The short version. dotMD does not collect anything. There
is no account, no sign-up, no analytics, no advertising, no tracking and no
third-party SDKs. Your notes are plain Markdown files that stay on your
device unless you choose to sync or share them.
We cannot read your notes. There is no server to read them from.
What dotMD stores, and where
Your notes are .md files written to one of
three places, whichever you choose in Settings → Sync:
- A folder you pick — for example inside iCloud Drive, Dropbox or an
Obsidian vault. That service then syncs the folder under its own privacy
policy.
- The app's private iCloud container, if enabled — synced by Apple to your
devices under your Apple ID.
- On your device only.
Your preferences (theme, font, accent colour, app lock
choice and similar) are stored in the app's own settings storage on the
device.
Nothing else is stored. No usage data, no crash reporting,
no identifiers.
Data we collect
None.
For App Store purposes: dotMD collects no data types,
performs no tracking, and links nothing to your identity.
Network activity
dotMD makes no network requests of its own. The single exception is that the
Reading View loads the MathJax library from
cdn.jsdelivr.net in order to display mathematical notation. That
request contains no note content and no personal information — it fetches a
public JavaScript file. Rendered pages are served with a Content Security
Policy that blocks them from sending data anywhere.
If you tap a link inside a note, it opens in your browser as normal, and
that site's own policies apply.
Security
- On iPhone and iPad, notes are encrypted at
rest by iOS data protection whenever your device is locked with a
passcode.
- On Mac, files are protected by FileVault
if you have it switched on — that's a macOS setting you control, not
something dotMD can enable. If FileVault is off, your notes are stored
unencrypted, exactly like any other document on your Mac.
- Optional App Lock (Face ID, Touch ID or device passcode)
can be required to open the app. Biometric data is handled entirely by
Apple; dotMD never sees it.
- Note content can be hidden when the app isn't in front,
so it doesn't appear in the iOS app switcher or when the app is hidden on a
Mac.
- Rendered and exported HTML escapes note content and blocks unsafe URL
schemes, so a malicious file you open cannot run code or exfiltrate your
note.
Permissions dotMD asks for
- Face ID / Touch ID — only if you enable App Lock, only to
unlock the app.
- Photos — only when you insert an image into a note, and
only the image you choose.
- Files / folder access — only the file or folder you
explicitly pick, so dotMD can read and write your notes there.
Each is requested at the moment you use the feature, and each can be
declined.
Your data, your control
Your notes are ordinary Markdown files. You can open them in any other
editor, move them, back them up, or delete them outside dotMD entirely.
Deleting the app removes its local notes; notes kept in a synced folder remain
with that service.
There is no account to close and no data for us to delete, because we never
receive any.
Children
dotMD is a plain text editor. It collects no data from anyone, including
children.
Changes
If this policy changes, the date at the top will change with it.
Contact
Questions about privacy in dotMD:
support@luistorres.app