Privacy
Last updated 31 July 2026
1. What is stored
Using HeadTidy without an account keeps everything in your browser's session storage. It never reaches a server. Signed-in accounts sync their profile, folders, map content, comments, share permissions, activity, versions and recovery checkpoints to HeadTidy's cloud database so the same workspace is available on your other devices.
2. Images
Images are processed on your device, stripped of their original metadata and converted to an optimised format before anything is stored. For signed-in accounts the optimised image is uploaded to private storage that only you can access, and the map holds a temporary signed link rather than the image itself. The original file is never uploaded. Guest and local modes keep the image on your device.
3. Analytics, feedback and advertising
HeadTidy uses privacy-preserving analytics for anonymous, aggregated page views: page path, referrer, country, device type, operating system and browser. It does not send map content, thought text, account details or custom behavioural events. Private share-link visits are excluded, and query strings are removed before a page view is recorded. Interface fonts are bundled with the application, so no font provider is contacted. There is no advertising and no sale of personal data.
If you submit the in-app feedback form, HeadTidy stores your chosen type and message plus the app version, browser, device type and current view. It never attaches map titles, thought or note text, table data or images.
4. Your controls
Signing out ends the local session while keeping your maps for next time. Clearing this site's browser data removes local accounts and maps from that browser. Deleting your account hides it and revokes its share links immediately, then schedules permanent removal after a recovery window. Export a backup first if the content matters: HeadTidy exports lossless JSON, Markdown, OPML, PNG and PDF on every plan.
5. Sharing and processors
Private share links behave like passwords: anyone holding one can use its View, Comment or Edit permission until it expires or you revoke it. Owners can add a passcode and can see last access time and open counts. HeadTidy uses third-party infrastructure providers to host the application and store account data. Adding any new processor, or enabling payments, requires this notice to be updated first.
6. Contact
The public launch must publish the operator's legal name, postal address and a privacy contact address here.