Services Privacy Policy
Last updated: July 14, 2026
For the Markdown editor alone, see the Privacy Policy.
1. Scope
This policy explains how information is handled in features beyond the standalone Markdown editor, including GitHub integration, reports and articles (press/report), code-analysis dashboards, and analytics. These features may be enabled at the operator's discretion; if you do not use them, the related processing does not occur. For the standalone Markdown editor, please see the separate Privacy Policy.
2. GitHub Integration
If you enable GitHub integration and sign in, your GitHub account identifiers and access token are used for authentication. The requested scope is “repo”, which grants listing, read, and write access to your repositories including private ones (OAuth Apps cannot narrow permissions to individual repositories). Opening a document reads its content, and saving commits it, to the GitHub repository you specify, routed through our server. These actions occur only in response to your actions, and the token is used solely for these purposes.
2-2. Google Integration (Drive / YouTube)
If you sign in with Google, we use your identity information (openid, email address, profile) and, depending on the features you use, request the following permissions. For Google Drive we request “drive.file” and “drive.install”, which grant access only to files you open or create with this app; we never read the rest of your Drive. File content and file name are sent to Google only when you save to Drive. For YouTube features we request “youtube.force-ssl”, used solely to create playlists and add videos in response to your actions.
2-3. Spotify Integration
If you sign in with Spotify, we request “playlist-modify-public” and “playlist-modify-private”, used solely to create playlists and add tracks in response to your actions.
2-4. Handling of Credentials
Authentication is handled by each provider via OAuth, and we never receive your password. Access tokens (and Google refresh tokens) are stored as an encrypted session in a browser cookie and are not stored in any database of ours. You can revoke access at any time from the settings of each provider (GitHub / Google / Spotify).
3. Backend Storage
Some features, such as reports/articles and code analysis, use the following backend services to store and retrieve data. Report and article content and images are stored in Amazon S3 and delivered via CloudFront (CDN). Development activity data shown by the code analysis dashboard (sessions, commits, changed files, and similar) is stored in Supabase. Only when you use these features is the relevant data stored in or read from the backend. Documents you are editing in the editor are never automatically saved to these backends.
4. External Services
Some features may connect to external services for display or retrieval, such as:
External data retrieval — report/article features fetch information from external sources such as YouTube, Spotify, RSS feeds, news, weather, and GitHub trending. These requests mainly target publicly available data.
Embeds and external images — if content includes images or embeds from external URLs (e.g., X/Twitter), requests are made to those URLs.
PlantUML — when rendering PlantUML diagrams, after confirming your consent, the diagram code is sent to an external PlantUML rendering server.
Fetching a URL you provide — for link previews (OGP) and RSS subscriptions, the URL you provide is sent to our server, which fetches public information from it. Only addresses on the public network can be fetched; requests to internal networks are blocked.
Web page import — when importing a web page as Markdown, the URL you provide is sent to a proxy server, which retrieves the page's public HTML for conversion. No data is sent unless you run an import.
5. Analytics
At the operator's discretion, the service may use Google Analytics to collect anonymous usage data such as page views and session duration. This data is used only to improve the service and is never used for advertising or sold to third parties. No personally identifiable information is collected.
6. Children's Privacy
This service does not knowingly collect information from children under 13.
7. Changes to This Policy
This privacy policy may be updated from time to time. Changes will be reflected on this page along with the update date.
8. Contact
If you have questions about this privacy policy, please contact us via GitHub Issues.