Privacy
Last updated: October 8, 2026
SharpMD works without an account, with no trackers and no third-party analytics. Cloud notes are optional, and your notes leave your machine only if you send them there.
Your files
The files you open are read by your browser, on your machine. They are never uploaded. When you save, the browser writes to the file or folder you picked.
What is stored, and where
Settings, reading positions and the list of recently opened folders are stored in your browser, on your device. Clearing the site or extension data removes them.
With the extension installed, the web app and the extension share one store on your device: browser notes, the list of recently opened files and folders, and display preferences. They pass between the two inside your browser, never over the network. If both use the same sync server, they also share the cloud session, so signing in or out on one side does the same on the other; with the cloud off or a different server on one side, each keeps its own. The web app receives the text of a file from your disk only when you open a link to it, confirm, and the file is in a folder you already opened with the extension; it stays inside your browser, and you can turn this off in Settings, under Install. The copies of cloud notes and the keys of protected folders are not shared.
Anonymous counts
No trackers and no third-party analytics. The site and the web app count a few anonymous events (a visit, the app opened, an account created) to know whether the product works. No cookie, no identifier, nothing about your notes. You can turn it off in Settings, and the extension sends none.
- What is sent to
sync.sharpmd.app: the name of the event, the page, and the channel the visit came from as one word: "reddit", "google", "direct", or the label a link carried inutm_source. On the home page, also which of two headlines was shown. Never the address you came from, the address of a page, a title, a file name, a search or your email. - The events. On the site: a page seen, a click on a button that opens the app or the plans, and the checkout opened. In the web app and the Android app: the app opened, and the first time in that browser that it was opened, that a note was created or opened, and that an edit was saved.
- What the server keeps: a number per day, event and channel. It does not store the IP address, the browser or anything that tells one visitor from another. The IP address is used in memory to limit how many counts one address sends, and is not written anywhere. Nobody is followed from one step to the next.
- What your browser keeps: the channel of your first visit, and which first-time events were already sent, so each one is sent once. Many people share those values. They are not identifiers.
- With an account, the server counts some steps as they happen: a sign-in code requested, an account created, a sign-in, and the first cloud note, AI token, share and payment of an account. It keeps the channel the account came from on the account, as that one word, and deletes it with the account. The server makes these counts from requests it receives anyway. With the counts turned off, the app does not send the channel.
- Nothing is sent when your browser asks not to be tracked (Do Not Track or Global Privacy Control), when you turn off "Send anonymous usage counts" in Settings, Advanced, or when the app uses your own server or no cloud. The extension sends no counts, over a file from your disk or on its own page. Published sites and copies of the app hosted somewhere else send none either.
Cloud notes, if you sign in
The sync server stores your email address, the notes you send to the cloud and, on the paid plan, their previous versions for 30 days. Sign-in codes, sessions and AI tokens are stored as hashes.
- The server stores the text of your notes, of their previous versions and of the comments you leave for the AI encrypted (AES-256-GCM). That protects the database and its backups. It is not end-to-end encryption: the running server holds the key, because it has to read notes to share them and to serve your AI over MCP.
- A folder you protect with a password is end-to-end encrypted. Its notes are encrypted in your browser before they are uploaded, with a key that only your password or your backup key opens. The server stores the encrypted text and cannot read it. The password and the key do not leave your browser.
- You can also protect your whole cloud with one password, from Settings, under Cloud. Every note and image of your account is then encrypted in your browser the same way, the ones you already had and new ones, and what this page says about a protected folder applies to all of them. With the whole cloud protected nothing can be shared, published as a site or automated until you remove the protection.
- The first time you save a note to the cloud, the app tells you once that the cloud is encrypted with a key the server holds, and that a password keeps even the server from reading your notes. The server records that the notice was shown to your account, so it does not appear again on another device.
- What the server still sees of a protected folder: the names of its notes and folders, their size and when they changed. Those notes cannot be shared, have no public links, take no comments for the AI and are left out of the server search.
- Without the password and without the backup key, the notes of a protected folder cannot be recovered. SharpMD cannot recover them either.
- If you unlock a protected folder for your AI, your browser sends the key of that folder to the server. The server keeps it in memory only, for the time you chose (15 minutes, 1 hour, 8 hours, or until you lock it), and meanwhile it can read and write the notes of that folder to serve your AI. Locking the folder, the time running out or a server restart erases the key. It is never written to disk.
- A note you share is visible to the accounts you share it with. A public link shows it to anyone who has the link, and the password if you set one.
- For each cloud note the server keeps who made its last save, and for each version in the history who had written it: the account, the AI token or the name a guest of a live session chose. It is shown, with the time, to the people who can already open that note. Who has a note open right now, people and AI agents working with one of your tokens, is shown the same way and kept only in the memory of the server for as long as it lasts.
- On a team plan the server stores the name of the team, which accounts belong to it and the invitations that are waiting: the email address that was invited, until the invitation is accepted, declined or removed. The invitation is sent by email through Resend and says who invites. Members see the email addresses of the other members. The notes in the team space belong to the team: every member reads them, administrators and editors edit them, and they stay with the team when someone leaves. Your own notes stay yours: nobody in the team, including whoever manages it, can read them. The server also stores the role of each member and the settings the administrators chose for the team space, with the template for new notes if they wrote one.
