Atlas spool on no1es.com
Privacy
This is the whole policy. It is short because the service is built to hold almost nothing about you, and what it does hold is listed here by name.
The one thing worth knowing
Your notes are files on your own computer. They are never uploaded here, not their text, not their titles, not their file names. no1es in the cloud exists to do two small jobs while your computer is asleep: hold what you say to an assistant on your phone until your computer wakes up and files it, and keep a flat copy of your to-do list and calendar so a phone has something to show you.
What is stored, and nothing else
- Your identity
- Your Google account id, your email address, your name and the web address of your Google profile picture. This arrives when you sign in and is the only thing sign-in asks Google for.
- What you put down elsewhere
- The words you give an assistant on another device, held until your computer collects them. Once your computer has filed them, they are marked done and deleted from disk at the next tidy-up, within seven days.
- Your to-dos and calendar
- A flat copy your computer sends up: to-do text and due dates, event titles, times and places. Your computer replaces anything from a note you marked private with the words "Something private" before it leaves your machine, so this service never receives those words at all. You can switch that off yourself, in which case the real words are sent, and that is your decision to make.
- Your paired computers
- A name you chose, when it was paired, and when it was last seen.
- Email permission, only if you grant it
- A token from Google that lets your computer read your recent mail. It is encrypted before it is written down. No message, subject, address or attachment is ever stored here.
What is never stored
No note. No note title. No email content. No passwords: there is no password to have, because Google is the only way in. No payment details. No location. No device fingerprint. No advertising identifier.
Secrets are kept as fingerprints
Every token, session and pairing code is stored as a one-way fingerprint, never as the thing itself. You are shown the real value once, at the moment it is made, and it cannot be recovered afterwards by anyone, including whoever runs this service. The Google token for email is the exception, because it has to be usable: it is sealed with strong encryption and the key is not kept in the same place.
Email, if you allow it
This is a separate choice behind its own button. Refusing it costs you nothing and everything else works.
The permission asked for is read and draft. It does not include sending, and there is no code anywhere in this service or in the app on your computer that could send a message. Drafts wait in your Gmail until you open them and press send yourself.
Reading happens on your computer, not here. This service hands your computer a one-hour key when it asks for one; your computer then talks to Google directly, reads only message headers and the one-line preview Google itself writes, and never fetches a message body. What it does with that is suggest, on your own screen, which of your own notes a conversation might belong with. You approve or you do not.
Take it back at any time, from your account page here or from your Google account settings. Either one works and neither needs the other.
Nobody else gets any of it
Nothing is sold, rented, shared or handed to an advertiser, ever. There is no analytics script, no tracking pixel and no third-party code on these pages. The only cookie is the one that keeps you signed in.
Three companies are unavoidably involved and they are all listed here. Google, because sign-in is theirs. Railway, because the servers run there, in the United States. Let's Encrypt, because the padlock in your address bar is theirs. No other service receives anything.
Getting rid of it
You can do all of this yourself, from your account page, without asking anyone:
- Unpair a computer
- Its access stops immediately.
- Take back the email permission
- The stored token is destroyed first, then Google is told to forget the grant.
- Delete your account
- Your identity, your held items, your to-do and calendar copy, your paired computers and any email token are all erased from disk. It is immediate and it cannot be undone. Your notes are untouched, because they were never here.
Children
This is not for anyone under 13, and accounts are not knowingly created for them.
Changes, and how to reach a person
If this policy changes in a way that affects what is stored, the date below changes and the change is described on this page rather than quietly folded in.
Questions, or a request about your own data: hello@arkhai.ai.
Last updated 10 October 2026.