Privacy Policy

1. Who we are and what this covers

The rho.md cloud service ("the Service") is operated by Digital Factory Australia Pty Ltd (ABN 16 694 991 243), trading as rho.md ("we", "us"). This policy covers the Service — accounts, publishing, sharing, sync, and reading on rho.md. The Rho MD desktop and mobile app is local-first: your documents live on your device, and none of them — nor your identity — is sent to us unless you sign in and use a cloud feature. The app itself — what you may do with the software — is covered by the Terms of Service, not this policy. Cloud accounts are for people aged 13 or over, or the higher minimum age where you live; we do not knowingly collect personal data from anyone younger, and if we learn that we have, we delete the account and its data.

Two requests are the exception, in that the app makes them without you asking: the update check (§2a) and, if left on, the Discover strip on the New Tab page, which asks rho.md for the titles of the few most recently published public documents. Neither carries your documents, your account, or any identifier. The Discover strip can be turned off in Settings › General; the update check's schedule is set in Settings › About (it can be reduced to manual-only) — see §2a for exactly what it sends.

2. What we collect

Account: your email address and chosen handle (via Supabase Auth). Content: documents you upload to the cloud and the metadata you attach — tags, categories, links, and any reader access lists you create for unlisted documents. Reading stats: approximate, privacy-preserving counts — we store a salted one-way hash of reader IP + date, never the IP itself. Interest signals: see §3. Payment: handled entirely by Stripe as Merchant of Record; we never see or store your card details. Support: emails you send to our support addresses. Crash reports: only if you agree when the app asks after a crash — one carries the app version, operating system, install channel and the crash excerpt from the log. The app redacts file paths, document names and email addresses before showing you the exact text for approval; nothing is sent until you press Send, and a report carries no account and no identifier. Feedback: the feedback form (rho.md/feedback, also linked from the app) sends only the words you type — anonymous unless you choose to include a way to reach you.

2a. The app's update check — what it sends

By default, once a day, the desktop app asks rho.md whether a newer version exists. The request is a plain web address, and these three values are the whole of it: the version you are running (e.g. 1.3.0), your operating system (linux, windows or darwin), and your processor architecture (e.g. x86_64). There is no account, no cookie, no installation id, no device fingerprint, and no request body. Our web server is configured to keep no access log for this address, so your IP is not recorded either. The reply is either "you are current" or the address and signature of the new build.

We do count these checks — in aggregate only. The server keeps one counter per app version × operating system × day, so we can tell how many installs are alive and which versions are still out there. Only those daily totals are stored: no individual request, no IP address, and no identifier is ever written down, and the no-access-log promise above stands unchanged. Counting is the only thing the update check feeds.

You control how often it happens, in Settings › About: Daily (the default), On start (only when Rho MD launches), or Never— which schedules nothing at all, while leaving the "Check now" button working whenever you want it. We deliberately offer no mode that takes that button away: the only thing it would add is making the app harder to update on purpose. We do ask you to keep some automatic checking on — Rho MD renders Markdown you may have obtained from anywhere, and if we ship a security fix, an install that never asks is one we cannot reach.

What the check does not do is act on its own: downloading and installing a new version always asks you first, unless you turn on "Install updates automatically" in Settings › About. Copies installed from the Snap Store or the Microsoft Store skip all of this — those stores handle updates, and the app makes no check of its own there.

2b. Why we are allowed to hold it

Where the GDPR or a similar law applies, these are our legal bases. To do what you asked (performance of a contract): your account, storing and delivering your documents, publishing, sync, and billing. Legitimate interests: keeping the Service secure and free of abuse, aggregate reading statistics, and the gravity field that connects writing with readers — each weighed against your interests, and each with a control (you can edit or mute gravity, and turn off the Discover strip). Legal obligation: records we are required to keep, such as payment and tax records and copyright takedown records.

3. Gravity — interest matching, in the open

To connect writing with readers, the Service computes a "gravity field" from what you have chosen to share with the cloud: the names of your public tags and constellations, an optional self-description, and your reading activity on rho.md. It never reads the content of documents on your device. Reading activity is folded into decaying aggregates (roughly a 30-day half-life) and the underlying raw events are deleted after processing. Your gravity field is not a hidden profile: you can see it, edit it, and mute any topic from your console at any time.

4. Charts and social data

What you chart (save) is private to you. Authors see only anonymous aggregate numbers; nobody's saves or reader counts are ever shown publicly.

5. Sync data

If you use paid sync, your sync data (including metadata about unpublished documents) is encrypted at rest and transferred over TLS, and lives in private storage that is never connected to any public or discovery feature. Sync data is used for one purpose only — keeping your devices in sync — and is never shared with third parties.

6. What we never do

We do not sell your data. We show no ads and use no advertising trackers. We do not feed private or unlisted content into any search index, recommendation surface, or public graph — this separation is structural, not just policy. Unlisted pages are served with noindex and no-referrer headers.

7. Cookies

Only authentication session cookies. No third-party advertising trackers.

8. Service providers and data location

Supabase (database & auth, US East), Cloudflare (DNS, CDN, email routing, and R2 object storage), Resend (transactional email), and Stripe (payments, as Merchant of Record). Each receives only what it needs to perform its function. Your cloud data is stored in the United States; we are an Australian company, and we handle your data under this policy wherever it is stored. For users in the EEA and the UK, those transfers rest on our providers' standard data processing terms, which incorporate the European Commission's Standard Contractual Clauses.

8a. Government and law-enforcement requests

We hand personal data to police, regulators, or courts only when we are legally compelled — a valid order, warrant, or statutory notice under a law that binds us — and then only the specific data that order covers, after checking that it was properly issued. A request that arrives as an email asking nicely is not an order, and we decline it. We will tell you when it happens, unless the law forbids us from telling you or someone is in immediate danger. Documents you have published are public already; nothing about a legal request is needed to read those.

9. Retention and deletion

Documents you delete or unpublish are removed from the Service; residual copies in our encrypted backups expire on a rolling basis. To delete your account and all associated cloud data, email privacy@rho.md from your account address — we complete deletion within 30 days. Your local documents are yours and are never touched.

9a. If something goes wrong

If a breach of our systems is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires, and the relevant European authority where the GDPR applies. We will tell you what happened and what it means for you, not just that something happened.

10. Your rights and how to complain

Depending on where you live, you may have rights to access, correct, export, or erase your personal data, and to object to or restrict some processing (including under the Australian Privacy Act, GDPR, and CCPA). Write to privacy@rho.md and we will respond within 30 days. Say what you want and from which account address; we do not charge for this.

If you are unhappy with how we handled it, you can take it to a regulator without asking us first: in Australia the Office of the Australian Information Commissioner, and in the EEA or the UK your national data protection authority.

11. Changes and contact

8 August 2026: §5 updated — sync data is now additionally encrypted at rest by the application itself (on top of storage-level encryption); wording simplified. 7 August 2026: §2a now discloses that update checks are counted as anonymous daily aggregates (version × platform × day, nothing else); §2 adds crash reports (always previewed, always redacted, never automatic) and the anonymous feedback form. 6 August 2026 and earlier: see prior versions on request.

We will announce material changes to this policy on the site or by email. Questions: privacy@rho.md — Digital Factory Australia Pty Ltd, trading as rho.md.