Article 01
Data controller
The controller for the processing described in this policy is the publisher of Newral: [To be completed: name, legal form, address and privacy contact].
Newral · Privacy
This policy explains, in order, which data may be processed when you use Newral, why it is processed and what rights you have.
Effective date: [To be completed: date] · Version: [To be completed: number]
Article 01
The controller for the processing described in this policy is the publisher of Newral: [To be completed: name, legal form, address and privacy contact].
Article 02
This policy covers the public website newral.fr and the web application app.newral.fr. Newral is a local-first Markdown application with no Newral account or note-storage backend. A local folder works without a third party; you may also connect a GitHub repository.
The policies of your browser, operating system, GitHub and delivery or hosting providers describe their own processing activities.
Article 03
Your notes. In local mode, note files are processed only in your browser. In GitHub mode, they travel directly between your browser and GitHub; Newral’s publisher and authentication functions do not receive them.
GitHub connection. If enabled, GitHub supplies your public login, GitHub App installations and authorised repository list. The user token is held in an encrypted HttpOnly cookie; the browser receives a temporary installation token limited to the selected repository.
Technical browsing data. When the website loads, the hosting infrastructure may receive information needed to serve the request, such as IP address, browser and device type, date and time, requested page and diagnostic information.
Website analytics. On public pages of newral.fr only, Vercel Web Analytics processes anonymous, aggregated page views. Note content, file names and actions in the application are excluded.
Vault settings. The app stores workspace preferences in .newral/config.json inside the chosen folder or repository.
Installed app. When Newral is installed from a compatible browser, its cache contains only the application interface and versioned technical files. It contains no notes, file names, GitHub responses or tokens.
Public-site display preferences. The public pages of newral.fr keep the light or dark theme selected in the footer in your browser’s local storage. Language is carried by the page URL. The theme stays in your browser, is sent to no one and identifies no one; clearing site data removes it.
Article 04
File processing lets the app display, edit, create, connect and organise notes. GitHub authentication and repository authorisation are used only when you select GitHub storage.
Technical data is used to deliver pages, keep the service available and secure it. The publisher’s legal basis: [To be completed: legal basis and, where necessary, legitimate interest].
Aggregated public-site statistics help understand page traffic and improve content. The applicable legal basis: [To be completed: legal basis and rationale].
Article 05
Permission to access a local folder or GitHub repository is optional, but the app cannot open or save notes without one of them.
Technical data associated with a web request is needed to display the requested page.
Article 06
Local notes remain in the selected folder on your device for as long as you choose. GitHub notes and commit history remain in the repository under your GitHub settings.
The most recent local folder handle may remain in IndexedDB; the selected GitHub repository metadata may remain in localStorage. Clearing site data removes these reopening aids and the GitHub session cookie. Hosting log retention: [To be completed: duration or retention criteria].
The audience-measurement choice is kept in the browser’s local storage for up to six months, then requested again. Google Analytics cookies are set only after consent; their retention and the retention of Google Analytics reports are configured in the Google Analytics property.
The vault configuration remains until it or the selected folder or repository is changed or deleted.
Article 07
Local notes are not sent to a recipient. In GitHub mode, GitHub receives and stores repository files and commits directly from the browser; note content does not pass through Newral’s Vercel Functions.
The public website and web application are hosted by Vercel, which may process technical browsing data and encrypted GitHub session material needed to provide the service. If you consent, Google also processes public-site audience measurement data through Google Analytics 4.
Other potential recipients: [To be completed: list, or “none”].
Article 08
Vercel’s, GitHub’s and, where Google Analytics is accepted, Google’s processing conditions and subprocessors may involve international transfers. The scope applicable to Newral and safeguards used: [To be completed: countries, transfer mechanism and how to obtain a copy of safeguards].
Article 09
GitHub mode uses secure, HttpOnly first-party cookies for temporary OAuth state and the encrypted session. They are necessary for GitHub connection and are not used for advertising or analytics.
Only if you consent, the public website loads Google Analytics 4, Vercel Web Analytics and Vercel Speed Insights to measure visits and performance on public pages. Google Analytics may process IP address and browsing data and set audience-measurement cookies. These services are not used for advertising, retargeting or personalisation.
You can accept, reject or change your choice through the Cookie settings link in every public-page footer. Withdrawing consent disables measurement and deletes Google Analytics cookies accessible to the browser. No custom event is recorded. The analytics component is absent from app.newral.fr; no note, file name or interaction in your vault is transmitted for this purpose.
Article 10
The architecture limits exposure: local notes stay in the selected folder and GitHub notes go directly to GitHub’s API, with no storage on a Newral server. Access is limited to the folder or repository you explicitly select.
You remain responsible for the security of your device, folder, GitHub account and backups.
Article 11
Depending on the processing and its legal basis, you may exercise rights of access, rectification, erasure, restriction, objection and portability, and withdraw consent where it is the legal basis.
For notes held only on your device, you exercise this control directly by viewing, editing or deleting your files. For technical data relating to the publisher, contact [To be completed: privacy contact email].
Article 12
If, after contacting the publisher, you believe your rights are not respected, you can lodge a complaint with the competent data-protection authority.
Submit a complaint to the CNILArticle 13
This policy will be updated if Newral’s processing or services change. The new version will be published on this page with its effective date.
Date of last revision: [To be completed: date].