SharpMD

Privacy

Last updated: October 8, 2026

SharpMD works without an account, with no trackers and no third-party analytics. Cloud notes are optional, and your notes leave your machine only if you send them there.

Your files

The files you open are read by your browser, on your machine. They are never uploaded. When you save, the browser writes to the file or folder you picked.

What is stored, and where

Settings, reading positions and the list of recently opened folders are stored in your browser, on your device. Clearing the site or extension data removes them.

With the extension installed, the web app and the extension share one store on your device: browser notes, the list of recently opened files and folders, and display preferences. They pass between the two inside your browser, never over the network. If both use the same sync server, they also share the cloud session, so signing in or out on one side does the same on the other; with the cloud off or a different server on one side, each keeps its own. The web app receives the text of a file from your disk only when you open a link to it, confirm, and the file is in a folder you already opened with the extension; it stays inside your browser, and you can turn this off in Settings, under Install. The copies of cloud notes and the keys of protected folders are not shared.

Anonymous counts

No trackers and no third-party analytics. The site and the web app count a few anonymous events (a visit, the app opened, an account created) to know whether the product works. No cookie, no identifier, nothing about your notes. You can turn it off in Settings, and the extension sends none.

Cloud notes, if you sign in

The sync server stores your email address, the notes you send to the cloud and, on the paid plan, their previous versions for 30 days. Sign-in codes, sessions and AI tokens are stored as hashes.

Images

When you paste, drop or pick an image, SharpMD makes it smaller in your browser before saving it and removes its metadata: camera, date and location. With the image quality set to "Original" in Settings the file is kept as it is, metadata included.

In a folder on your disk the image is saved next to the document, and in a note kept in the browser it stays inside the note. Neither leaves your device. In a cloud note the image is uploaded to sync.sharpmd.app as an attachment: the server stores the file, its type, its size, a hash and the date. It does not store the name the file had. The note keeps the address of the image.

That address works like a public link: anyone who has it can see the image, without an account. It is long and random and nothing lists it, but sharing the note, a public link, a live session or a published site hands it to whoever reads the note, and it keeps working for them until the image is deleted. Images in a protected folder are different: they are encrypted in your browser with the key of the folder, the server cannot read them and they have no public address. Protecting a folder that already had images encrypts them too and deletes the readable copies, unless a note outside the folder uses them. For those images the app tells the server which ones each note uses, by their identifiers only, so the unused ones can be deleted.

An image that no note uses is deleted from the server after 30 days, and at once if you delete it in Settings, Cloud, Storage. Deleting your account deletes all of them.

Deleting your account

You delete the account yourself in the app: Settings, Cloud, "Delete account", and type the account's email to confirm. You can also write to hello@sharpmd.app from the account's email and it is deleted for you.

What is deleted from the server: your email address, your notes, their version history, the trash, the comments for the AI, the feedback you sent, your contributions to the community gallery, the AI tokens, the sessions, what you shared and what was shared with you, the public links, the sites you published, the protected folders and the live sessions. The copies kept in your browser are removed too. It cannot be undone.

If the account pays a subscription, cancel it first: the server does not delete an account that is still being charged. If you are a member of a team, you leave the team and its notes stay with the team. If you manage a team, remove its other members first; the team and its notes are deleted with your account.

Community gallery

In Settings, Tools you can add templates, themes and diagram palettes that other people shared, and share yours. Looking at the gallery and adding from it needs no account. What you add is kept in your browser.

Sharing needs an account. What is sent is what the preview shows: the type, the name, the description, the language, the public name you choose and the content (the open note as a template, your current theme, or a palette). Nothing else from the app goes with it. The server stores that with your account, so you can see its state and withdraw it. It is reviewed by a person before it is published. Once approved it is public for everyone, under the public name you chose; your email address is never shown.

The server counts how many times each contribution was added. It is a number: it does not record who added it. You can withdraw a contribution in the same place, and it is deleted from the server. Deleting your account deletes your contributions too. Copies other people already added stay on their devices.

Published sites

On the paid plan you can publish a cloud folder as a public website. Nothing is public until you press Publish, and only the notes of the folder you chose are published. Notes in a folder protected with a password are never published, and a note with publish: false in its front matter is left out.

