Privacy Policy
Last updated: March 3, 2026
Forgetwell is operated by Bluelight Inc. ("we", "us", or "our"). We are committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data.
1. Information We Collect
We collect the minimum information necessary to provide the Forgetwell service:
- Account information: Your email address, display name, and a securely hashed password when you register. If you sign in with Google, we receive your email, name, and Google account ID. If you sign in with Apple, we receive your name (on first sign-in) and your email address (or, if you choose "Hide My Email," Apple's private relay address) along with a stable Apple user identifier.
- Notes and tags: The content you create within Forgetwell, including notes, tags, and your organizational preferences.
- Uploaded images: Images you attach to your notes are stored on our servers.
2. How We Use Your Information
We use your information solely to:
- Provide, maintain, and improve the Forgetwell service
- Authenticate your identity and secure your account
- Send account-related emails (verification, password reset) when applicable
We do not use your data for advertising, profiling, or any purpose unrelated to providing the service.
3. Data Storage and Security
Your data is stored in a SQLite database on our server. We take reasonable measures to protect your information, including:
- Passwords are hashed using bcrypt and never stored in plain text
- All connections are encrypted with HTTPS/TLS
- Authentication uses signed JWT tokens
- The server is hardened with firewall rules, SSH key authentication, and automatic security updates
4. Data Sharing
We do not sell, rent, or share your personal information with third parties. Your notes and tags are private to your account. Uploaded image URLs are link-private: anyone who obtains a specific image URL can fetch that image. We may disclose information only if required by law.
5. Cookies and Tracking
Forgetwell does not use cookies for tracking or analytics. We store your authentication token and theme preference in your browser's local storage to keep you logged in and remember your settings.
6. Data Export and Deletion
You can export all your data (notes, tags, and settings) at any time using the export feature in the app. If you wish to delete your account and all associated data, please contact us at the email below.
7. Third-Party Services
If you choose to sign in with Google, Google's privacy policy applies to the authentication process. We only receive your basic profile information (email, name, account ID) and do not access any other Google data.
If you choose to sign in with Apple, Apple's privacy policy applies to the authentication process. We only receive your name (on first sign-in), email address, and a stable Apple user identifier. You may use Apple's "Hide My Email" feature, in which case we receive a private relay address instead of your real email; we do not attempt to unmask it.
8. Children's Privacy
Forgetwell is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "last updated" date. Continued use of Forgetwell after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this privacy policy or your data, contact us at support@bluelight.ventures.