Privacy
Operator: this is a default policy template, review and adapt it before going to production. Last touched: 2026-04-28.
What MDDock stores
The MDDock desktop client is local-first. Your markdown files, history, and recall index live in your workspace on your machine. They are never uploaded unless you explicitly publish a project or enable cloud sync.
What this site stores
When you visit this site: mddock.com
- HTTP request logs (IP, user agent, path) for the duration set by the operator
- If you sign in: your handle, email, and avatar URL from the OAuth provider
- If you publish a project: the project files you submit and basic metadata (stars, forks)
We do not run third-party analytics, ad networks, or session replay tools by default. The operator may choose to add them; if so, this page should be updated to disclose them.
Cookies
This site uses one essential cookie set by next-auth to keep you signed in. No tracking cookies are used by default.
Encryption and sync
Local vaults are encrypted at rest with AES-256-GCM (12-word recovery phrase). Cloud sync and Cloud Docs are encrypted in transit (TLS); synced content is stored on the server so collaborators and agents you authorize can access it. End-to-end encrypted sync is on the roadmap.
Your data, your call
- Export everything:
mddock export --to-zip - Delete published projects: from your project page β Settings β Delete
- Delete your account: contact the operator (no self-serve flow yet)
Changes
Material changes to this policy will be announced in the changelog.