What becomes public: the title and the text of each published note as a web page, the images embedded in it, the title of the site, the address you chose and, if you write one, an author name. Your email address does not appear on the site. Anyone with the address can read it, and search engines can index it unless you ask them not to in the settings of the site. The pages are drawn in your browser and the server stores them as they are served, without encryption at rest, because they are public.

To take it down, open the site from the menu of its folder or from Settings, Cloud and choose Unpublish: the pages stop being served right away and are deleted from the server. Deleting the site also frees its address. Deleting a note removes its page at once. If the account leaves the paid plan, the site is unpublished after 7 days and its settings are kept. Copies that other people or search engines made while it was public are out of our reach. Deleting your account deletes your sites.

Whoever visits a published site is not tracked: the pages carry no analytics, no third-party scripts and no cookies, and the choice of light or dark stays in the visitor's browser. An image the author linked from another server is loaded from that server. A site that breaks the rules can be suspended: how to report one.

Automations

On the paid plan you can make SharpMD send a notice to an address you choose (Slack, Make, n8n, Zapier or your own) when a note or a kanban card changes. That address receives the type of event, the date, an opaque id of the account (never your email address), the path of the note and a link to open it, who made the change (the app, the API, an AI, or an opaque id and the role of a team member, never their name or address) and the data of the event: for a card, its title, column, dates and attributes. The text of the note is sent only if you turn that on for that automation. Notes in a protected folder never produce a notice. What happens with the data at that address depends on the service you chose.

The server stores the address and the signing secret of each automation, encrypted at rest. Of each delivery it keeps the type of event, the path of the note, whether it arrived, the response code and how long it took, for the last 50 deliveries of each automation and up to 30 days. The content that was sent is deleted once it is delivered or given up. An inbound address lets whoever has it add text to one note: the server stores a hash of its secret, how many times it was used and when. A token for the API reaches the same notes as a token for an AI. Deleting the account deletes all of this.

Live sessions

On the paid plan you can open a live session on one of your cloud notes and pass its link to other people. They join from the web, without an account, and edit the note with you.

Dictation and reading aloud

Both are tools you turn on in Settings, Tools. They are off until you do.

AI assistant with your own key

A tool you turn on in Settings, Tools. It is off until you do, and SharpMD provides no AI of its own: you connect a key from your provider: Claude (Anthropic), OpenAI, Google Gemini, DeepSeek, Groq, Kimi (Moonshot AI), MiniMax, Mistral, OpenRouter, Together AI or xAI (Grok), or an OpenAI-compatible server such as Ollama or LM Studio. You can keep one key per provider.

Network requests

Permissions of the extension

Questions

Write to hello@sharpmd.app. Support has the common fixes. The rules of the hosted service are in the Terms.

Privacidad

Última actualización: 8 de octubre de 2026

SharpMD funciona sin cuenta, sin rastreadores ni analítica de terceros. Las notas en la nube son opcionales, y tus notas salen de tu máquina solo si las mandás ahí.

Tus archivos

Los archivos que abrís los lee tu navegador, en tu máquina. Nunca se suben. Al guardar, el navegador escribe en el archivo o la carpeta que elegiste.

Qué se guarda y dónde

Los ajustes, la posición de lectura y la lista de carpetas recientes se guardan en tu navegador, en tu dispositivo. Si borrás los datos del sitio o de la extensión, se van.

Con la extensión instalada, la app web y la extensión comparten un solo depósito en tu dispositivo: las notas del navegador, la lista de archivos y carpetas recientes y las preferencias de apariencia. Pasan de una a la otra dentro de tu navegador, nunca por la red. Si las dos usan el mismo servidor de sincronización, comparten también la sesión de la nube: entrar o salir de un lado hace lo mismo del otro; con la nube apagada o con otro servidor de un lado, cada una sigue con la suya. La app web recibe el texto de un archivo de tu disco solo cuando abrís un enlace a ese archivo, confirmás, y el archivo está en una carpeta que ya abriste con la extensión; queda dentro de tu navegador, y se puede apagar en Ajustes, en Instalar. Las copias de las notas de la nube y las llaves de las carpetas protegidas no se comparten.

