Last updated 2026-07-30. This is a beta product — this policy will be revised as the app changes.
Black Server Book is a relationship-tracking app. It's local-first: by default, everything you enter — the people you track, and the moments/tasks/notes attached to them — is stored only on your own device (the "Local vault"), and we never see it.
Logging in creates a second, separate "Synced" vault, hosted on our infrastructure (Supabase), so you can access your data from more than one device. Switching to it never overwrites your Local vault, and using the Local vault never requires an account at all.
Synced data is stored encrypted at rest by our hosting provider's infrastructure. It is not currently end-to-end encrypted — we are technically able to access it, though we don't do so except to operate, maintain, or debug the service, or if legally required. If you want data nobody but you can ever read, use the Local vault.
Because this app is about relationships, the content you enter is often about other people who have never used Black Server Book and never agreed to anything here. Please be thoughtful about what you record about someone else.
Account email and password (password is never visible to us in plain text — Supabase handles authentication). Whatever content you enter into the Synced vault. Basic technical error reports (an error message, rough context like which browser, and your account id if you're logged in when it happens) so we can find and fix bugs — see "Error reports" below.
When something breaks in the app, a small report (error message, browser/user-agent string, timestamp, and your account id if logged in) is sent to us automatically, so we can find and fix it. This happens whether or not you have an account — it's the same mechanism either way. These reports are not used for anything except fixing bugs.
We don't sell your data. We don't show ads. We don't share Synced data with third parties except the infrastructure providers needed to run the service itself (currently: Supabase for hosting/auth/database).
If/when a paid tier exists, payment is processed by Stripe — we don't store your card details ourselves.
You can permanently delete everything in your Synced vault yourself, at any time, from Settings in the app — see "Delete my account and data." This doesn't touch your Local vault (which is entirely on your own device, so it's yours to delete however you already delete files).
Questions about this policy: [your contact email].