Information on your devices
Whalyn saves changes locally first. In a browser, notes and workspace settings are kept in browser storage, and attachment contents are kept in IndexedDB. In the iOS app, notes and attachments are kept in the app’s local storage. The iOS share extension temporarily places a page address, title, and excerpt in Whalyn’s shared app-group inbox so the app can import the clip.
If you enable reminders, the browser or iOS app schedules notifications on that device. A notification may show the note title, depending on your device’s notification settings.
Local-only notes are not sent to Whalyn’s account service unless you sign in and sync. Your browser or device controls the protections and backups for these local copies. They can remain on a device after you delete an account elsewhere, and downloaded exports remain wherever you saved them.
Information stored for account sync
If you create or use a Whalyn account, the service stores your email address, a salted password hash, session records, and the notes and files you choose to sync. Note data can include titles, formatted text, spaces, tags, tasks, reminder dates, related-note links, and web-clip addresses or excerpts. Attachments are stored with their note. Whalyn uses this information to sign you in, keep your workspace available across devices, and provide the features you request.
Account notes and files are stored on Whalyn’s servers so they can sync. They are not end-to-end encrypted: the service operator can access account data to operate and support the service. Passwords are stored as one-way salted hashes rather than readable passwords. Whalyn uses an essential session cookie for account authentication; it does not use advertising cookies.
Technical access logs may contain a network address, request path, method, response status, and timing. The Whalyn application access log does not record request bodies or headers, including the AI API-key header. The operator’s hosting and encrypted backup infrastructure handles data to provide and recover the service. Logs are used to operate and protect the service.
Optional AI Assistant
The AI Assistant sends information only after you enter an OpenAI API key and choose Ask. Whalyn sends the open note’s title, up to 16,000 characters of its plain text, and your question through the Whalyn server to OpenAI. It does not send attachments or other notes. Whalyn forwards your key for that request and does not save it on its server. On the web, the key stays in the open tab’s memory; in iOS, you can optionally save it in this device’s non-synchronizing Keychain.
Whalyn requests store:false so the Responses API does not keep application state for the answer. OpenAI may still retain prompts and answers in standard abuse-monitoring logs for up to 30 days, with legal or safety exceptions. OpenAI API use may incur charges. See OpenAI’s data controls.
AI answers are shown temporarily and are not saved to your notes. Whalyn does not include advertising or analytics SDKs in the current web or iOS app.
Read-only share links
If you create a share link, anyone who obtains its unique URL can read that note while the link is active. The shared page excludes attachments and account details. You can revoke the link from the note. Like other URLs, a share link may remain in a recipient’s browser history or in technical infrastructure logs.
Exports, deletion, and retention
You can export your workspace as a Whalyn JSON backup or as Evernote ENEX. Account deletion is available from the profile menu on the web and from Account in the iOS app. Deleting an account removes its active server account, notes, share links, sessions, and attachment files. Local copies on other devices and copies you exported are not removed by a server-side account deletion.
Whalyn’s server is included in encrypted system backups. Those backups follow a rolling schedule of 14 daily, 8 weekly, and 6 monthly snapshots, so a deleted item may remain in an older backup until that snapshot expires. Technical service logs follow the host’s log-retention settings.
Local-only notes remain in browser or app storage until you delete them or clear that storage. You can contact the person who provided your Whalyn invitation for privacy questions or help with an account.
Changes to this policy
Whalyn may update this page as its features or data practices change. The date at the top shows when the page was last revised. Please review it again when a new version is published.