Terms of Service
Last updated: April 28, 2026 (version 2026-04-28)
Summary
A plain-English outline of what this agreement says. The numbered sections below are the actual Terms — they control if there's ever a conflict.
- You must be at least 16 to use the Service. One account per person; you're responsible for what happens under your login and under any API tokens you generate (§10).
- Every account can keep up to 10 notes free, forever. When you reach the cap, a subscription raises the ceiling — see Schedule A for the per-tier numbers — and you can always sign in, read, edit, and export what you've already written.
- Subscriptions renew automatically. You can cancel any time; cancellation takes effect at the end of the current billing period, and we don't pro-rate partial months.
- Your notes are yours. We only use them to run the Service (storage, backups, export) — we don't sell them, mine them, or train AI on them.
- You can delete your account and all associated notes at any time from your profile — or by emailing us. Before you do, request a full export from Options → Download all; the link is one-time and valid for 24 hours.
- EU/UK consumers retain all rights you cannot waive by contract — including a 14-day right of withdrawal (§20), subject to the immediate-performance consent collected at checkout.
Welcome to MyNotes. These Terms of Service ("Terms") are a binding agreement between you and MyNotes ("we", "us", "our"). They govern your access to and use of our website, applications, JSON API, and related services (together, the "Service"). Please read them carefully. By creating an account or otherwise using the Service, you agree to these Terms and to our Privacy Policy. If you do not agree, do not use the Service.
1. Eligibility
You must be at least 16 years old — the minimum age we enforce at signup — and otherwise old enough to form a binding contract in your jurisdiction to use the Service. If a higher minimum age applies where you live, you must meet that age. If you are using the Service on behalf of an organization, you represent that you have authority to bind that organization, and "you" refers to both you and the organization.
2. Your account
- You provide accurate registration information and keep it current — in particular the email address on your account, which we use for security and transactional notices (see §3).
- You are responsible for safeguarding your password and for every action taken under your account, including any actions taken via API tokens you have issued (see §10).
- You notify us promptly at support@example.com if you suspect unauthorized use of your account or of an API token issued from it.
- One person per account — please don't share logins. A single human may hold only one account unless we agree otherwise in writing.
- If you lose access to the email address on your account, we may not be able to recover the account on your behalf. Keep that address current and reachable.
3. Communications
Some communications are an inherent part of operating an account and you cannot opt out of them while you have an active one:
- Security and account-integrity notices — sign-in confirmations, password resets, email-change confirmations, and alerts about activity that looks unusual.
- Billing and subscription notices — receipts, renewal reminders, payment-failure notices, and any notice we are required to send under consumer-protection law.
- Transactional notices triggered by your own actions — for example, the one-time download link emailed when you request a full-account export (see §15).
- Material changes to these Terms or to the Privacy Policy — see §24.
We do not currently send marketing emails. If we add an opt-in marketing channel in the future, you will be able to subscribe at the time and to unsubscribe from any such message at any time without affecting the transactional communications above. Notices we send to the email address on your account are deemed delivered when sent, regardless of whether you have opened them.
4. The Service
MyNotes is a note-taking service. You can create, edit, organize, pin, rename, and export rich-text and plain-text notes, and read them from any signed-in browser. Paid tiers also expose a programmatic JSON API documented at /docs and governed by §10. The full set of capacity limits and rate limits that apply to your account is set out in Schedule A at the end of this document (also published at /limits). We may adjust those limits from time to time with reasonable notice for material reductions. Full-account exports are produced asynchronously and delivered via a one-time email link valid for 24 hours — see §15 for the full export flow.
5. Beta and pre-release features
From time to time we may make new functionality available on a beta, preview, or experimental basis. Beta features are clearly labelled, are provided "as is" without any service-level commitment, and may be changed, withdrawn, restricted, or rolled out unevenly to different accounts at any time without notice. The disclaimers in §22 and the limitation of liability in §23 apply with full force to beta features. Any feedback you choose to share about a beta is governed by §7.