- A team has an activity log of its shared space, which only its administrators can read. Each entry holds what was done (created, edited, moved, deleted, restored, shared, a public link, an invitation, a role or a setting changed, the space protected, an AI connecting), the path of the note, the account that did it, the name of the token if it was an AI, and the time. For a live session on a team note it also holds who opened it, who ended it, and the name a guest chose when what they wrote was saved or when they were removed. It never holds the text of a note, and it holds no email address: not the one that was invited and not the one a note was shared with. The address of the person who acted is looked up from their account when an administrator opens the log, so once an account is deleted its entries show no name. With a protected space the paths of the notes are in the log, as they are in the rest of the server. Entries are deleted after 90 days, and the whole log is deleted with the team. Your personal settings (appearance, language, tools) and your own notes are never in it. The version history of the team space is kept for up to a year, or less if the administrators say so.
- Whoever manages a team can protect the team space with one password. The notes of the team are then encrypted in each member's browser, and of that space the server stores what it stores of a protected folder: the salt, the number of rounds, the key wrapped with the password and a check value, plus the names of the notes and folders, their size and when they changed. It never receives the password or the key, unless a member unlocks the space for their own AI, under the same terms as a protected folder. It also stores whether members may do that, and that someone has left the team since the password last changed. Members get the password from whoever manages the team, outside SharpMD. What a member already read or copied cannot be taken back when they leave.
- The sign-in code is sent by email through Resend, which receives your address to deliver it. The button in that email carries your address and the code after the
#of the link, a part your browser does not send to any server; the app removes it from the address bar as it reads it and does not store it. - When you send feedback or report a note, the server stores the text you wrote, your email address if you gave one or were signed in, and four details: the version of the app, whether it was the web app or the extension, your browser and your language. It is also sent by email to SharpMD. It never includes your notes. It is deleted after 180 days, or when you delete your account.
- Payments are handled by Paddle, the merchant of record. SharpMD never sees your card: it only learns that the subscription for your account is active or has ended.
- A copy of each cloud note you open is kept in your browser, so it opens without a connection. The copy of a note in a protected folder is kept encrypted. Signing out removes those copies, except edits that have not been uploaded yet.
- "Remember on this device" keeps the key of a protected folder in your browser, in a form that cannot be exported. "Forget on this device", locking the folder or signing out removes it.
- Deleting a cloud note moves it to the trash, where it stays for 30 days and can be restored. After that, or when you delete it from the trash or empty the trash, it is removed from the server. A note from a protected folder stays encrypted in the trash.
Images
When you paste, drop or pick an image, SharpMD makes it smaller in your browser before saving it and removes its metadata: camera, date and location. With the image quality set to "Original" in Settings the file is kept as it is, metadata included.
In a folder on your disk the image is saved next to the document, and in a note kept in the browser it stays inside the note. Neither leaves your device. In a cloud note the image is uploaded to sync.sharpmd.app as an attachment: the server stores the file, its type, its size, a hash and the date. It does not store the name the file had. The note keeps the address of the image.
That address works like a public link: anyone who has it can see the image, without an account. It is long and random and nothing lists it, but sharing the note, a public link, a live session or a published site hands it to whoever reads the note, and it keeps working for them until the image is deleted. Images in a protected folder are different: they are encrypted in your browser with the key of the folder, the server cannot read them and they have no public address. Protecting a folder that already had images encrypts them too and deletes the readable copies, unless a note outside the folder uses them. For those images the app tells the server which ones each note uses, by their identifiers only, so the unused ones can be deleted.
An image that no note uses is deleted from the server after 30 days, and at once if you delete it in Settings, Cloud, Storage. Deleting your account deletes all of them.
Deleting your account
You delete the account yourself in the app: Settings, Cloud, "Delete account", and type the account's email to confirm. You can also write to hello@sharpmd.app from the account's email and it is deleted for you.
What is deleted from the server: your email address, your notes, their version history, the trash, the comments for the AI, the feedback you sent, your contributions to the community gallery, the AI tokens, the sessions, what you shared and what was shared with you, the public links, the sites you published, the protected folders and the live sessions. The copies kept in your browser are removed too. It cannot be undone.
If the account pays a subscription, cancel it first: the server does not delete an account that is still being charged. If you are a member of a team, you leave the team and its notes stay with the team. If you manage a team, remove its other members first; the team and its notes are deleted with your account.
Community gallery
In Settings, Tools you can add templates, themes and diagram palettes that other people shared, and share yours. Looking at the gallery and adding from it needs no account. What you add is kept in your browser.
Sharing needs an account. What is sent is what the preview shows: the type, the name, the description, the language, the public name you choose and the content (the open note as a template, your current theme, or a palette). Nothing else from the app goes with it. The server stores that with your account, so you can see its state and withdraw it. It is reviewed by a person before it is published. Once approved it is public for everyone, under the public name you chose; your email address is never shown.
The server counts how many times each contribution was added. It is a number: it does not record who added it. You can withdraw a contribution in the same place, and it is deleted from the server. Deleting your account deletes your contributions too. Copies other people already added stay on their devices.
Published sites
On the paid plan you can publish a cloud folder as a public website. Nothing is public until you press Publish, and only the notes of the folder you chose are published. Notes in a folder protected with a password are never published, and a note with publish: false in its front matter is left out.
