Privacy
Last updated 29 September 2026.
Virgulas is local-first. In Memory, Local, and File modes nothing you write is ever sent to a Virgulas server. Remote mode stores a single encrypted document so you can sync between devices; the server never receives the key.
What is stored, and where
- Your outline — in Memory mode it lives only in the tab; in Local mode
it is encrypted with your passphrase and kept in this browser's
localStorage; in File mode it is written to a.vmdfile you choose. In Remote mode the same ciphertext is also stored in our Supabase-hosted database, keyed to your account. - Account email and password — only if you use Remote mode. Authentication is handled by Supabase; the password is never stored by the app.
- Non-secret device settings — storage mode, theme, last username, sync timestamps, the Supabase endpoint, and the quick-capture queue are stored unencrypted in this browser. They never contain your document text.
- Analytics — we self-host an Umami instance at
um.vps.pitermarx.com. It is cookieless, collects aggregate page views, and does not build a profile or track you across sites.
What we cannot see
The document is encrypted on your device with AES-GCM-256 using a key derived from your passphrase (PBKDF2-HMAC-SHA256). The server stores only ciphertext and cannot read it. If you forget your passphrase, the data cannot be recovered — not even by us.
Legal basis, retention, and your rights
Where the GDPR applies, we process your account email to perform the contract (Remote mode) and aggregate analytics on the basis of legitimate interest. You can delete your stored document and sign out at any time from Options → Delete account; the encrypted row is removed immediately. To have the account record itself erased, or to exercise access, rectification, portability, or objection rights, contact us through the repository link below. We keep data only while your account exists.