Security and Privacy Pledge

Mikipage is a place to write down the things you haven't shown anyone yet: unfinished thinking, family details, work you're not ready to be judged on. You should know what we will and won't do with them. This page states it as specific commitments you can check us against. It does not ask you to take our good intentions on trust.

[1] explains how your data is protected: encryption, where it lives, protected notes. This page is about us: the promises we make about how we handle your data.

How we keep Mikipage secure

  • AWS-grade security. Mikipage's founder comes from Amazon Web Services and has more than 20 years of experience in the industry, and has brought AWS's security habits to Mikipage. The two-person rule below is one of them.
  • Built on AWS, encrypted throughout. Your data is encrypted whenever it travels and wherever it is stored. For the few notes you want nobody else to read, a protected note is encrypted in your browser before it is saved. [1] has the technical details.
  • We use it ourselves. Our own team keeps private notes in Mikipage every day. We know what it would mean for them to leak, because our notes would leak too.

1. Security is job #1

Any security issue gets our highest priority, however small or trivial it looks. It goes ahead of new features, deadlines and everything else in the queue.

If anything looks wrong to you, such as a note you can see but shouldn't, a page that exposes more than it should, or a suspicious email that claims to be from us, write to support@mikipage.com. We will look into it before anything else.

2. Our team stays out of your data

Running Mikipage almost never involves a person: nearly all of the work that touches your data in production is automated. Building pages, indexing notes for search and sending notifications all happen without anyone at Mikipage reading what you wrote.

A person looks at production data only as a last resort, when a problem can't be fixed any other way, such as a bug that happens only in production. For those cases we follow a two-person rule, modelled on the one used at AWS: before anyone on our team opens production data, a second person reviews and approves the reason and the scope. Nobody opens your data alone, so nobody can do it casually or by accident. The access covers only what the problem needs, and it ends when the problem is fixed.

Our own notes are in the same system under the same rule. We keep your data private to you for the same reason we keep ours private to us.

3. We never sell your data

We never sell your data, rent it out, or use it for advertising. Mikipage is paid for by the people who use it, not by investors or advertisers (see [2]). Your notes are not a product we could sell.

Mikipage runs on a few computing services, mostly on AWS, that are necessary to process your data, and they process it only to do the work you asked for: AWS hosts the app and your data, the search index keeps a copy of your notes so you can search them, and the AI model providers read note text when AI runs for you. [1] describes each of these.

4. When you leave, your data leaves with you

Take everything first: export your notes and pages as Markdown, or keep a copy with the Obsidian plugin (see [2]). Then write to support@mikipage.com from your account's email address and ask us to delete your account.

Within 30 days, we delete your account and everything it owns: notes, pages, attachments, the search index of your notes, and your AI history.

Our backups exist to recover from a disaster, and older backups are replaced by newer ones on a rolling basis. We don't restore a deleted account from them. If we ever restore a backup to recover from an incident, we delete your data again.

This is an Alpha draft

Mikipage is in Alpha, and "Alpha" means things can still change, this page included. We would rather tell you exactly where we are than promise more than we can stand behind today. We will mark this pledge final when it is ready. Until then, we welcome your feedback on it at support@mikipage.com.

  • [1]: how your data is protected, and who can read it
  • [2]: what happens to your notes in the long run, or if we stop
  • [3]: other questions
Yesterday 7:17pm
Comments
Log in to comment.

No comments yet.