What becomes public: the title and the text of each published note as a web page, the images embedded in it, the title of the site, the address you chose and, if you write one, an author name. Your email address does not appear on the site. Anyone with the address can read it, and search engines can index it unless you ask them not to in the settings of the site. The pages are drawn in your browser and the server stores them as they are served, without encryption at rest, because they are public.
To take it down, open the site from the menu of its folder or from Settings, Cloud and choose Unpublish: the pages stop being served right away and are deleted from the server. Deleting the site also frees its address. Deleting a note removes its page at once. If the account leaves the paid plan, the site is unpublished after 7 days and its settings are kept. Copies that other people or search engines made while it was public are out of our reach. Deleting your account deletes your sites.
Whoever visits a published site is not tracked: the pages carry no analytics, no third-party scripts and no cookies, and the choice of light or dark stays in the visitor's browser. An image the author linked from another server is loaded from that server. A site that breaks the rules can be suspended: how to report one.
Automations
On the paid plan you can make SharpMD send a notice to an address you choose (Slack, Make, n8n, Zapier or your own) when a note or a kanban card changes. That address receives the type of event, the date, an opaque id of the account (never your email address), the path of the note and a link to open it, who made the change (the app, the API, an AI, or an opaque id and the role of a team member, never their name or address) and the data of the event: for a card, its title, column, dates and attributes. The text of the note is sent only if you turn that on for that automation. Notes in a protected folder never produce a notice. What happens with the data at that address depends on the service you chose.
The server stores the address and the signing secret of each automation, encrypted at rest. Of each delivery it keeps the type of event, the path of the note, whether it arrived, the response code and how long it took, for the last 50 deliveries of each automation and up to 30 days. The content that was sent is deleted once it is delivered or given up. An inbound address lets whoever has it add text to one note: the server stores a hash of its secret, how many times it was used and when. A token for the API reaches the same notes as a token for an AI. Deleting the account deletes all of this.
Live sessions
On the paid plan you can open a live session on one of your cloud notes and pass its link to other people. They join from the web, without an account, and edit the note with you.
- What a guest sees: that note and nothing else. Its text while the session is open, the name you chose for the session, the names of the other people in it and the block each one is in. Not your email, not your other notes or folders, not the history of the note.
- What is kept about a guest: the name they chose, in the memory of the server while they are in the session, and a re-entry key stored as a hash so they can come back after a dropped connection. No email and no account. Both are gone when the session ends, when you remove that guest or when they leave. Their own browser remembers the name, to suggest it next time.
- What a guest writes becomes part of your note, like any other edit, and of its version history.
- The link is the key: whoever has it can read and edit that note until the session ends. The server stores only a hash of its secret. The secret travels after the # of the address, which the browser does not send to the site that hosts the web version.
- You can end the session at any time: every guest loses access at once and the link stops working. Removing one guest cuts their access at once and changes the link. A session ends by itself after 12 hours with nobody connected, and when its note is deleted, renamed or moved.
- On a note of a team, a member who can edit opens the session if the administrators allow it. The other members who have the note open are in it from their account, without the link, and guests see the visible name each one chose, never an email. Whoever opened it or an administrator can end it, and it ends by itself if that member can no longer open one. A guest reaches that note and nothing else of the team. A team space protected with a password has no live sessions.
- A note in a password-protected folder cannot be opened live: the server cannot read it.
Dictation and reading aloud
Both are tools you turn on in Settings, Tools. They are off until you do.
- Reading aloud uses the voices installed in your device or browser. The text is not sent to SharpMD or to any service of ours.
- Dictation uses the speech recognition of your browser. SharpMD does not receive, record or store audio: it only gets the text the browser returns, and writes it in your note.
- Where the audio is transcribed depends on the browser. If it can recognize speech on the device, SharpMD offers to download that language and uses it, and the audio does not leave the device. If not, the browser may send the audio to its own provider (in Chrome, Google; in Safari, Apple) to transcribe it. The app tells you this before the first time and waits for you to accept.
- The microphone turns on only when you press its button or its shortcut. While it listens there is a fixed indicator with a button to stop. It stops by itself when you switch notes, leave the tab or stay silent for a while.
- What is stored: your choices (the tools turned on, the language, the voice, the speed) and that you accepted the notice, in your browser.
AI assistant with your own key
A tool you turn on in Settings, Tools. It is off until you do, and SharpMD provides no AI of its own: you connect a key from your provider: Claude (Anthropic), OpenAI, Google Gemini, DeepSeek, Groq, Kimi (Moonshot AI), MiniMax, Mistral, OpenRouter, Together AI or xAI (Grok), or an OpenAI-compatible server such as Ollama or LM Studio. You can keep one key per provider.
- What is stored: the provider, its address, the model and your key, only in the browser of that device. The key is encrypted with a key the browser does not let anyone export. If you choose to be asked for a password, that key comes from the password, which is not stored.
- The key is not sent to SharpMD, is not part of the settings shared between the web app and the extension, and is not written to notes, exports or feedback. On screen only its last four characters are shown.
- The text you send to the assistant (the selection, the block or the note you ask about) goes from your browser straight to the provider you chose. That provider bills it and handles it under its own terms. Nothing of it goes through
sync.sharpmd.app. - Text from a protected folder is sent only if you confirm it that time, and an option stops it for good.
- The conversation in the panel is kept in memory and is gone when you close it. Only what you insert into the note is saved.
