes into Hjarni. When you use one:

- We receive the message through Resend, turn it into a note in the folder you chose, and record who sent it and when at the top of that note.
- That sender may be someone other than you, and they may not have a Hjarni account. Only give a capture address to senders you are willing to bring into your notes.
- Attachments are stored with the note like any other file you upload.
- Resend holds the received message for 30 days as part of delivering it, then deletes it. We keep no copy of the original message, only the note it became.
- We keep a delivery record for each message (the sender is not part of it) so we can show you what arrived and stop abuse. Records for mail we refused are deleted after 7 days.
- Revoking a capture address stops it resolving immediately. Notes it already created are yours and stay where they are.

## Third-party sharing

We do not sell, rent, or share your data with third parties. When you connect an AI assistant via MCP or the API, that assistant accesses your data using tokens you control. You can revoke access at any time by deleting the token.

## Sub-processors

We use the following third-party services to operate Hjarni. These parties process data on our behalf under strict contractual obligations:

- **Hetzner (Germany):** server hosting and data storage.
- **Stripe (Ireland, EU):** payment processing for subscriptions bought on the web. Stripe processes your payment details directly and is PCI DSS Level 1 certified.
- **Resend (USA):** transactional email (account confirmations, password resets, billing notifications), and receiving mail sent to a capture address.
- **Fastmail (Australia):** support inbox for email between you and support@hjarni.com.

A subscription bought inside the iOS or Android app is sold by Apple or Google as merchant of record, under their own privacy policies rather than on our behalf. We receive only the purchase's identifier and status, never your payment details.

See the [Security page](https://hjarni.com/security) for the full subprocessor table including what each one sees.

## Data storage and international transfers

Your data is stored on Hetzner servers within the European Union. We aim to keep all data within the EU. In cases where data may be transferred outside the EU/EEA (for example, Stripe processing payments or if you access the service from outside the EU), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), in compliance with GDPR.

## Data retention

- Your data is retained as long as your account is active.
- Archived notes can be restored. Deleted notes move to Trash, where they can be restored for up to 30 days; they are then permanently removed (you can also delete them from Trash permanently at any time) and leave backup rotations within a further 30 days.
- Security logs (IP addresses, timestamps) are kept for 30 days for debugging and abuse prevention, then discarded.
- Mail received at a capture address is held by Resend for 30 days as part of delivery. Our record of a refused delivery is deleted after 7 days; the notes created from accepted mail are kept like any other note.
- If you delete your account, all associated data is removed within 30 days, including from backup rotations.

## Cookies

Hjarni uses a session cookie to keep you signed in. We do not use tracking cookies, analytics cookies, or any third-party cookies.

## Your rights

Under the GDPR, you have the following rights regarding your personal data:

- **Access:** you can view all your data within the app at any time.
- **Rectification:** you can modify your data directly in the app.
- **Erasure:** you can delete individual notes or request full account deletion.
- **Data portability:** you can export your data from within the app as a ZIP of Markdown files with your folder structure and attachments preserved.
- **Restriction and objection:** you can contact us to restrict or object to certain processing activities.
- **Lodge a complaint:** you have the right to file a complaint with your local data protection authority. For Belgium, this is the [Gegevensbeschermingsautoriteit (GBA)](https://www.gegevensbeschermingsautoriteit.be).

To exercise any of these rights, contact us at the email address below or use the relevant features in the app.

## Changes to this policy

We may update this privacy policy from time to time. When we make significant changes, we will notify you by email and/or by displaying a notice in the app before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

## Contact

For privacy questions or requests, email [evert@hjarni.com](mailto:evert@hjarni.com).