Conteos anónimos

Sin rastreadores ni analítica de terceros. El sitio y la app web cuentan unos pocos eventos anónimos (una visita, la app abierta, una cuenta creada) para saber si el producto funciona. Sin cookie, sin identificador y sin nada de tus notas. Se apaga en Ajustes, y la extensión no manda ninguno.

Notas en la nube, si entrás con tu cuenta

El servidor de sincronización guarda tu correo, las notas que mandás a la nube y, en el plan pago, sus versiones anteriores durante 30 días. Los códigos de acceso, las sesiones y los tokens para la IA se guardan como hashes.

Imágenes

Cuando pegás, arrastrás o elegís una imagen, SharpMD la achica en tu navegador antes de guardarla y le quita los metadatos: cámara, fecha y ubicación. Con la calidad de las imágenes en "Original", en Ajustes, el archivo queda como es, con sus metadatos.

En una carpeta de tu disco la imagen se guarda al lado del documento, y en una nota guardada en el navegador queda dentro de la nota. Ninguna de las dos sale de tu dispositivo. En una nota de la nube la imagen se sube a sync.sharpmd.app como adjunto: el servidor guarda el archivo, su tipo, su tamaño, un hash y la fecha. No guarda el nombre que tenía el archivo. La nota guarda la dirección de la imagen.

Esa dirección funciona como un enlace público: quien la tiene puede ver la imagen, sin cuenta. Es larga y al azar y nada la lista, pero compartir la nota, un enlace público, una sesión en vivo o un sitio publicado se la da a quien lee la nota, y le sigue sirviendo hasta que la imagen se borra. Las imágenes de una carpeta protegida son distintas: se cifran en tu navegador con la llave de la carpeta, el servidor no las puede leer y no tienen dirección pública. Proteger una carpeta que ya tenía imágenes también las cifra y borra las copias legibles, salvo que una nota de afuera las use. De esas imágenes la app le dice al servidor cuáles usa cada nota, solo por sus identificadores, para que se puedan borrar las que nadie usa.

Una imagen que ninguna nota usa se borra del servidor a los 30 días, y en el momento si la borrás en Ajustes, Nube, Almacenamiento. Eliminar tu cuenta las borra todas.

Eliminar tu cuenta

La cuenta la eliminás vos desde la app: Ajustes, Nube, "Eliminar la cuenta", y escribís el correo de la cuenta para confirmar. También podés escribir a hello@sharpmd.app desde el correo de la cuenta y la eliminamos.

Qué se borra del servidor: tu correo, tus notas, su historial de versiones, la papelera, los comentarios para la IA, los comentarios que mandaste, tus aportes a la galería de la comunidad, los tokens para la IA, las sesiones, lo que compartiste y lo que te compartieron, los enlaces públicos, los sitios que publicaste, las carpetas protegidas y las sesiones en vivo. Las copias guardadas en tu navegador también se quitan. No se puede deshacer.

Si la cuenta paga una suscripción, primero cancelala: el servidor no elimina una cuenta que se sigue cobrando. Si sos miembro de un equipo, salís del equipo y sus notas quedan en el equipo. Si administrás un equipo, primero sacá a los demás miembros; el equipo y sus notas se eliminan con tu cuenta.

Galería de la comunidad

En Ajustes, Herramientas podés agregar plantillas, temas y paletas de diagramas que compartió otra gente, y compartir los tuyos. Mirar la galería y agregar de ella no pide cuenta. Lo que agregás queda en tu navegador.

Compartir pide una cuenta. Se envía lo que muestra la vista previa: el tipo, el nombre, la descripción, el idioma, el nombre público que elegís y el contenido (la nota abierta como plantilla, tu tema actual o una paleta). Nada más de la app viaja con eso. El servidor lo guarda junto a tu cuenta, para que veas su estado y puedas retirarlo. Lo revisa una persona antes de publicarse. Una vez aprobado queda público para todos, con el nombre público que elegiste; tu correo no se muestra nunca.

El servidor cuenta cuántas veces se agregó cada aporte. Es un número: no registra quién lo agregó. Podés retirar un aporte desde el mismo lugar, y se borra del servidor. Al eliminar tu cuenta se borran también tus aportes. Las copias que otra gente ya agregó quedan en sus dispositivos.