- The limit: a key in a browser is protected from other sites and from our server, not from someone using your unlocked device. A key with a spending limit is the safer choice, and you can remove it in the same place where you added it.
Network requests
- The extension installed from its ZIP checks once a day the version number published on GitHub, to tell you when there is an update. It sends no data, and you can make it weekly or turn it off in Settings. The Chrome Web Store version does not make this request.
- Images that a document links from the web are loaded from where the document points.
- With cloud notes in use, the app talks to
sync.sharpmd.app. - With the AI assistant on and your key added, the app talks to the provider you chose, at the address shown next to its key (for example
api.anthropic.com,api.openai.comorgenerativelanguage.googleapis.com, or the server address you typed), and only when you ask it for something. - The site and the web app at
sharpmd.appsendsync.sharpmd.appanonymous counts: what they are and how to turn them off. - The web version is a static page hosted on GitHub Pages. GitHub, as the host, may log the address of the visitor like any web server.
Permissions of the extension
file:///*and all sites: to render a Markdown file wherever it lives, local or served by a website. The extension only acts on addresses that end in a Markdown extension, and on the SharpMD web app, to share the browser notes with it. When you click its button it checks that the web app answers before opening it. A link to the web app can ask to open a Markdown file from your disk: the path travels in the fragment of the address (after the #), which the browser does not send to any server, and the extension only takes that tab to the file after you confirm. The web app does not get the contents of the file.storage: to keep your settings and browser notes in the browser.scripting: to load the math and diagram libraries only when a document uses them.
Questions
Write to hello@sharpmd.app. Support has the common fixes. The rules of the hosted service are in the Terms.
Privacidad
Última actualización: 8 de octubre de 2026
SharpMD funciona sin cuenta, sin rastreadores ni analítica de terceros. Las notas en la nube son opcionales, y tus notas salen de tu máquina solo si las mandás ahí.
Tus archivos
Los archivos que abrís los lee tu navegador, en tu máquina. Nunca se suben. Al guardar, el navegador escribe en el archivo o la carpeta que elegiste.
Qué se guarda y dónde
Los ajustes, la posición de lectura y la lista de carpetas recientes se guardan en tu navegador, en tu dispositivo. Si borrás los datos del sitio o de la extensión, se van.
Con la extensión instalada, la app web y la extensión comparten un solo depósito en tu dispositivo: las notas del navegador, la lista de archivos y carpetas recientes y las preferencias de apariencia. Pasan de una a la otra dentro de tu navegador, nunca por la red. Si las dos usan el mismo servidor de sincronización, comparten también la sesión de la nube: entrar o salir de un lado hace lo mismo del otro; con la nube apagada o con otro servidor de un lado, cada una sigue con la suya. La app web recibe el texto de un archivo de tu disco solo cuando abrís un enlace a ese archivo, confirmás, y el archivo está en una carpeta que ya abriste con la extensión; queda dentro de tu navegador, y se puede apagar en Ajustes, en Instalar. Las copias de las notas de la nube y las llaves de las carpetas protegidas no se comparten.
Conteos anónimos
Sin rastreadores ni analítica de terceros. El sitio y la app web cuentan unos pocos eventos anónimos (una visita, la app abierta, una cuenta creada) para saber si el producto funciona. Sin cookie, sin identificador y sin nada de tus notas. Se apaga en Ajustes, y la extensión no manda ninguno.
- Qué se manda a
sync.sharpmd.app: el nombre del evento, la página y el canal por el que llegó la visita, en una palabra: "reddit", "google", "direct", o la etiqueta que traía el enlace enutm_source. En la portada, también cuál de dos titulares se mostró. Nunca la dirección de la que venís, la dirección de una página, un título, un nombre de archivo, una búsqueda ni tu correo. - Los eventos. En el sitio: una página vista, un clic en un botón que abre la app o los planes, y el cobro abierto. En la app web y en la app de Android: la app abierta, y la primera vez en ese navegador que se abrió, que se creó o se abrió una nota, y que se guardó una edición.
- Qué guarda el servidor: un número por día, evento y canal. No guarda la dirección IP, el navegador ni nada que distinga a un visitante de otro. La dirección IP se usa en memoria para limitar cuántos conteos manda una misma dirección, y no se escribe en ningún lado. A nadie se lo sigue de un paso al otro.
- Qué guarda tu navegador: el canal de tu primera visita, y cuáles eventos de primera vez ya se mandaron, para mandar cada uno una sola vez. Son valores que mucha gente comparte. No son identificadores.
- Con una cuenta, el servidor cuenta algunos pasos cuando pasan: un código de ingreso pedido, una cuenta creada, un ingreso, y la primera nota en la nube, el primer token de IA, el primer compartir y el primer pago de una cuenta. En la cuenta guarda el canal por el que llegó, con esa misma palabra, y lo borra con la cuenta. El servidor hace esos conteos con pedidos que recibe igual. Con los conteos apagados, la app no manda el canal.
- No se manda nada cuando tu navegador pide que no lo sigan (Do Not Track o Global Privacy Control), cuando apagás "Mandar conteos de uso anónimos" en Ajustes, Avanzado, ni cuando la app usa tu propio servidor o va sin nube. La extensión no manda conteos, ni sobre un archivo de tu disco ni en su propia página. Los sitios publicados y las copias de la app alojadas en otro lado tampoco.
