notes

Privacy

Padgit is a web page that edits markdown files in GitHub repositories. There is no Padgit database, no account with us, no analytics and no tracking. This page says exactly who can see what, including the parts that depend on trusting whoever runs the copy you are using.

The short version

Note links include the repository, branch and filename in the address fragment. The static host does not receive the fragment, but browser history and copied links can retain it after sign-out. Clear browser history separately if needed. An in-progress sign-in temporarily keeps that link in session storage so it can reopen the note afterwards; it is removed with the sign-in state.

Preview runs in your browser using pinned Marked and DOMPurify scripts from cdnjs.cloudflare.com, alongside the editor library. Every file from the CDN, editor included, is pinned to an integrity hash, so a changed file is refused. Note text is not sent to the CDN. Content search reads files directly from GitHub into browser memory and includes this repository’s local drafts. It creates no persistent search index. Preview images are read through the same GitHub API with the current sign-in and displayed as image data in memory. External image URLs are not requested; no image proxy or extra host sees your notes. Image data is not persisted by Padgit.

What GitHub sees

Everything the app does is an ordinary request to GitHub’s API, api.github.com, made with your own sign-in: listing files, reading a note, saving it as a commit. GitHub’s own privacy statement covers what GitHub keeps. Signing in happens on github.com, where GitHub asks you to approve the app. The page itself is usually hosted on GitHub Pages, so GitHub also sees the page being loaded, as for any website. Your picture in settings comes from avatars.githubusercontent.com, GitHub’s image server.

What your sign-in can reach is limited to reading and writing the contents of repositories the app is installed on that you also have access to. That is the repositories you chose when you installed it, plus any that someone else installed it on and you can use, such as an organisation’s. Like any GitHub sign-in it can also read public repositories. It cannot see your private email address, your issues or your settings, and cannot act anywhere else on your behalf.

What the broker sees

GitHub will only turn a sign-in into a token for an app that proves who it is with a secret, and a web page cannot keep a secret. The broker is a tiny program that holds that secret and does this one swap. It receives:

It passes them to GitHub and hands GitHub’s answer (your tokens) straight back to your browser. It stores nothing and logs nothing: there is no database, no storage and no logging in its code, which is short enough to read in a few minutes (broker/worker.js). Your notes never pass through it; once your browser has a token it talks to GitHub directly.

The broker runs on Cloudflare Workers. Like any hosting company, Cloudflare handles the requests that reach it.

Other places the page loads from

The editor, CodeMirror, is loaded from cdnjs.cloudflare.com, a public library server. Cloudflare sees that your browser fetched it, as for any website using it. That code then runs inside the page, like the app’s own. Each of these files is pinned to the hash of one exact version: if cdnjs ever served something different, your browser would refuse to run it. What you trust is that those versions of CodeMirror, Marked and DOMPurify are what they claim to be. If the editor does not load, or is refused, the app still works with a plain text box. The page’s security policy lets it send data only to GitHub and the broker.

Who you are trusting

If you use someone else’s copy of Padgit, you are trusting that person, not just this code:

The code in this repository does none of these things. If you would rather not trust anyone but GitHub, run your own copy (see the end of this page).

What your browser keeps

All of this stays on your device, in the browser’s storage for this site:

Name What it holds Removed when
notes.config.v2 your sign-in (the token, when it expires, and the refresh token that renews it), your GitHub username and picture link, the repository and branch you chose, your pinned files you sign out, or GitHub stops accepting the sign-in
notes.ui.v1 which folders are open, the note you last had open, up to 12 open note tabs and 30 recently opened paths with opening times for the last-used repository and branch, the pinned list you last looked at, the file list’s width and whether it is hidden, and which versions of your notes are pinned (by their GitHub version id, so each is read only once to find pins) you sign out
notes.draft.v1: followed by the repository, branch and file the words you have typed but not yet saved in that file, which version they were based on, and when the change is saved, you press Discard, or you sign out
notes.theme Light or Dark, if you chose one in Settings (nothing for Same as this device) you choose Same as this device again; signing out keeps it, as it says nothing about you
notes.navigation a random history identifier and the number of forward steps, in this tab’s session storage; no paths or note text you sign out or the tab closes
notes.textSize Smaller, Normal or Larger note text, stored in this browser like the theme browser data is cleared; signing out keeps it
notes.signin for a sign-in in progress: a random value that ties GitHub’s answer to this sign-in, the proof value sent to the broker, and whether to remember you you come back from GitHub; if you never do, when the tab closes

Normally these are in local storage, so you stay signed in on this browser. If you tick Forget me when I close the browser, they are kept in session storage instead, which the browser throws away when the tab is closed. Two things to know on a shared computer:

The one-off notes.signin value is always in session storage.

Sign out (in settings) removes all of it from this browser, unsaved changes included; the app warns you first. If instead GitHub stops accepting your sign-in (it expired, or you revoked it), the app signs you out but keeps your unsaved changes, so nothing you typed is lost; they are there if you sign in again, and Sign out removes them.

Signing out does not cancel the sign-in on GitHub. A token copied off this device would keep working until it expires, at most eight hours later, and a copied refresh token could keep getting new ones for up to six months. If you think either was copied, revoke the app on GitHub.

How to take the access back

On GitHub, click your profile picture, then Settings, then Applications:

To take everything back, do both. Nothing needs deleting on the broker, because it keeps nothing.

Self-hosting instead

You can run your own copy, with your own GitHub App, your own page and your own broker, so the only people you trust are GitHub and the companies that host the page and the broker (GitHub Pages and Cloudflare, unless you choose others). Running your own copy walks through it: about twenty minutes, with a GitHub account and a free Cloudflare account.