Privacy policy
Last updated: October 10, 2026 (the app's new name and address, how to reach us, and a clearer account of how Cobbleday stores and uses Google data).
Cobbleday (formerly called cairn) is a notes, tasks and calendar app at app.cobbleday.com. In this policy "Cobbleday", "we" and "us" mean the operator of the service. It is a small, invite-only beta: you can sign in only if your Google account's email address is on its beta list. It is free, has no ads, and is offered as is, without guarantees. This website, cobbleday.com, uses no cookies, analytics or trackers.
What Cobbleday stores, and where
- On Cobbleday's server (a rented server in a data centre): the notes, tasks, projects, events and settings you create, synced between your devices. Each account's data is kept in its own database. Also: your email address and Google account id (to sign you in), a Google sign-in token (so Cobbleday can work with your Drive and Calendar when you aren't using it), the devices signed in to your account (name, type, app version, last activity), and counts and sizes of your data (how many tasks, how much storage) for running the service.
- In your Google Drive, in a Cairn folder (the app's former name): your attachments, Markdown copies of your notes, and backups of your Cobbleday data.
- On your devices: a copy of your data, so Cobbleday works offline. Each account signed in on a browser keeps its own copy, apart from anyone else's.
Your data is not sold, shared with third parties, used for advertising, or used to train AI models.
Who can see it
Other users never see your data, and the app has no way to show it to anyone but you. Our admin page shows only accounts, counts, sizes and statuses (for example "12 notes, 3 MB"), never the content of a task, note, event or file. To be straightforward: as the people running the server, we can technically access the files on it, including the databases that hold your data. We don't look at them, except when you ask for help with your own data.
Error reports and feedback
-
Error reports (on by default during the beta; turn them off in Settings → About → "Send error reports"):
when Cobbleday crashes, a sync fails or the server has an error, the app sends what kind of error it was, where in
Cobbleday's code it happened, the page it was on as a pattern (for example
/notes/:id), the app version and the kind of device (for example "web · Chrome · Linux"). Quoted text, email addresses and ids are removed on your device and again on the server, and no task, note or event text is ever included. Reports are stored on Cobbleday's server with your account, are seen only by us, and are deleted after 30 days. - Feedback you send with "Send feedback" comes to us, and we read it: your words, your email address (so we can reply), the details you leave in (app version, device, page, theme, window size) and a screenshot if you add one. It is the only place we see anything you wrote, because you chose to send it. It is kept for up to 180 days.
- To measure reliability, the server also counts app starts per app version and the days on which each account synced a change.
Deleting your account removes your feedback and your part in error reports within a day. No third-party error, analytics or tracking service is used.
How Cobbleday uses Google data
-
Google Drive (
drive.file): Cobbleday only sees the files it created itself (the Cairn folder above). It cannot see your other Drive files. -
Google Calendar (
calendar.events,calendar.calendarlist.readonly): Cobbleday reads your calendars and events to show them, and creates, changes or deletes events only when you ask it to (for example, time-blocking a task). Cobbleday's server keeps a copy of the list of your calendars and of their events (title, description, times, repeats, reminders), from about 90 days back to about 13 months ahead, so the calendar loads quickly and changes sync both ways; your devices keep the list of calendars for offline use. The copy follows your changes in Google, and is deleted with your account. - Basic profile (
openid,email): to identify the account signing in.
Google data is used only to provide these features, the ones you see and use in Cobbleday. In particular, it is:
- never sold, never used for advertising, and never transferred to anyone else, except as needed to provide these features to you, to comply with the law, or to keep the service secure (for example, investigating abuse);
- never read by a person, except with your permission (for example, when you ask for help with your own data), for security purposes, or where the law requires it;
- never used to create, train or improve machine-learning or AI models.
Cobbleday's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Taking your data with you
In Cobbleday, Settings → Account → Export your data downloads a ZIP file of everything you keep in Cobbleday: your notes as Markdown files in their folders, the files you attached, your tasks, projects, events and the rest as JSON (tasks also as a spreadsheet file), and your settings. It never contains sign-in tokens. You can export once every 10 minutes; the download link works for an hour.
Removing access and deleting your data
You can revoke Cobbleday's access to your Google account at any time at myaccount.google.com/permissions. Signing out of Cobbleday on a browser removes that account's data from that browser; the desktop app asks whether to keep it.
To delete your account, use Settings → Account → Delete account in Cobbleday on the web. To confirm, you sign in with Google once more and type your email address. Then, at once: every browser and device is signed out and removes its copy of your data the next time it connects, Cobbleday's access to your Google account is revoked, and your account and its data leave the service. The server keeps the data for 30 days in case the deletion was a mistake (email privacy@cobbleday.com within that time to get it back), then erases it for good, together with the server's own backup copies of it. What remains is a short entry in the server's account log: that an account with your email address existed and was deleted, and when. Using Cobbleday again later takes a new invite, and starts empty. You can also ask for the deletion by email, at privacy@cobbleday.com.
Files Cobbleday put in your Google Drive (attachments, Markdown copies of your notes, backups) stay yours; delete the Cairn folder in Drive to remove them.
Contact
Privacy questions and requests (export, deletion, correction): privacy@cobbleday.com. Anything else: hello@cobbleday.com.