Privacy policy
Last updated: August 18, 2026
This policy explains what information the monthlet.ai website collects and how it is used. It covers this website, the download and update-check endpoints, the monthlet AI waitlist, and problem reports sent explicitly from the app. The monthlet desktop app stores your notes on your device; we do not receive them, except for content you explicitly send us through the app’s problem-report feature. The app itself is governed by its EULA, shown on first launch.
Information we collect
Waitlist. When you join the monthlet AI waitlist, we store your email address, your language preference, the time of signup, and your browser’s user-agent string. We use this only to notify you when monthlet AI becomes available and to share closely related product updates. We do not use it for anything else.
Download counting. When you download the app via /download, we record a one-way hash of your IP address (SHA-256 with a salt that changes daily), the date, your browser’s user-agent, and where the visit came from (the referring site, or a short campaign label such as “reddit” from the link you followed). The raw IP address is never stored, and the hash cannot be traced back to you. This exists only to count unique downloads per day and to see which channels bring them.
Update-check counting. The monthlet app periodically contacts our update endpoint to check for new versions. When it does, we record one-way hashes of the IP address (SHA-256 with salts that rotate daily, weekly, and monthly), the date, and the request’s user-agent string. The raw IP address is never stored, and the hashes cannot be traced back to you or linked across periods. This exists only to count unique active installations per day, week, and month.
Problem reports. When an AI response in the app’s chat was not what you expected, you can send us the content of that exchange. It is sent only when you review the content on screen and perform the send operation yourself. A report includes your message, the AI response, the tools the AI called, the name of the AI model used, and the app version. You can optionally add a comment and an email address. We use reports only to investigate problems in monthlet and improve its quality, and for nothing else. Reports are kept until they have served that purpose, and for no longer than 12 months. If you contact us with the report ID shown after sending, we will delete that report. If we become aware that a report contains personal information about someone other than the sender, we will delete it.
Site analytics. We use Cloudflare Web Analytics, which is cookie-less and aggregate. It does not identify individual visitors. In addition, if you agree to it, we use Google Analytics to see which pages are read, how far into them people get, and where visitors came from. Nothing is sent to Google Analytics unless you agree: it is off by default, and the banner shown on your first visit is what turns it on. Advertising features, including Google Signals, are not enabled.
Cookies. This website does not use cookies for tracking unless you agree to Google Analytics. If you do, Google Analytics sets its own cookies (names beginning with _ga) to tell repeat visits apart and to keep a session together. They are not used for advertising.
Changing your mind. Declining leaves nothing stored beyond a note of that choice, and no measurement happens. If you agreed and want to stop, clear this site’s cookies and site data in your browser; the banner will ask again on your next visit. Google also offers a browser add-on that opts you out of Google Analytics on every site.
Where your data lives
The website and its data run on Cloudflare (hosting, the waitlist database, the problem-report database, and analytics). Waitlist entries are also copied to a private Google Sheet for operational review. Downloads and app updates are served from GitHub Releases, so GitHub receives your IP address when downloading them, under its own privacy policy. If you agreed to Google Analytics, Google receives the measurement data described above, under its own privacy policy.
Storing data with these providers is a form of entrustment: we review their terms and security practices and supervise that your data is handled appropriately.
We do not sell your data, show ads, or share your information with anyone beyond the service providers above.
How we protect your data
We collect as little as possible to begin with, and protect what we do hold: access is limited to the operator and guarded with multi-factor authentication, and the services that store the data (Cloudflare and Google) apply access controls and encryption in transit and at rest.
Where the data is processed. Waitlist data and problem reports are stored on Cloudflare and Google servers located in the United States. We keep ourselves informed about the data-protection rules that apply there and apply the safeguards above accordingly.
Retention and your rights
Waitlist entries are kept until they have served their purpose (notifying you about monthlet AI) or until you ask us to remove yours.
Problem reports are kept until they have served their purpose (investigating the problem), and for no longer than 12 months; after that they are deleted automatically.
Under applicable law (including Japan’s Act on the Protection of Personal Information), you may ask us to disclose the personal data we hold about you or its purpose of use, correct it, delete it, stop using it, or stop providing it to third parties. Email [email protected] from the address you signed up with (or with other reasonable proof of identity), and we will respond without undue delay. If a legal exception prevents us from fulfilling a request, we will tell you why.
For problem reports, the email address is optional, so requests are matched using the report ID shown when you sent the report. Include that ID when you contact us.
The monthlet app and your notes
Your notes are plain HTML files stored locally on your Mac. They are never uploaded to our servers.
When you use the in-app chat with your own AI provider API key, requests go directly from your device to that provider (such as Anthropic, OpenAI, or Google) under that provider’s terms. We do not proxy, log, or store those requests, except for content you explicitly send us through the problem-report feature described above.
Google account integrations
monthlet can connect to Google Sheets and Google Calendar, so that the in-app chat can read a spreadsheet you point it at, read your schedule, and add an event when you ask for one. Each connection is optional and stays off until you set it up in Settings, and you can disconnect it at any time.
What we ask for. For Sheets, read-only access to your spreadsheets (spreadsheets.readonly). For Calendar, access to your events (calendar.events) and read-only access to the list of your calendars (calendar.calendarlist.readonly), so that you can choose which calendar to work with. In both cases we also ask for your email address (openid, userinfo.email) so the app can show which account is connected. monthlet does not request permission to change your spreadsheets, and does not request access to Google Drive.
Creating calendar events. calendar.events covers writing as well as reading, and monthlet uses it to create an event when you ask for one. Every event is shown to you for approval before it is created, and nothing is written if you decline. monthlet does not modify or delete events that already exist; the app has no function that does so.
How it is handled. The authorisation is stored encrypted on your device using the operating system’s credential protection, and is never sent to our servers. Spreadsheets and calendar entries are read on your device; the contents you ask about are passed to the AI provider you configured, the same way as the rest of your chat. We do not proxy, log, or store them. Disconnecting revokes the authorisation with Google and deletes the stored credentials from your device.
Future connectors may request access to other Google services. Each one is optional and asks for its own consent before anything is accessed.
monthlet’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who operates this service
This website and monthlet are operated by t27d, an individual developer based in Japan. The operator’s legal name and address, as required to be made available under Japanese privacy law, will be provided without undue delay on request at [email protected].
Changes to this policy
If this policy changes, we will update this page and the date above. Material changes will be noted on this page.
Language
This policy is prepared in Japanese and in English. The Japanese version is the authoritative text; if the two differ, the Japanese version prevails.
Contact
Questions or requests: [email protected]