6. Your content
Your notes are yours. We do not claim ownership of anything you create, upload, or store in the Service ("Your Content"). You are solely responsible for Your Content and for ensuring you have the rights to store and share it.
You grant us a worldwide, non-exclusive, royalty-free license to host, store, reproduce, back up, transmit, display, and create derivative copies of Your Content solely to operate, secure, and improve the Service (for example, replicating notes between servers, generating search indexes, or producing export archives at your request). This license does not authorize us to use Your Content to train machine-learning or AI models, or to sell Your Content to third parties. It ends when you delete Your Content or close your account, except for residual copies in encrypted backups, which expire on our normal backup rotation.
You retain all moral rights you may have in Your Content under applicable law. Public-share links you choose to generate are subject to the public-notes throttle in Schedule A and may be revoked by you at any time from within the Service.
7. Feedback
If you send us suggestions, feature requests, bug reports, or other feedback, you grant us a perpetual, irrevocable, royalty-free license to use it without restriction or compensation. You are not obligated to send us feedback, and we are not obligated to act on it or to keep it confidential.
8. Acceptable use
You agree not to, and not to attempt to:
- Store, upload, or distribute content that is illegal, infringing, defamatory, fraudulent, or that you do not have the right to share — including content that sexually exploits minors, which we report to the relevant authorities.
- Use the Service to harass, threaten, dox, stalk, or otherwise violate the rights or privacy of others.
- Impersonate any person or entity, or misrepresent your affiliation with one — including in profile fields, note content, or shared links.
- Upload malware, execute scripts against the Service, or use it to distribute spam or unsolicited messages.
- Probe, scan, reverse engineer, or attempt to disrupt, overload, or test the security of the Service or its infrastructure, except as expressly permitted by a published responsible-disclosure policy.
- Circumvent billing, rate limits, free-plan limits, the per-tier capacity limits in Schedule A, the API limits in §10, or any other access control — or use automated means to create accounts.
- Interfere with another user's lawful use of the Service, or use the Service to interfere with any third-party service.
- Resell, sublicense, or provide the Service to third parties without our prior written consent.
- Use the Service to train machine-learning models, scrape other users' data, or build a competing product.
- Use the Service in violation of applicable export-control or sanctions laws (including those administered by OFAC, the European Union, and the United Kingdom), or make it available to persons or entities subject to such restrictions.
- Use the Service in life-critical, life-supporting, medical, aviation, nuclear, or other safety-critical contexts where failure of the Service could lead to death, personal injury, or environmental damage. The Service is not designed, built, or warranted for such use.
We may investigate suspected violations and cooperate with law-enforcement requests as required by law. Repeated or material breach of this section is grounds for suspension or termination under §14.
9. Free plan
Every account can keep up to 10 notes free, indefinitely — no trial clock, no card required. When you reach the cap, an active subscription is required to create additional notes. Reading, editing, and exporting your existing notes remain available on any account, and deleting a note frees its slot. Subscription tiers (Paid, Dev, Dev-pro) raise this and other caps; the full breakdown is in Schedule A at the end of this document.
10. API access and tokens
Paid tiers expose a JSON API documented at /docs. Access is authenticated with bearer tokens you generate from your profile. The number of active tokens you can hold per account, the per-token rate limits, and the request and payload size limits are set out in Schedule A.
- Tokens are credentials. Treat them like passwords: do not share them, embed them in client-side code, or commit them to public repositories. Anyone in possession of a token can act as your account up to the API's rate and capacity limits.
- You are responsible for traffic. Every request authenticated by your token counts against your account's limits, applies to your stored content, and is your responsibility — whether issued by you, by an integration you authorized, or by a third party who obtained your token.
- Revocation. You can revoke any token from your profile at any time. We may also revoke a token (or all tokens for an account) on reasonable notice if its use threatens the integrity, security, or availability of the Service, or appears to be circumventing rate or capacity limits.
- Idempotent retries. The API accepts an
Idempotency-Keyheader on mutating requests so that retries are safely no-op replays. Replays that present the same key but a conflicting body are rejected; otherwise idempotency is opt-in and writes without the header proceed normally. - Real-time browser sync. See §16 for the deliberate limit on browser propagation of API writes to open editor tabs.
