Last updated: January 2, 2025
RiteMark, operated by Productory Services OÜ ("we", "our", or "us"), is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our WYSIWYG markdown editor. We believe in transparency – this policy is written in plain language to help you understand exactly what data we collect and why.
We believe in radical transparency. Here's exactly what we store:
We only collect data for specific, legitimate purposes:
What we collect: Your Google User ID, name, email, and profile picture from Google OAuth.
Why we need it: To verify your identity and keep you signed in securely across devices.
Example: When you sign in with Google, we store your refresh token so you don't have to sign in again every time you open RiteMark.
What we collect: Your editor preferences (keyboard shortcuts, "pick up where you left off" toggle).
Why we need it: To provide a seamless experience across all your devices.
Storage: Settings are encrypted and stored in your Google Drive AppData folder. You control this data and can delete it at any time by deleting your account.
We use these trusted services to provide RiteMark:
We only keep data as long as necessary:
You have the following rights regarding your personal data:
What it means: You can download a copy of all data we store about you.
How to do it: Go to Settings & Account → Privacy & Data → "Download my data"
What you'll get: A JSON file with your user ID, settings, and refresh token metadata (not the actual token).
What it means: You can request deletion of all your data from our servers.
How to do it: Go to Settings & Account → Privacy & Data → "Delete my account"
What gets deleted:
What stays: Your Google account and Google Drive files remain intact (we don't have access to delete those).
What it means: You can download your data in a machine-readable format (JSON).
How to do it: Same as "Right to Access" above.
What it means: You can object to how we process your data.
How to do it: Contact jarmo@productory.eu
What it means: You can revoke your consent at any time.
How to do it: Sign out or delete your account. You can also revoke Google permissions at
myaccount.google.com/permissions
We integrate with these trusted services:
Used for: Authentication and file operations
Data shared: Your Google User ID, email, name, profile picture
Privacy policy: policies.google.com/privacy
Used for: Hosting and serverless functions
Data shared: Refresh tokens (encrypted), user ID
Privacy policy: netlify.com/privacy
Used for: AI features (if you bring your own API key)
Data shared: Your document content (when you explicitly use AI features)
Privacy policy: openai.com/privacy
Important: Your OpenAI API key is stored locally in your browser with AES-256-GCM encryption (never sent to our servers). When you use AI features, your content is sent directly to OpenAI using your own API key.
We implement industry-standard security measures:
RiteMark is operated from Estonia (EU). Some of our service providers (Netlify, Google) may process data outside the EU. These transfers are protected by:
RiteMark is not intended for children under 16. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact jarmo@productory.eu immediately.
We may update this Privacy Policy occasionally. When we make material changes:
Here's our legal justification for processing your data:
RiteMark is committed to transparency. You can review our source code on GitHub to verify how we handle your data: github.com/productoryapp/ritemark
Data Controller: Productory Services OÜ
Registry Code: 16993803
Address: Tartu mnt 83, Tallinn, Estonia, 10115
Email: jarmo@productory.eu
Data Protection Officer: Jarmo Tuisk (jarmo@productory.eu)
If you believe we've violated your privacy rights, you can file a complaint with: Estonian Data Protection Inspectorate (our lead supervisory authority under GDPR).