Notas en la nube, si entrás con tu cuenta
El servidor de sincronización guarda tu correo, las notas que mandás a la nube y, en el plan pago, sus versiones anteriores durante 30 días. Los códigos de acceso, las sesiones y los tokens para la IA se guardan como hashes.
- El servidor guarda cifrado (AES-256-GCM) el texto de tus notas, de sus versiones anteriores y de los comentarios que le dejás a la IA. Eso protege la base y sus respaldos. No es cifrado de punta a punta: el servidor en marcha tiene la clave, porque tiene que leer las notas para compartirlas y para dárselas a tu IA por MCP.
- Una carpeta que protegés con contraseña va cifrada de punta a punta. Sus notas se cifran en tu navegador antes de subir, con una llave que solo abren tu contraseña o tu clave de respaldo. El servidor guarda el texto cifrado y no lo puede leer. La contraseña y la llave no salen de tu navegador.
- También podés proteger toda tu nube con una sola contraseña, desde Ajustes, en Nube. Todas las notas e imágenes de tu cuenta se cifran entonces en tu navegador de la misma forma, las que ya tenías y las nuevas, y lo que esta página dice de una carpeta protegida vale para todas. Con toda la nube protegida nada se comparte, se publica como sitio ni se automatiza hasta que quites la protección.
- La primera vez que guardás una nota en la nube, la app te dice una sola vez que la nube está cifrada con una llave que tiene el servidor, y que con una contraseña ni el servidor puede leer tus notas. El servidor anota que ese aviso ya se le mostró a tu cuenta, para que no vuelva a aparecer en otro dispositivo.
- Lo que el servidor sigue viendo de una carpeta protegida: los nombres de sus notas y carpetas, cuánto pesan y cuándo cambiaron. Esas notas no se comparten, no tienen enlaces públicos, no llevan comentarios para la IA y quedan fuera de la búsqueda del servidor.
- Sin la contraseña y sin la clave de respaldo, las notas de una carpeta protegida no se pueden recuperar. SharpMD tampoco puede.
- Si desbloqueás una carpeta protegida para tu IA, tu navegador le manda al servidor la llave de esa carpeta. El servidor la guarda solo en memoria, por el tiempo que elegiste (15 minutos, 1 hora, 8 horas, o hasta que la bloquees), y mientras tanto puede leer y escribir las notas de esa carpeta para tu IA. Bloquear la carpeta, vencer el plazo o reiniciar el servidor borran la llave. Nunca se escribe en el disco.
- De cada nota de la nube el servidor guarda quién hizo el último guardado, y de cada versión del historial quién la había escrito: la cuenta, el token de IA o el nombre que eligió un invitado de una sesión en vivo. Se muestra, con la hora, a quienes ya pueden abrir esa nota. Quién tiene abierta una nota en este momento, personas y agentes de IA que trabajan con uno de tus tokens, se muestra igual y queda solo en la memoria del servidor mientras dura.
- Una nota compartida la ven las cuentas con las que la compartís. Un enlace público se la muestra a quien tenga el enlace, y la contraseña si le pusiste una.
- En un plan de equipo el servidor guarda el nombre del equipo, qué cuentas lo integran y las invitaciones que esperan respuesta: el correo invitado, hasta que la invitación se acepta, se rechaza o se quita. La invitación llega por correo a través de Resend y dice quién invita. Los miembros ven el correo de los demás miembros. Las notas del espacio del equipo son del equipo: todos los miembros las leen, quienes administran o editan las cambian, y quedan en el equipo cuando alguien sale. Tus notas propias siguen siendo tuyas: nadie del equipo, tampoco quien lo administra, puede leerlas. El servidor guarda además el papel de cada miembro y los ajustes que eligieron quienes administran el espacio del equipo, con la plantilla de las notas nuevas si escribieron una.
- Un equipo tiene un registro de actividad de su espacio compartido, que solo leen quienes lo administran. Cada fila guarda qué se hizo (crear, editar, mover, eliminar, restaurar, compartir, un enlace público, una invitación, un cambio de papel o de ajuste, la protección del espacio, la entrada de una IA), la ruta de la nota, la cuenta que lo hizo, el nombre del token si fue una IA, y el momento. De una sesión en vivo sobre una nota del equipo guarda además quién la abrió, quién la terminó, y el nombre que eligió un invitado cuando se guardó lo que escribió o cuando lo sacaron. Nunca guarda el texto de una nota, y no guarda ningún correo: ni el que se invitó ni aquel con el que se compartió una nota. El correo de quien hizo algo se busca en su cuenta cuando alguien que administra abre el registro, así que si la cuenta se elimina sus filas quedan sin nombre. Con el espacio protegido, las rutas de las notas figuran en el registro, igual que en el resto del servidor. Las filas se borran a los 90 días, y el registro entero se borra con el equipo. Tus ajustes personales (apariencia, idioma, herramientas) y tus notas propias nunca están ahí. El historial de versiones del espacio del equipo se guarda hasta un año, o menos si quienes administran lo deciden.