- Deprecation. If we remove or materially change an API endpoint, we will give at least 30 days' notice through the Service or by email to the address on the account.
11. Subscriptions and billing
We offer a single annual plan in three paid tiers (Paid, Dev, Dev-pro). Payment is handled by our payment processor, Lemon Squeezy, which is also the merchant of record for your purchase. Their terms and privacy policy apply to the payment relationship in addition to ours.
- Prices, currencies, and applicable taxes or VAT are shown at checkout. You authorize recurring charges for the plan you select.
- Subscriptions renew automatically at the end of each billing period until you cancel.
- We do not see or store your full card number. Lemon Squeezy returns only a customer and subscription identifier to us.
- If a charge fails, we may retry it, suspend paid features until payment is received, and, after reasonable notice, downgrade or close the account. Notes you have already created remain readable and exportable in line with §15.
- Receipts and renewal reminders are sent to the email address on your account as transactional notices under §3.
12. Cancellation, refunds, and plan changes
You can cancel your subscription at any time from the billing portal. Cancellation stops the next renewal and takes effect at the end of your current annual term. We do not refund the unused portion of an annual term.
Except where refunds are required by applicable consumer-protection law (including the statutory rights described in §20), all fees are non-refundable. We may offer refunds at our discretion.
You can change your tier at any time from the billing portal; an upgrade takes effect immediately, a downgrade takes effect at the end of the current billing period. If a downgrade would put you above the new tier's caps in Schedule A, we will not delete content — you will be in read-only mode for new writes in the affected category until you reduce usage below the new cap or upgrade again.
We may change pricing, plan features, or plan availability for future billing periods with at least 30 days' notice; the new price applies on your next renewal. Mid-term price changes do not apply to a billing period you have already paid for.
13. Third-party services
The Service relies on third parties to operate, including the payment processor described above, a transactional email provider, and a cloud hosting and database provider. We are not responsible for the content, policies, or practices of third-party services, and your use of them is governed by their own terms. Our handling of personal data by these sub-processors is described in the Privacy Policy.
14. Suspension and termination
You may close your account at any time from your profile page, or by emailing privacy@example.com from the address on your account. Closing your account cancels any active subscription as of the end of the current billing period.
We may suspend or terminate your account, remove content, or restrict features if you violate these Terms (in particular §8), if your account poses a security, legal, or abuse risk to the Service or to other users, if a payment fails and is not cured after notice (see §11), or if we are required to do so by law. Where the issue can reasonably be remedied, we'll try to give you notice and a chance to correct it first. Where it cannot — for example, an active security or legal threat — we may act first and notify you afterwards.
A suspension is not a deletion: while your account is suspended you may still be able to sign in to retrieve a full export under §15, unless the suspension is for active abuse or a legal hold. If we terminate your account, we will tell you the reason at the time of action unless doing so is unsafe or prohibited by law.
15. Your data after termination
Before closing your account, you can request a full export of your notes at any time from Options → Download all. Exports are produced asynchronously: when you request one, we build the archive in the background and email a one-time download link to the address on your account. The link is valid for 24 hours; after that, the file is automatically removed from our servers and you can request a fresh export. You consent to receive these transactional emails as part of using the export feature (see §3).
After your account is closed, your notes are deleted from our production database; copies may remain in encrypted backups until they expire on our normal backup rotation. We retain the minimum billing and log records required to meet legal, tax, and accounting obligations, and aggregated, non-identifying analytics about Service usage. Specific retention periods are set out in the Privacy Policy.
16. Service changes and availability
We may add, change, or remove features, and we may release new versions of the Service, at any time. We aim for high availability but do not guarantee that the Service will be uninterrupted, error-free, or secure against every threat. Maintenance, upgrades, or factors beyond our reasonable control may cause temporary unavailability. We do not offer a contractual service-level agreement; planned maintenance windows, where they affect availability, will be announced through the Service or by email where reasonably practicable.
