Tagged Sync for reMarkable

Privacy

Last updated:

Short version: this website sets no cookies and the plugin has no telemetry. Nothing about how you use either is collected, counted or sold. The only personal data that reaches me at all comes from buying a licence or from writing to me.

Responsible for this processing (controller, Art. 4 No. 7 GDPR): hochbichler.com - IT Services e.U., owner Thomas Hochbichler, Rapoldeck 58, 3335 Weyer, Austria, support@hochbichler.com. Full contact details: Imprint.

1. This website

Hosting. The site is served by Cloudflare Pages (Cloudflare, Inc.). Like every web server, Cloudflare processes the technical data a browser must send to receive a page — IP address, time, requested URL, user agent — to deliver the site and defend it against attack. Legal basis: legitimate interest in operating a secure website, Art. 6(1)(f) GDPR. Cloudflare acts as processor under a data processing agreement and the EU standard contractual clauses. How long: I neither receive these server logs nor store them. Cloudflare holds them only as long as it needs them to deliver and defend the site, under its own retention rules, and then deletes them.

Measurement. The site uses Cloudflare Web Analytics. It counts page views and referrers. It sets no cookie, stores nothing on your device and builds no fingerprint or cross-site profile. Because nothing is stored on or read from your device, no consent banner is required (§ 165 TKG 2021). Legal basis: legitimate interest in knowing whether the site works at all, Art. 6(1)(f) GDPR. How long: what I see is an aggregate — counts per page and per referrer, with no identifier that could be traced back to a single visit. Cloudflare retains that aggregated report under its own retention rules; on my side there is no record about you to keep or to delete.

Redirect pages. Links to the Obsidian store, the checkout and the repository pass through /go/… pages. They exist so a click shows up as a page view in the same cookieless statistic. They store nothing.

No third parties beyond that. No advertising, no tracking pixels, no embedded video, no externally hosted fonts, no social widgets. The one file not served from this domain is the analytics script above, delivered by Cloudflare from static.cloudflareinsights.com. Everything else — text, images, video, styles — comes from taggedsync.com itself.

2. What the plugin sends, and when

The plugin runs on your own machine. It talks to your reMarkable account — or, with Pro, to your tablet directly — and to a transcription backend you configure. None of that goes to me, and no page image or transcript ever leaves your device except to a backend you set up yourself.

The direct connection to your tablet is a Pro feature and stays inside your own network, or on the USB cable. It reaches no server of mine and no third party; a vault that syncs this way needs no reMarkable account at all. When you pair a tablet, the plugin asks you for its root password, uses it for that one connection to install an access key for this vault, and never stores it. After pairing it reads files from the tablet and runs a few commands on it to list them and to compare them with what you already have.

The licence check is the only call the paid tier makes over the internet: if you use a Pro feature, the plugin asks polar.sh whether your key is valid — at most once every seven days, sending the key, this vault’s activation id and the plugin’s public organization id. No email address, no vault name, no note content, no usage statistics. A free user causes no such call, ever.

The trial ticket is the one request the plugin makes to a server of mine: when you press Start free trial, the plugin sends taggedsync.com a 12-character hash of the id Obsidian gave your vault — no name, no path, no note, no email — and gets the trial’s start date back, signed. The server keeps, per hash, the date it first issued, the date it was last asked and a count, so that a vault gets the same 14 days back however its data.json is edited or the plugin reinstalled. Never on load, never on sync, never unless you press the button. Basis: my legitimate interest in a trial that ends, Art. 6(1)(f) GDPR; the hash is linked to no person.

The authoritative, detailed description lives with the plugin: PRIVACY.md in the repository.

3. When you buy

Polar Software Inc. is the seller and merchant of record. It runs the checkout and collects your email address, payment and tax data as its own controller, under Polar’s privacy policy. I never see your card details.

Separately, I keep a minimal buyer list: email address, order id and date, licence key — so a key can be re-issued if it is lost or if the payment provider disappears. Legal basis: performing the licence contract, Art. 6(1)(b) GDPR, and my legitimate interest in being able to honour perpetual licences, Art. 6(1)(f) GDPR. It is kept locally, encrypted at rest, shared with no one, and held as long as the licence exists — which, the licence being perpetual, means indefinitely. Ask me to delete your entry and I will; the trade-off is that I can then no longer re-issue your key.

4. Support

A GitHub issue is public and processed by GitHub under its own terms. If you email me, I keep the correspondence as long as it is useful for support, and no longer.

5. Transfers to the United States

Cloudflare, Inc., Polar Software Inc. and GitHub, Inc. are established in the United States, so the processing described above involves a transfer of personal data to a third country (Chapter V GDPR).

Cloudflare acts as my processor. The transfer is covered by a data processing agreement incorporating the EU standard contractual clauses (Commission Implementing Decision (EU) 2021/914).

Polar and GitHub act as controllers in their own right for what they collect — the checkout and the public issue tracker respectively. Each is responsible for its own transfer basis, set out in Polar’s privacy policy and GitHub’s privacy statement.

The buyer list I keep myself never leaves my own machines and is not transferred anywhere.

6. Your rights

You can ask for access, correction, erasure, restriction or portability (Art. 15–20 GDPR). Write to support@hochbichler.com — no form, no account. You can also complain to the Austrian data protection authority, the Datenschutzbehörde. For data held by Polar as the seller, address Polar directly; I cannot delete records in their system.

7. Your right to object

This one is set out separately because Art. 21(4) GDPR says it must be.

Where I process your data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, on grounds relating to your particular situation. That basis is used in exactly three places on this page: the hosting logs, the cookieless page-view statistic, and keeping your entry on the buyer list so a lost key can be re-issued.

To object, write one line to support@hochbichler.com — no form, no account, no reason required beyond your situation. I will then stop that processing unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.