- Quien administra un equipo puede proteger el espacio del equipo con una sola contraseña. Las notas del equipo se cifran entonces en el navegador de cada miembro, y de ese espacio el servidor guarda lo mismo que de una carpeta protegida: la sal, la cantidad de vueltas, la llave envuelta con la contraseña y un valor de comprobación, además de los nombres de las notas y de las carpetas, su tamaño y cuándo cambiaron. Nunca recibe la contraseña ni la llave, salvo que un miembro desbloquee el espacio para su propia IA, en las mismas condiciones que una carpeta protegida. También guarda si los miembros pueden hacerlo, y que alguien salió del equipo desde el último cambio de contraseña. Los miembros reciben la contraseña de quien administra el equipo, por fuera de SharpMD. Lo que un miembro ya leyó o copió no se puede retirar cuando sale.
- El código de acceso llega por correo a través de Resend, que recibe tu dirección para entregarlo. El botón de ese correo lleva tu dirección y el código después del
#del enlace, una parte que tu navegador no le manda a ningún servidor; la app lo saca de la barra de direcciones al leerlo y no lo guarda. - Cuando mandás un comentario o denunciás una nota, el servidor guarda el texto que escribiste, tu correo si lo diste o tenías la sesión abierta, y cuatro datos: la versión de la app, si era la app web o la extensión, tu navegador y tu idioma. También le llega por correo a SharpMD. Nunca incluye tus notas. Se borra a los 180 días, o cuando eliminás tu cuenta.
- Los pagos los maneja Paddle, que es quien vende. SharpMD nunca ve tu tarjeta: solo se entera de que la suscripción de tu cuenta está activa o terminó.
- De cada nota de la nube que abrís queda una copia en tu navegador, para abrirla sin conexión. La copia de una nota de una carpeta protegida queda cifrada. Al salir de la cuenta esas copias se borran, salvo lo escrito que todavía no se subió.
- "Recordar en este dispositivo" guarda la llave de una carpeta protegida en tu navegador, de una forma que no se puede exportar. "Olvidar en este dispositivo", bloquear la carpeta o salir de la cuenta la borran.
- Al eliminar una nota de la nube pasa a la papelera, donde queda 30 días y se puede restaurar. Después, o cuando la eliminás de la papelera o la vaciás, se borra del servidor. Una nota de una carpeta protegida sigue cifrada en la papelera.
Imágenes
Cuando pegás, arrastrás o elegís una imagen, SharpMD la achica en tu navegador antes de guardarla y le quita los metadatos: cámara, fecha y ubicación. Con la calidad de las imágenes en "Original", en Ajustes, el archivo queda como es, con sus metadatos.
En una carpeta de tu disco la imagen se guarda al lado del documento, y en una nota guardada en el navegador queda dentro de la nota. Ninguna de las dos sale de tu dispositivo. En una nota de la nube la imagen se sube a sync.sharpmd.app como adjunto: el servidor guarda el archivo, su tipo, su tamaño, un hash y la fecha. No guarda el nombre que tenía el archivo. La nota guarda la dirección de la imagen.
Esa dirección funciona como un enlace público: quien la tiene puede ver la imagen, sin cuenta. Es larga y al azar y nada la lista, pero compartir la nota, un enlace público, una sesión en vivo o un sitio publicado se la da a quien lee la nota, y le sigue sirviendo hasta que la imagen se borra. Las imágenes de una carpeta protegida son distintas: se cifran en tu navegador con la llave de la carpeta, el servidor no las puede leer y no tienen dirección pública. Proteger una carpeta que ya tenía imágenes también las cifra y borra las copias legibles, salvo que una nota de afuera las use. De esas imágenes la app le dice al servidor cuáles usa cada nota, solo por sus identificadores, para que se puedan borrar las que nadie usa.
Una imagen que ninguna nota usa se borra del servidor a los 30 días, y en el momento si la borrás en Ajustes, Nube, Almacenamiento. Eliminar tu cuenta las borra todas.
Eliminar tu cuenta
La cuenta la eliminás vos desde la app: Ajustes, Nube, "Eliminar la cuenta", y escribís el correo de la cuenta para confirmar. También podés escribir a hello@sharpmd.app desde el correo de la cuenta y la eliminamos.
Qué se borra del servidor: tu correo, tus notas, su historial de versiones, la papelera, los comentarios para la IA, los comentarios que mandaste, tus aportes a la galería de la comunidad, los tokens para la IA, las sesiones, lo que compartiste y lo que te compartieron, los enlaces públicos, los sitios que publicaste, las carpetas protegidas y las sesiones en vivo. Las copias guardadas en tu navegador también se quitan. No se puede deshacer.
Si la cuenta paga una suscripción, primero cancelala: el servidor no elimina una cuenta que se sigue cobrando. Si sos miembro de un equipo, salís del equipo y sus notas quedan en el equipo. Si administrás un equipo, primero sacá a los demás miembros; el equipo y sus notas se eliminan con tu cuenta.
Galería de la comunidad
En Ajustes, Herramientas podés agregar plantillas, temas y paletas de diagramas que compartió otra gente, y compartir los tuyos. Mirar la galería y agregar de ella no pide cuenta. Lo que agregás queda en tu navegador.
Compartir pide una cuenta. Se envía lo que muestra la vista previa: el tipo, el nombre, la descripción, el idioma, el nombre público que elegís y el contenido (la nota abierta como plantilla, tu tema actual o una paleta). Nada más de la app viaja con eso. El servidor lo guarda junto a tu cuenta, para que veas su estado y puedas retirarlo. Lo revisa una persona antes de publicarse. Una vez aprobado queda público para todos, con el nombre público que elegiste; tu correo no se muestra nunca.