Sitios publicados

En el plan pago podés publicar una carpeta de la nube como sitio web público. Nada es público hasta que tocás Publicar, y se publican solo las notas de la carpeta que elegiste. Las notas de una carpeta protegida con contraseña no se publican nunca, y una nota con publish: false en su encabezado queda afuera.

Qué queda público: el título y el texto de cada nota publicada, como página web, las imágenes incrustadas en ella, el título del sitio, la dirección que elegiste y, si escribís uno, un nombre de autor. Tu correo no aparece en el sitio. Cualquiera que tenga la dirección puede leerlo, y los buscadores pueden indexarlo salvo que pidas lo contrario en los ajustes del sitio. Las páginas se dibujan en tu navegador y el servidor las guarda como se sirven, sin cifrado en reposo, porque son públicas.

Para bajarlo, abrí el sitio desde el menú de su carpeta o desde Ajustes, Nube y elegí Despublicar: las páginas dejan de servirse en el momento y se borran del servidor. Eliminar el sitio además libera su dirección. Eliminar una nota saca su página en el acto. Si la cuenta deja el plan pago, el sitio se despublica a los 7 días y sus ajustes quedan guardados. Las copias que otra gente o los buscadores hayan hecho mientras fue público quedan fuera de nuestro alcance. Al eliminar tu cuenta se borran tus sitios.

A quien visita un sitio publicado no se lo sigue: las páginas no llevan analítica, scripts de terceros ni cookies, y la elección de claro u oscuro queda en el navegador de quien visita. Una imagen que el autor enlazó desde otro servidor se carga de ese servidor. Un sitio que rompe las reglas se puede suspender: cómo denunciar uno.

Automatizaciones

En el plan pago podés hacer que SharpMD mande un aviso a una dirección que elegís (Slack, Make, n8n, Zapier o una propia) cuando cambia una nota o una tarjeta de un tablero. Esa dirección recibe el tipo de evento, la fecha, un identificador opaco de la cuenta (nunca tu correo), la ruta de la nota y un enlace para abrirla, quién hizo el cambio (la app, la API, una IA, o un identificador opaco y el papel de alguien del equipo, nunca su nombre ni su correo) y los datos del evento: de una tarjeta, su título, su columna, sus fechas y sus atributos. El texto de la nota viaja solo si lo prendés en esa automatización. Las notas de una carpeta protegida nunca generan un aviso. Lo que pasa con esos datos en esa dirección depende del servicio que elegiste.

El servidor guarda la dirección y el secreto de firma de cada automatización, cifrados en reposo. De cada entrega guarda el tipo de evento, la ruta de la nota, si llegó, el código de la respuesta y cuánto tardó, para las últimas 50 entregas de cada automatización y hasta 30 días. El contenido que se mandó se borra cuando se entrega o se da por perdido. Una dirección de entrada le deja a quien la tiene agregar texto a una nota: el servidor guarda un hash de su secreto, cuántas veces se usó y cuándo. Un token para la API llega a las mismas notas que un token para una IA. Eliminar la cuenta borra todo esto.

Sesiones en vivo

Con el plan pago podés abrir una sesión en vivo sobre una de tus notas de la nube y pasarle el enlace a otras personas. Entran desde la web, sin cuenta, y editan la nota con vos.

Dictado y lectura en voz alta

Las dos son herramientas que prendés en Ajustes, Herramientas. Hasta entonces están apagadas.

Asistente de IA con tu clave

Una herramienta que prendés en Ajustes, Herramientas. Hasta entonces está apagada, y SharpMD no da IA propia: conectás una clave de tu proveedor: Claude (Anthropic), OpenAI, Google Gemini, DeepSeek, Groq, Kimi (Moonshot AI), MiniMax, Mistral, OpenRouter, Together AI o xAI (Grok), o un servidor compatible con OpenAI como Ollama o LM Studio. Podés guardar una clave por proveedor.

Pedidos de red

Permisos de la extensión

Consultas

Escribí a hello@sharpmd.app. En Ayuda están los arreglos más comunes. Las reglas del servicio alojado están en los Términos.