Privacy Policy
md2gd ("md2gd", "we", "us") provides two-way sync between local Markdown files and Google Docs. This policy explains what data we collect, how we use it, and — importantly — what we do not touch.
The short version
We never store the contents of your documents. Your Markdown files and Google Docs sync directly between the md2gd client on your device and Google's APIs; that content does not pass through or get stored on our servers. We keep only the minimum needed to identify your account and coordinate syncs.
Information we collect
- Account identity. When you sign in with Google, we receive your Google account identifier and email address to create and identify your account.
- Google authorization. With your consent, Google issues a token that lets md2gd act on your behalf for the documents you link. We store this token encrypted at rest and use it only to perform the syncs you set up.
- Sync metadata. The linkages you create — local file paths, Google Doc IDs, and sync status/timestamps — so the service knows what to keep in sync.
- What we do not collect: the contents of your Markdown files or Google Docs. Document content flows directly between your device and Google and is never stored by us.
How we use Google user data
md2gd requests the drive.file and documents scopes. The drive.file scope limits access to only the files you create with, or explicitly open/link through, md2gd — not your whole Drive. We use this access solely to read and write the specific Google Docs you link, in order to perform the two-way sync you requested.
md2gd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell it or transfer it to third parties except as needed to provide the service or as required by law.
Service providers
We rely on a small set of subprocessors to run md2gd:
- Google — the Docs and Drive APIs your content syncs with.
- Supabase — our database (account identity, encrypted tokens, sync metadata).
- Cloudflare — hosting and edge delivery of the md2gd web service.
Security
Authorization tokens are encrypted at rest, access to your Google data is scoped to drive.file, and all traffic is served over HTTPS. No system is perfectly secure, but we aim to collect as little as possible so there is little to expose.
Retention and deletion
- You can revoke md2gd's access to your Google account at any time at myaccount.google.com/permissions.
- You can request deletion of your md2gd account and associated data (identity, tokens, and sync metadata) by contacting us. We retain data only as long as your account is active or as required by law.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above.
Contact
Questions or data requests: privacy@md2gd.com.