Privacy Policy
Effective August 20, 2026 · Last updated September 2, 2026
1. Overview
Ensō is made by Raintree Forge LLC ("we", "us"). This policy covers this website (ensoapp.io), the web app at app.ensoapp.io, and the Ensō desktop and mobile apps.
The short version:
- Your content is yours. We store it only to sync and back it up for you.
- We don't sell your data, and Ensō itself shows no ads. The desktop and mobile apps contain no advertising or analytics trackers; this website and the web app at app.ensoapp.io use Google Analytics — and Google's advertising tools to measure and personalize the ads we run for Ensō elsewhere — but only if you accept when we ask.
- We collect the minimum needed to run the service: an email address, your content, and operational logs.
- You can export your data and delete your account at any time.
2. Data we collect
- Account data — your email address and a hash of your password (we store passwords only as Argon2 hashes, never in plain text).
- Your content — the things you create in Ensō: todos, notes, calendar events, reading-list items (including saved offline copies of pages), projects, and mail state.
- Device & sync metadata — a record per signed-in device and the change log that keeps your devices in sync (what changed and when).
- Server logs — standard access logs (IP address, user agent, request timestamps), kept briefly for security and debugging.
We do not collect usage telemetry from the desktop or mobile apps — they contain no analytics or usage-tracking scripts.
Analytics. This website — ensoapp.io, including
the documentation at /docs/ — and the web app at app.ensoapp.io use
Google Analytics to count page views and see which pages and steps
people find useful. In the web app that includes broad milestones
like reaching the sign-up form, creating an account, visiting the
billing page, and starting or cancelling a checkout — never the
content of what you type, and never your notes, tasks, or other
content. It is off until you say otherwise: we ask on your first
visit, no analytics cookies are set unless you accept, and your
answer is remembered in a small enso-consent cookie
shared across ensoapp.io and app.ensoapp.io, so one answer covers
both and we don't ask twice. If you do accept, Google Analytics
stores _ga cookies (scoped to ensoapp.io and its
subdomains) so a repeat visit isn't counted as a new person.
Advertising. Accepting also turns on Google's advertising features for the ads we run for Ensō elsewhere: conversion measurement (so we can tell which ads actually lead to sign-ups) and ad personalization (Google may use your visit to show you more relevant Ensō ads and to build the audiences those ads reach). Ensō itself never shows ads, and your content is never involved. If you decline, none of this runs — no analytics or advertising cookies are set, and nothing about your visit is shared with advertisers. You can change your answer at any time in section 7.
Crash and error reports. When something in the app
or on our server breaks, a report is recorded so we can fix it:
the error message, a technical stack trace, the screen you were on
(the app route, not its contents), the app version and platform,
and — for reports tied to a signed-in account — your account id so
we can follow up. Reports never include your notes, tasks, pages,
or email content, and anything email-address-shaped is replaced
with [email] before the report leaves the device. We
keep these reports on our own server for 30 days. We also send
them to Sentry (Functional Software, Inc.), an
error-monitoring service that processes them on our behalf under
its privacy policy; Sentry reports are configured
to carry no IP addresses or personal identifiers.
3. Connected email accounts (Gmail / Outlook)
Ensō's Email module is optional. If you connect a Gmail or Outlook account, you authorize Ensō via OAuth — we never see or store your email password. We access your mailbox only to display, organize, and file your mail at your direction, and we sync only the mail state the feature needs. Your mail is never used for advertising, profiling, or training, and is never sold or shared.
Ensō's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect a mail account in Ensō at any time, and you can also revoke Ensō's access from your Google or Microsoft account security settings.
4. End-to-end encrypted vaults
Content you place in a vault is encrypted on your device before it's sent to us. Our servers store only ciphertext: we cannot read vault contents, cannot search them, and cannot recover them if you lose both the vault password and the recovery code. Vault data is excluded from everything else in this policy that would involve us processing content, because we can't.
