Privacy Policy
1. Who we are and what this covers
The rho.md cloud service ("the Service") is operated by Digital Factory Australia Pty Ltd ("we", "us"). This policy covers the Service — accounts, publishing, sharing, sync, and reading on rho.md. The Rho MD desktop and mobile app is local-first: your documents live on your device, and none of them — nor your identity — is sent to us unless you sign in and use a cloud feature. The app itself is covered by its EULA, not this policy.
Two requests are the exception, in that the app makes them without you asking: the update check (§2a) and, if left on, the Discover strip on the New Tab page, which asks rho.md for the titles of the few most recently published public documents. Neither carries your documents, your account, or any identifier. The Discover strip can be turned off in Settings › General; the update check's schedule is set in Settings › About (it can be reduced to manual-only) — see §2a for exactly what it sends.
2. What we collect
Account: your email address and chosen handle (via Supabase Auth). Content: documents you upload to the cloud and the metadata you attach — tags, categories, links, and any reader access lists you create for unlisted documents. Reading stats: approximate, privacy-preserving counts — we store a salted one-way hash of reader IP + date, never the IP itself. Interest signals: see §3. Payment: handled entirely by Stripe as Merchant of Record; we never see or store your card details. Support: emails you send to our support addresses.
2a. The app's update check — what it sends
By default, once a day, the desktop app asks rho.md whether a newer version exists. The request is a plain web address, and these three values are the whole of it: the version you are running (e.g. 1.3.0), your operating system (linux, windows or darwin), and your processor architecture (e.g. x86_64). There is no account, no cookie, no installation id, no device fingerprint, and no request body. Our web server is configured to keep no access log for this address, so your IP is not recorded either. The reply is either "you are current" or the address and signature of the new build.
You control how often it happens, in Settings › About: Daily (the default), On start (only when Rho MD launches), or Never— which schedules nothing at all, while leaving the "Check now" button working whenever you want it. We deliberately offer no mode that takes that button away: the only thing it would add is making the app harder to update on purpose. We do ask you to keep some automatic checking on — Rho MD renders Markdown you may have obtained from anywhere, and if we ship a security fix, an install that never asks is one we cannot reach.
What the check does not do is act on its own: downloading and installing a new version always asks you first, unless you turn on "Install updates automatically" in Settings › About. Copies installed from the Snap Store or the Microsoft Store skip all of this — those stores handle updates, and the app makes no check of its own there.
3. Gravity — interest matching, in the open
To connect writing with readers, the Service computes a "gravity field" from what you have chosen to share with the cloud: the names of your public tags and constellations, an optional self-description, and your reading activity on rho.md. It never reads the content of documents on your device. Reading activity is folded into decaying aggregates (roughly a 30-day half-life) and the underlying raw events are deleted after processing. Your gravity field is not a hidden profile: you can see it, edit it, and mute any topic from your console at any time.
4. Charts and social data
What you chart (save) is private to you. Authors see only anonymous aggregate numbers; nobody's saves or reader counts are ever shown publicly.
5. Sync data — an honest note on encryption
If you use paid sync, your sync data (including metadata about unpublished documents) is stored encrypted at rest and transferred over TLS, in a private bucket that is never connected to any public or discovery feature. However, it is not yet end-to-end encrypted: our infrastructure can technically read it. End-to-end encryption is on our roadmap; this policy will be updated when it ships.
6. What we never do
We do not sell your data. We show no ads and use no advertising trackers. We do not feed private or unlisted content into any search index, recommendation surface, or public graph — this separation is structural, not just policy. Unlisted pages are served with noindex and no-referrer headers.
7. Cookies
Only authentication session cookies. No third-party advertising trackers.
8. Service providers and data location
Supabase (database & auth, US East), Cloudflare (DNS, CDN, email routing, and R2 object storage), Resend (transactional email), and Stripe (payments, as Merchant of Record). Each receives only what it needs to perform its function. Your cloud data is stored in the United States; we are an Australian company, and we handle your data under this policy wherever it is stored.
9. Retention and deletion
Documents you delete or unpublish are removed from the Service; residual copies in our encrypted backups expire on a rolling basis. To delete your account and all associated cloud data, email [email protected] from your account address — we complete deletion within 30 days. Your local documents are yours and are never touched.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, or erase your personal data (including under the Australian Privacy Act, GDPR, and CCPA). Write to [email protected] and we will respond within 30 days.
11. Changes and contact
We will announce material changes to this policy on the site or by email. Questions: [email protected] — Digital Factory Australia Pty Ltd.