Dash LogoDash Notes

Privacy Policy

Last updated: September 8, 2026

Our Approach

Dash is a privacy-first, offline note-taking app. The app itself collects no data about you. This isn't just policy — it's architecture. Dash is designed from the ground up so that your notes never leave your device unless you explicitly choose to share or sync them, and then only in encrypted form.

Data We Collect

For local note-taking: none.

No account. No usage analytics. No telemetry. No crash reports. No cookies. No tracking pixels. The app does not collect, transmit, or store any personal data on its own.

If you subscribe to Dash Sync: your email address (used for the passwordless sign-in code and to check your subscription), your subscription status, and end-to-end encrypted vault data that our relay cannot read. Details are in the Optional Network Features and Third-Party Services sections below.

Data Storage

All notes are stored locally on your device. Dash never syncs your data to any server unless you turn on Dash Sync, and then only as ciphertext encrypted on your device.

  • Desktop (macOS): JSON files stored in ~/Library/Application Support/Dash/
  • iOS app: On-device app storage (if you enable Dash Sync, the vault key is kept in the iOS Keychain)
  • PWA (Web): IndexedDB in your browser

Optional Network Features

Two optional features use a zero-knowledge relay server when you explicitly choose to use them:

Encrypted Sharing

Content is encrypted client-side with AES-256-GCM before upload. The relay stores only encrypted blobs it cannot read. Shared notes are auto-deleted after 30 days. No accounts, no logs.

Dash Sync (optional subscription)

Notes, folders, tags, attachments and version history are encrypted on your device with a vault key that never leaves your devices. The relay stores only ciphertext, plus the sign-in email and subscription status needed to verify your entitlement. Deleted notes sync as encrypted tombstones and are purged after 30 days.

Auto-Updates (Desktop Only)

The Mac app checks for updates in the background via GitHub. No personal data is transmitted during this process.

Third-Party Services

  • Stripe — Payment processing for the Mac desktop app one-time purchase and the Dash Sync subscription. Stripe receives your email, billing address, and card. We never see your card details. For active sync subscribers, our server stores your email, your Stripe customer/subscription IDs, and your subscription status so we can verify the sync entitlement on each device.
  • RevenueCat — Used only on the iOS app to process Dash Sync subscriptions via Apple In-App Purchase. RevenueCat receives an anonymous device-generated ID and your Apple-provided subscription receipt. They do not receive your email or any note content.
  • Resend — Sends sign-in codes (6-digit, one per session) and one-time transactional notices. We never use Resend for marketing. Resend sees only your email address and the short code body.
  • GitHub — Open source code hosting and Mac app update checks.
  • Deno Deploy — Hosts the relay server. The relay stores end-to-end encrypted vault blobs (ciphertext only), per- request timestamps + IPs for abuse prevention, and (for sync subscribers) the entitlement records described above. The relay never has access to your vault key or note plaintext.

Open Source

The full source code for Dash is available on GitHub for anyone to audit. Our privacy claims are verifiable, not trust-based. You can inspect exactly how your data is handled at every step.

Contact

For questions about this privacy policy, contact @efesopoulos on Twitter/X.