Privacy Policy

Last updated 27 July 2026 · UK GDPR & Data Protection Act 2018

The short version

Palarid stores everything you type on your own device, inside your browser. There is no server holding your data, no account system and no advertising. We cannot see your notes, habits, money figures, health entries or passwords — they do not leave your computer unless you export them yourself.

1. Who we are

Palarid provides a free browser-based personal workspace at palarid.com. Under UK GDPR we are the data controller only for the limited technical data described below. For everything you create in the app, you are the controller and the sole holder of that data.

Contact: huseyin_h@hotmail.co.uk

2. What we collect

Data you create — notes, habits, budgets, health logs, saved passwords, files: stored exclusively in your browser's local storage and IndexedDB, on your device. It is never transmitted to us. We have no ability to read, recover or delete it.

Technical data — our host, Netlify, processes your IP address and browser user-agent in server logs to deliver the page and to prevent abuse. This is standard for any website.

Correction, 27 July 2026 — please read.

An earlier version of this policy said Palarid used no analytics. That was not accurate: Netlify's Real User Monitoring script (/.netlify/scripts/rum) has been loading on page views. It measures page performance, not your content, and it cannot read anything stored in your browser — but the blanket "no analytics" claim was wrong and we are correcting it rather than quietly editing it out. Removing this script is a tracked task.

Similarly, an earlier version said ipapi.co was used "only on the IP Info tool". It has in fact also been used to resolve your approximate town for the Daily Brief. As of this release, sharing that location with AI features is off by default and must be switched on explicitly in the AI settings.

3. Lawful basis (UK GDPR Article 6)

4. Third parties

Certain tools fetch live information. When one runs, your IP address is necessarily visible to that provider:

If you add your own API key it is stored on your device only and sent only to that provider.

5. Sending information outside the UK

This section was missing from earlier versions of this policy. UK GDPR Article 13(1)(f) requires us to tell you when your information goes overseas and on what legal footing, so here it is.

Palarid has no servers. But when you use a feature that calls an external service, your request — including your IP address, and for AI features the text you typed — reaches that provider wherever they operate. Most are in the United States.

ServiceWhat reaches themWhere
Netlify (hosting)IP address, browser typeUSA
Pollinations.aiThe prompt you submitOutside the UK
OpenAI / Groq / Anthropic / OpenRouter (only with your own key)The prompt you submitUSA
ipapi.coIP addressOutside the UK
Open-Meteo, USGS, NOAA, NASAIP address, coordinates you requestEU / USA
OpenStreetMap, EsriIP address, map tiles requestedEU / USA
unpkg, jsDelivrIP addressGlobal CDN

The safeguard. Transfers to the United States rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified, or on the International Data Transfer Agreement / Addendum where it is not. We are being straight with you: as a very small project we have not individually audited each provider's certification status. If that matters to you, the practical protection is to avoid the features that call them — every one is optional, and Palarid's core works with no network at all.

What never leaves. Your notes, tasks, money figures, health entries and vault contents are not transferred anywhere, because they are not sent to us in the first place.

6. Retention

Your data stays on your device until you delete it or clear your browser storage. We hold nothing, so there is nothing for us to retain or delete on your behalf.

Known limitation, stated plainly: the in-app "clear all data" control currently covers browser local storage. It does not yet cover IndexedDB or the offline cache. Until it does, the most complete way to remove everything is to clear site data for palarid.com in your browser settings. This is a tracked defect, not intended behaviour.

7. Children

Palarid is not directed at children under 13. It contains general reference information, including first aid and health tools, intended for adults.

8. Security

The site is served over HTTPS with HSTS. The optional password vault uses AES-GCM with a PBKDF2-derived key at 100,000 iterations; your master password is never stored and cannot be recovered by us or anyone else. Current OWASP guidance for PBKDF2-HMAC-SHA256 is 600,000 iterations, and raising it is a tracked task. Because your data lives on your device, its security also depends on your device being secure.

See the security page for open issues, stated honestly.

9. Changes

Material changes appear here with a new "last updated" date. Where a previous statement was wrong, we correct it visibly rather than deleting it.

10. Complaints

You may complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk · 0303 123 1113.

← Trust Centre · Your rights & the ICO · Your data · Cookies · Terms · Accessibility