Privacy Policy
Effective Date: September 17, 2026 • Version 2.2.0
Sphene is architected from first principles as a 100% local-first, sovereign knowledge substrate. All your notes, drawings, encryption keys, index databases, and personal files remain on your physical hardware. We operate zero telemetry servers, zero user tracking scripts, and zero centralized databases containing user information.
1. Information We Do NOT Collect
Unlike conventional cloud-based note-taking platforms, Sphene respects your absolute privacy:
- Zero Note or Vault Data: Your Markdown files, images, attachments, and knowledge graphs never pass through our servers.
- Zero Analytics or Telemetry: Sphene does not include tracking SDKs, analytics beacons, or telemetry phone-home pings. We do not track when you open notes, how long you write, or what plugins you use.
- Zero Profiling or Advertising: We do not build marketing profiles, use cookies for tracking, or sell data to advertisers or brokers.
- Zero Passwords or Private Keys: Vault master keys and partition passphrases are hashed and derived entirely on your client device using PBKDF2/AES-256-GCM. We never have access to your decryption keys.
2. Personal Cloud Integrations (Google Drive & Dropbox)
Sphene provides optional, user-initiated synchronization with your personal Google Drive or Dropbox accounts. When you choose to enable cloud backup, synchronization occurs directly between your local Sphene instance and your personal cloud provider account.
Google API Services User Data Policy Compliance
Sphene's integration with Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements:
- Scopes Requested: Sphene requests
https://www.googleapis.com/auth/drive.file(access only to files created or opened by Sphene),userinfo.email, anduserinfo.profile(to display the connected account name in your local settings). - Purpose of Access: Google Drive access is requested solely to synchronize your personal encrypted or plaintext notes into your designated "Sphene Vault" folder in Google Drive.
- Zero Server Transmission: Google user data and files are processed strictly on your local device. We never transmit, store, or forward your Google Drive data to any Sphene-owned or third-party server.
- No Sale of User Data: We never sell, rent, or monetize Google user data under any circumstances.
- No Advertising Use: Data accessed via Google APIs is never used to serve personalized, retargeted, or interest-based advertising.
- No Generalized AI Model Training: Google user data is strictly excluded from training generalized artificial intelligence or machine learning models.
Dropbox API Data Policy Compliance
Similarly, when pairing with Dropbox, authentication is performed via standard OAuth 2.0 PKCE.
Sphene synchronizes notes exclusively to an isolated App Folder sandbox (/Apps/Sphene Vault/).
Dropbox tokens and file payloads remain strictly local to your machine.
3. Zero-Knowledge OAuth Callback Relay
To permit local (localhost:8743), mesh VPN (Tailscale), and homelab instances to authenticate against Google and Dropbox without requiring each end-user to create complex cloud developer projects, Sphene provides a stateless browser relay hosted at https://sphene.app/oauth/callback.
The relay page runs entirely in client-side HTML and JavaScript in your browser. It receives the authentication hash fragment (#access_token=...) from Google or Dropbox, inspects the origin parameter encoded in state, and immediately redirects your browser back to your local or private vault instance.
The relay server never receives, logs, intercepts, or retains the token.
4. Data Retention and Deletion
Because Sphene maintains no central user storage, you maintain 100% control over data retention:
- Local Data: To delete all local data, simply delete your local vault folder and database directory on your hard drive.
- Disconnecting Cloud Accounts: You can disconnect Google Drive or Dropbox at any time in Sphene Settings under "Cloud Storage". This immediately wipes the authentication token from local storage.
- Revoking Cloud Permissions: You can revoke Sphene's access directly at any time via Google Account Permissions or Dropbox Connected Apps.
5. Third-Party Services and External Links
When utilizing optional third-party integrations (such as Google Drive, Dropbox, or custom Model Context Protocol agents), your relationship with those providers is governed by their respective privacy policies and terms of service. Sphene has no control over and assumes no responsibility for the privacy practices of third-party cloud infrastructure.
6. Children's Privacy
Sphene is a general productivity tool and does not knowingly collect or solicit personal information from children under the age of 13.
7. Updates to This Policy
We may update this Privacy Policy periodically to reflect new features or evolving regulatory guidelines. Any modifications will be posted directly to this page with an updated Effective Date.
8. Contact Information
If you have any questions or privacy inquiries regarding Sphene Sovereign Hub, please contact our maintainers:
Sphene Sovereign Knowledge Project
Email: privacy@sphene.app
Website: https://sphene.app
GitHub: github.com/sphene-org/sphene