Real-time browser propagation of API writes is limited to append-only notes. If you have a note open in the web UI while another client (e.g. a script using your API token) writes to it, the browser tab is updated in place only for notes that are append-only — those use a per-user, per-note streaming channel that replaces the body as new content lands. Editable (CRUD) notes updated through the API are not pushed to an open browser tab; the tab will continue to show the previous content until the page is refreshed. This is a deliberate design choice to avoid clobbering in-flight, autosaved edits in the browser editor.
17. Your own backups
We take reasonable steps to keep your notes safe, including regular encrypted backups. Even so, the only way to be sure you have an offline copy of your notes is to export them yourself. Because exports are delivered via a time-limited email link (see §15), please save the resulting archive locally before the 24-hour link expires. If anything you write is irreplaceable, please request and save an export periodically.
18. Intellectual property
The Service, including its software, design, trademarks, logos, and text (other than Your Content), is owned by us or our licensors and is protected by intellectual-property laws. We grant you a limited, non-exclusive, non-transferable, revocable license to use the Service for its intended purpose under these Terms. The corresponding end-user licence and its restrictions are set out in full in the End-User License Agreement; in case of conflict between this section and the EULA on a licence-scope question, the EULA controls (see §26). No other rights are granted by implication, estoppel, or otherwise.
19. Copyright complaints (DMCA)
We respect copyright. If you believe content stored on the Service infringes your copyright, send a notice to privacy@example.com with the subject line DMCA Notice, and include:
- Your physical or electronic signature.
- Identification of the copyrighted work you claim has been infringed.
- Identification of the allegedly infringing material and a link or description sufficient for us to locate it.
- Your contact information (address, telephone number, email).
- A statement that you have a good-faith belief that the use is not authorized by the copyright owner, its agent, or the law.
- A statement, under penalty of perjury, that the information in the notice is accurate and that you are the owner or authorized to act on behalf of the owner.
We may remove or disable access to allegedly infringing material and terminate the accounts of repeat infringers. If you believe your content was removed in error, you may send a counter-notice to the same address. Bad-faith notices may result in liability for damages under applicable law. Outside the United States, we follow equivalent notice-and-takedown procedures where available and respond to lawful takedown requests under the law of the requesting jurisdiction.
20. Consumer rights (EU / UK)
If you are a consumer in the European Union, the United Kingdom, or another jurisdiction with mandatory consumer-protection laws, nothing in these Terms limits rights you cannot waive by contract. In particular:
- Right of withdrawal. You have a statutory right to withdraw from a paid subscription within 14 days of purchase without giving a reason. Because MyNotes is a digital service supplied immediately, we ask at checkout that you consent to performance beginning before the withdrawal period ends and acknowledge that you will lose the right of withdrawal once performance has started and you have benefited from the Service. Where the right still applies, contact support@example.com within 14 days of your purchase and we will refund you in line with applicable law.
- Statutory warranties. The disclaimers in §22 and the liability cap in §23 apply only to the extent permitted by law. Statutory warranties of conformity, satisfactory quality, and fitness for purpose apply where required.
- Forum. Consumers may bring proceedings in the courts of their country of residence where applicable law so provides, and may rely on mandatory provisions of the law of that country.
- Online dispute resolution. EU consumers may also use the European Commission's Online Dispute Resolution platform. We are not, however, obliged to participate in ODR proceedings before a consumer arbitration body.
21. Indemnification
You will defend, indemnify, and hold us harmless against claims, losses, and costs (including reasonable legal fees) arising from (a) Your Content, (b) your use of the Service in breach of these Terms, (c) your violation of law or of any third-party rights, or (d) misuse of an API token issued from your account (see §10). We may assume the exclusive defense of any matter subject to this section, in which case you will cooperate with us. This section does not apply to consumers to the extent prohibited by applicable law.
22. Disclaimers
To the fullest extent permitted by law, the Service is provided "as is" and "as available", without warranties of any kind, whether express, implied, or statutory — including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and uninterrupted or error-free operation. We do not warrant that the Service will meet your requirements, that any defects will be corrected, or that data you store will not be lost or corrupted. Some jurisdictions do not allow the exclusion of certain warranties; in those jurisdictions, the above exclusions apply to the extent permitted.
