Privacy Policy

Last updated 2026-07-30. This is a beta product — this policy will be revised as the app changes.

What Black Server Book is

Black Server Book is a relationship-tracking app. It's local-first: by default, everything you enter — the people you track, and the moments/tasks/notes attached to them — is stored only on your own device (the "Local vault"), and we never see it.

If you create a Synced account

Logging in creates a second, separate "Synced" vault, hosted on our infrastructure (Supabase), so you can access your data from more than one device. Switching to it never overwrites your Local vault, and using the Local vault never requires an account at all.

Synced data is stored encrypted at rest by our hosting provider's infrastructure. It is not currently end-to-end encrypted — we are technically able to access it, though we don't do so except to operate, maintain, or debug the service, or if legally required. If you want data nobody but you can ever read, use the Local vault.

Because this app is about relationships, the content you enter is often about other people who have never used Black Server Book and never agreed to anything here. Please be thoughtful about what you record about someone else.

What we collect

Account email and password (password is never visible to us in plain text — Supabase handles authentication). Whatever content you enter into the Synced vault. Basic technical error reports (an error message, rough context like which browser, and your account id if you're logged in when it happens) so we can find and fix bugs — see "Error reports" below.

Error reports

When something breaks in the app, a small report (error message, browser/user-agent string, timestamp, and your account id if logged in) is sent to us automatically, so we can find and fix it. This happens whether or not you have an account — it's the same mechanism either way. These reports are not used for anything except fixing bugs.

What we don't do

We don't sell your data. We don't show ads. We don't share Synced data with third parties except the infrastructure providers needed to run the service itself (currently: Supabase for hosting/auth/database).

Payments

If/when a paid tier exists, payment is processed by Stripe — we don't store your card details ourselves.

Deleting your data

You can permanently delete everything in your Synced vault yourself, at any time, from Settings in the app — see "Delete my account and data." This doesn't touch your Local vault (which is entirely on your own device, so it's yours to delete however you already delete files).

Contact

Questions about this policy: [your contact email].