El servidor cuenta cuántas veces se agregó cada aporte. Es un número: no registra quién lo agregó. Podés retirar un aporte desde el mismo lugar, y se borra del servidor. Al eliminar tu cuenta se borran también tus aportes. Las copias que otra gente ya agregó quedan en sus dispositivos.
Sitios publicados
En el plan pago podés publicar una carpeta de la nube como sitio web público. Nada es público hasta que tocás Publicar, y se publican solo las notas de la carpeta que elegiste. Las notas de una carpeta protegida con contraseña no se publican nunca, y una nota con publish: false en su encabezado queda afuera.
Qué queda público: el título y el texto de cada nota publicada, como página web, las imágenes incrustadas en ella, el título del sitio, la dirección que elegiste y, si escribís uno, un nombre de autor. Tu correo no aparece en el sitio. Cualquiera que tenga la dirección puede leerlo, y los buscadores pueden indexarlo salvo que pidas lo contrario en los ajustes del sitio. Las páginas se dibujan en tu navegador y el servidor las guarda como se sirven, sin cifrado en reposo, porque son públicas.
Para bajarlo, abrí el sitio desde el menú de su carpeta o desde Ajustes, Nube y elegí Despublicar: las páginas dejan de servirse en el momento y se borran del servidor. Eliminar el sitio además libera su dirección. Eliminar una nota saca su página en el acto. Si la cuenta deja el plan pago, el sitio se despublica a los 7 días y sus ajustes quedan guardados. Las copias que otra gente o los buscadores hayan hecho mientras fue público quedan fuera de nuestro alcance. Al eliminar tu cuenta se borran tus sitios.
A quien visita un sitio publicado no se lo sigue: las páginas no llevan analítica, scripts de terceros ni cookies, y la elección de claro u oscuro queda en el navegador de quien visita. Una imagen que el autor enlazó desde otro servidor se carga de ese servidor. Un sitio que rompe las reglas se puede suspender: cómo denunciar uno.
Automatizaciones
En el plan pago podés hacer que SharpMD mande un aviso a una dirección que elegís (Slack, Make, n8n, Zapier o una propia) cuando cambia una nota o una tarjeta de un tablero. Esa dirección recibe el tipo de evento, la fecha, un identificador opaco de la cuenta (nunca tu correo), la ruta de la nota y un enlace para abrirla, quién hizo el cambio (la app, la API, una IA, o un identificador opaco y el papel de alguien del equipo, nunca su nombre ni su correo) y los datos del evento: de una tarjeta, su título, su columna, sus fechas y sus atributos. El texto de la nota viaja solo si lo prendés en esa automatización. Las notas de una carpeta protegida nunca generan un aviso. Lo que pasa con esos datos en esa dirección depende del servicio que elegiste.
El servidor guarda la dirección y el secreto de firma de cada automatización, cifrados en reposo. De cada entrega guarda el tipo de evento, la ruta de la nota, si llegó, el código de la respuesta y cuánto tardó, para las últimas 50 entregas de cada automatización y hasta 30 días. El contenido que se mandó se borra cuando se entrega o se da por perdido. Una dirección de entrada le deja a quien la tiene agregar texto a una nota: el servidor guarda un hash de su secreto, cuántas veces se usó y cuándo. Un token para la API llega a las mismas notas que un token para una IA. Eliminar la cuenta borra todo esto.
Sesiones en vivo
Con el plan pago podés abrir una sesión en vivo sobre una de tus notas de la nube y pasarle el enlace a otras personas. Entran desde la web, sin cuenta, y editan la nota con vos.
- Qué ve un invitado: esa nota y nada más. Su texto mientras la sesión esté abierta, el nombre que elegiste para la sesión, los nombres de las demás personas y en qué bloque está cada una. No ve tu correo, ni tus otras notas o carpetas, ni el historial de la nota.
- Qué se guarda de un invitado: el nombre que eligió, en la memoria del servidor mientras está en la sesión, y una contraseña de reingreso guardada como hash, para que pueda volver si se le corta la conexión. Ni correo ni cuenta. Las dos cosas se van cuando termina la sesión, cuando sacás a ese invitado o cuando sale. Su propio navegador recuerda el nombre, para proponérselo la próxima vez.
- Lo que escribe un invitado pasa a ser parte de tu nota, como cualquier otra edición, y de su historial de versiones.
- El enlace es la llave: quien lo tenga puede leer y editar esa nota hasta que la sesión termine. El servidor guarda solo un hash de su secreto. El secreto viaja después del # de la dirección, que el navegador no le manda al sitio que aloja la versión web.
- Podés terminar la sesión cuando quieras: todos los invitados pierden el acceso en el acto y el enlace deja de servir. Sacar a un invitado le corta el acceso en el acto y cambia el enlace. Una sesión termina sola a las 12 horas sin nadie conectado, y cuando su nota se elimina, cambia de nombre o se mueve.
- En una nota de un equipo, la abre un miembro que puede editar, si quienes administran lo permiten. Los demás miembros que tienen la nota abierta participan desde su cuenta, sin el enlace, y los invitados ven el nombre visible que eligió cada uno, nunca un correo. La termina quien la abrió o alguien que administra, y termina sola si ese miembro ya no puede abrir una. Un invitado alcanza esa nota y nada más del equipo. Un espacio de equipo protegido con contraseña no tiene sesiones en vivo.