5. How we use data
We use your data only to:
- provide the service — store your content, sync it between your devices, and back it up;
- keep the service secure — authentication, abuse prevention, and debugging with operational logs;
- support you when you contact us;
- send transactional service email (such as verification or password-reset messages). We won't send marketing email without your separate consent.
We don't use your content for advertising or to train machine learning models.
6. Where your data lives
Ensō's servers are located in the United States, and encrypted backups are kept at a separate location, also in the United States. If you use Ensō from outside the US, your data is transferred to and processed in the US. Your devices additionally keep a full local copy of your workspace — that copy lives only with you.
7. Sharing & third parties
We do not sell your personal data, and we do not share it with advertisers or data brokers — ever. Data leaves our systems only in these cases:
- Infrastructure — our servers run on a hosting provider's machines; like any host, it processes data on our behalf under its service agreement.
- Payments — when paid plans are live, payments are handled by Stripe (Stripe, Inc.). Card details go to Stripe directly and are never stored on our servers; we keep your Stripe customer id, subscription status, and billing period, and Stripe processes your payment information under its own privacy policy. Stripe may also collect your billing address for tax purposes.
- Error monitoring — crash/error reports (see section 2) are processed by Sentry (Functional Software, Inc.) on our behalf. They contain technical details only — never your content.
- Analytics & advertising — if you accept, page-view and milestone data from this website and the web app at app.ensoapp.io (see section 2) is processed by Google Analytics, and Google's advertising services (Google Ads) may use it to measure and personalize the ads we run for Ensō — all Google LLC, under its own privacy policy. This never covers your content or the desktop and mobile apps, and if you decline, none of it runs.
- Providers you connect — if you connect Gmail or Outlook, your requests naturally flow to Google or Microsoft under their own privacy policies.
- Legal requirements — if we're legally compelled (for example by a valid court order), we may have to disclose data; we'll notify you unless we're legally barred from doing so.
- Business transfer — if Raintree Forge LLC is ever acquired or merged, your data may transfer with the service, under this policy's protections.
8. Retention & deletion
- We keep your data for as long as your account is active.
- When you delete individual content, it's removed from the live service; when you delete your account, your server-side content and account data are deleted.
- Deleted data can persist in encrypted backups for up to 90 days before aging out; backups are never used to "undelete" an account except at your request during that window.
- Server logs are retained for a short operational window and then discarded.
- Copies on your own devices are under your control and are yours to keep or delete.
9. Your rights
Wherever you live, you can access, correct, export, or delete your data. Export and account deletion are available in the app; for anything else, email contact@raintree.dev and we'll respond within 30 days.
If you're in the EU/EEA or UK, the GDPR gives you these rights formally — access, rectification, erasure, portability, restriction, and objection — plus the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are the performance of our contract with you (running the service) and our legitimate interest in keeping it secure.
If you're a California resident, the CCPA/CPRA gives you the rights to know, delete, and correct, and the right not to be discriminated against for exercising them. We don't sell or share personal information as those terms are defined in the CCPA, so there's nothing to opt out of.
10. Security
- All traffic is encrypted in transit with TLS.
- Passwords are hashed with Argon2; vaults add client-side end-to-end encryption on top.
- Desktop app updates are cryptographically signed.
- Data is backed up nightly to a separate, isolated location, and restores are tested regularly.
No system is perfectly secure, but if a breach ever affects your data we'll notify you promptly and tell you what happened and what we're doing about it. Security researchers: please report vulnerabilities to contact@raintree.dev and give us a reasonable chance to fix them before public disclosure.
11. Children
Ensō isn't directed at children under 13, and we don't knowingly collect data from them. If we learn an account belongs to a child under 13, we'll delete it. If you believe a child is using Ensō, contact us.
12. Changes to this policy
We may update this policy as the service evolves. For material changes we'll give notice by email or in the app before they take effect, and the effective date at the top of this page always reflects the current version.
13. Contact
Raintree Forge LLC · contact@raintree.dev