Privacy Policy
md2gd ("md2gd", "we", "us") provides two-way sync between local Markdown files and Google Docs. This policy explains what data we collect, how we use it, and, importantly, what we do not touch.
The short version
We never store the contents of your documents. Your Markdown files and Google Docs sync directly between the md2gd client on your device and Google's APIs; that content does not pass through or get stored on our servers. We keep only the minimum needed to identify your account and coordinate syncs, plus basic analytics to improve the product.
Information we collect
- Account identity. When you sign in with Google, we receive your Google account identifier and email address to create and identify your account.
- Google authorization. With your consent, Google issues a token that lets md2gd act on your behalf for the documents you link. We store this token encrypted at rest and use it only to perform the syncs you set up.
- Sync metadata. The linkages you create, local file paths, Google Doc IDs, and sync status/timestamps, so the service knows what to keep in sync.
- Usage and device data. Basic analytics about how the website and service are used (see Analytics and cookies below), and standard server logs such as IP address, browser type, and request timestamps for security and diagnostics.
- What we do not collect: the contents of your Markdown files or Google Docs. Document content flows directly between your device and Google and is never stored by us.
How we use Google user data
md2gd requests the drive.file scope (plus the openid and email scopes to identify your account). The drive.file scope limits access to only the files you create with, or explicitly open/link through, md2gd, not your whole Drive. We use this access solely to read and write the specific Google Docs you link, in order to perform the two-way sync you requested.
md2gd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as needed to provide the service or as required by law.
Analytics and cookies
We use cookies and similar technologies for two purposes:
- Strictly necessary. A session cookie keeps you signed in and a short-lived cookie protects the sign-in flow against cross-site request forgery. These are required for the Service to work.
- Analytics. We use PostHog to understand how the website and service are used, page views, interactions (autocapture), error reports, and, where enabled, session replays. This helps us diagnose issues and improve the product. Analytics data is processed in the United States.
You can limit or block cookies in your browser settings, and you can opt out of analytics by enabling your browser's "Do Not Track" / global privacy signal or by using tracker-blocking tools. Blocking analytics does not affect core sync functionality.
Service providers
We rely on a small set of subprocessors to run md2gd:
- Google, the Docs and Drive APIs your content syncs with.
- Supabase, our database (account identity, encrypted tokens, sync metadata).
- Cloudflare, hosting and edge delivery of the md2gd web service.
- PostHog, product and website analytics, as described above.
Security
Authorization tokens are encrypted at rest, access to your Google data is scoped to drive.file, and all traffic is served over HTTPS. No system is perfectly secure, but we aim to collect as little as possible so there is little to expose.
Retention and deletion
- Account identity and sync metadata are kept while your account is active and deleted after you request account deletion.
- Authorization tokens are deleted when you unlink your account, revoke access, or delete your account.
- Server logs are retained for up to 90 days for security and diagnostics, then deleted or anonymized.
- Analytics data is retained according to our PostHog configuration and is not used to identify you beyond your account.
- You can revoke md2gd's access to your Google account at any time at myaccount.google.com/permissions, and you can request deletion of your md2gd account and associated data by contacting us. We retain data only as long as your account is active or as required by law.
Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, export, or object to the processing of your personal data, and to withdraw consent. To exercise any of these rights, email privacy@md2gd.com; we will respond as required by applicable law.
We do not sell or share your personal information for money or for cross-context behavioral advertising, and we have not done so. If you are a California resident, you have the right to know, delete, and opt out; because we do not sell or share personal information, there is nothing to opt out of, and we will not discriminate against you for exercising your rights.
International users
md2gd is operated from, and processes data in, the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your country.
Children
The Service is not directed to children, and you must be at least 18 years old to use it. We do not knowingly collect personal data from anyone under 18 (or under 13 in any case). If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above.
Contact
Questions or data requests: privacy@md2gd.com.