- Una nota de una carpeta protegida con contraseña no se puede abrir en vivo: el servidor no la puede leer.
Dictado y lectura en voz alta
Las dos son herramientas que prendés en Ajustes, Herramientas. Hasta entonces están apagadas.
- La lectura en voz alta usa las voces instaladas en tu dispositivo o en tu navegador. El texto no se manda a SharpMD ni a ningún servicio nuestro.
- El dictado usa el reconocimiento de voz de tu navegador. SharpMD no recibe, no graba y no guarda audio: solo le llega el texto que devuelve el navegador, y lo escribe en tu nota.
- Dónde se transcribe el audio depende del navegador. Si puede reconocer la voz en el dispositivo, SharpMD ofrece descargar ese idioma y lo usa, y el audio no sale del dispositivo. Si no, el navegador puede enviar el audio a su propio proveedor (en Chrome, Google; en Safari, Apple) para transcribirlo. La app te lo avisa antes de la primera vez y espera a que aceptes.
- El micrófono se prende solo cuando apretás su botón o su atajo. Mientras escucha hay un indicador fijo con un botón para cortar. Se corta solo al cambiar de nota, al salir de la pestaña y tras un rato de silencio.
- Qué se guarda: tus elecciones (las herramientas prendidas, el idioma, la voz, la velocidad) y que aceptaste el aviso, en tu navegador.
Asistente de IA con tu clave
Una herramienta que prendés en Ajustes, Herramientas. Hasta entonces está apagada, y SharpMD no da IA propia: conectás una clave de tu proveedor: Claude (Anthropic), OpenAI, Google Gemini, DeepSeek, Groq, Kimi (Moonshot AI), MiniMax, Mistral, OpenRouter, Together AI o xAI (Grok), o un servidor compatible con OpenAI como Ollama o LM Studio. Podés guardar una clave por proveedor.
- Qué se guarda: el proveedor, su dirección, el modelo y tu clave, solo en el navegador de ese dispositivo. La clave va cifrada con una llave que el navegador no deja exportar. Si elegís que te pida una contraseña, esa llave sale de la contraseña, que no se guarda.
- La clave no se manda a SharpMD, no forma parte de las preferencias que comparten la app web y la extensión, y no se escribe en notas, exportaciones ni comentarios. En pantalla se ven solo sus últimos cuatro caracteres.
- El texto que le mandás al asistente (lo elegido, el bloque o la nota sobre la que preguntás) va de tu navegador derecho al proveedor que elegiste. Ese proveedor lo cobra y lo trata según sus condiciones. Nada de eso pasa por
sync.sharpmd.app. - El texto de una carpeta protegida se envía solo si lo confirmás esa vez, y hay una opción para que no salga nunca.
- La conversación del panel queda en memoria y se pierde al cerrarlo. Se guarda solo lo que insertes en la nota.
- El límite: una clave en un navegador está protegida de otros sitios y de nuestro servidor, y no de alguien que use tu dispositivo desbloqueado. Conviene una clave con tope de gasto, y se quita en el mismo lugar donde la cargaste.
Pedidos de red
- La extensión instalada desde el ZIP mira una vez por día el número de versión publicado en GitHub, para avisarte cuando hay una actualización. No manda ningún dato, y desde Ajustes lo podés pasar a semanal o apagar. La versión de la tienda de Chrome no hace este pedido.
- Las imágenes que un documento enlaza desde la web se cargan desde donde apunta el documento.
- Con las notas en la nube en uso, la app habla con
sync.sharpmd.app. - Con el asistente de IA prendido y tu clave cargada, la app habla con el proveedor que elegiste, en la dirección que se ve junto a su clave (por ejemplo
api.anthropic.com,api.openai.comogenerativelanguage.googleapis.com, o la dirección del servidor que escribiste), y solo cuando le pedís algo. - El sitio y la app web de
sharpmd.apple mandan async.sharpmd.appconteos anónimos: qué son y cómo se apagan. - La versión web es una página estática alojada en GitHub Pages. GitHub, como alojamiento, puede registrar la dirección de quien la visita, como cualquier servidor web.
Permisos de la extensión
file:///*y todos los sitios: para mostrar un archivo Markdown esté donde esté, local o servido por un sitio web. La extensión solo actúa sobre direcciones que terminan en una extensión de Markdown, y sobre la app web de SharpMD, para compartir con ella las notas del navegador. Al tocar su botón consulta si la app web contesta antes de abrirla. Un enlace a la app web puede pedir que se abra un archivo Markdown de tu disco: la ruta viaja en el fragmento de la dirección (después del #), que el navegador no manda a ningún servidor, y la extensión solo lleva esa pestaña al archivo después de que confirmás. La app web no recibe el contenido del archivo.storage: para guardar tus ajustes y las notas del navegador.scripting: para cargar las librerías de matemática y diagramas solo cuando un documento las usa.
Consultas
Escribí a hello@sharpmd.app. En Ayuda están los arreglos más comunes. Las reglas del servicio alojado están en los Términos.
TermsTérminosPrivacyPrivacidadRefundsReembolsosAcceptable useUso aceptableCopyrightDerechos de autorSupportAyuda