23. Limitation of liability
To the fullest extent permitted by law, in no event will we, our officers, employees, or contractors be liable for any indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost revenues, lost data, loss of goodwill, or business interruption, whether based on contract, tort (including negligence), statute, or any other legal theory, even if we have been advised of the possibility of such damages.
Our aggregate liability arising out of or related to the Service or these Terms, across all claims combined, will not exceed the greater of (a) the amounts you paid us for the Service in the twelve months preceding the event giving rise to the liability, or (b) USD 100. Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law (for example, liability for fraud, gross negligence, death, or personal injury caused by our negligence, or — for EU/UK consumers — liability that cannot be excluded under mandatory consumer law; see §20). Each provision of this section is severable: if one carve-out is held unenforceable, the remainder of the cap continues to apply.
24. Changes to these Terms
We may update these Terms from time to time. Each version has an identifier shown at the top of
this page (driven by the CURRENT_TERMS_VERSION
constant in the application). If changes are material — for example, a change to fees, to the
licence in §6, to the limits in Schedule A in a way that materially reduces what your tier
receives, or to the dispute-resolution mechanics in §25 — we'll notify you by email or through
the Service at least 14 days before they take effect, unless a shorter period is needed for
legal or security reasons.
Non-material changes (typographical fixes, clarifications, reorganization that doesn't change rights or obligations) take effect on publication. Your continued use of the Service after the effective date means you accept the updated Terms. If you don't agree, you may close your account before the new Terms take effect, and §15 governs the export of your data.
25. Governing law and disputes
These Terms are governed by the laws of [Your jurisdiction], without regard to conflict-of-laws rules. The courts of [Your jurisdiction] have exclusive jurisdiction over any dispute arising out of or in connection with these Terms, subject to the consumer-forum rule in §20. Before filing a formal claim, please contact us at support@example.com so we can try to resolve the issue informally; we will work in good faith to respond within 30 days.
26. General
- Entire agreement. These Terms, the Schedule A incorporated by reference, the Privacy Policy, and the End-User License Agreement are the entire agreement between you and us about the Service and supersede any prior agreement on the same subject.
- Order of precedence. If there is a conflict between (a) the figures in Schedule A and explanatory text in these Terms, the figures in Schedule A control; (b) these Terms and the EULA, the EULA controls for matters within its scope (licence grant, permitted use, restrictions); (c) these Terms and the Privacy Policy, the Privacy Policy controls for matters within its scope (personal-data handling). In all other cases these Terms control.
- Survival. Sections 6 (your content licence to us), 7 (feedback), 18 (intellectual property), 19 (DMCA), 21 (indemnification), 22 (disclaimers), 23 (liability cap), 25 (governing law), and this §26 survive termination of these Terms to the extent necessary to give effect to their purpose.
- Severability. If any provision is held unenforceable, the rest of the Terms remain in force, and the unenforceable provision will be modified to the minimum extent necessary to be enforceable while preserving its intent.
- No waiver. Our failure to enforce a right is not a waiver of that right, and a waiver on one occasion does not waive any other right or future enforcement.
- Assignment. You may not assign these Terms without our written consent, and any attempted assignment is void. We may assign them in connection with a merger, acquisition, reorganization, or sale of all or substantially all of our assets.
- Notices. We may send notices to the email address on your account; you may send notices to support@example.com. Notices are deemed delivered when sent to the address on file.
- Force majeure. We are not liable for delays or failures caused by events beyond our reasonable control, including network outages, denial-of-service attacks, third-party-provider failures, natural disasters, war, civil unrest, or government action.
- No agency. These Terms do not create any partnership, agency, joint venture, fiduciary, or employment relationship.
- Headings. Section headings are for convenience only and do not affect interpretation.
- Language. The English-language version of these Terms is the controlling version. Translations are provided for convenience only.
27. Contact
Questions about these Terms? Email support@example.com. Privacy and data-deletion requests go to privacy@example.com. DMCA notices use the same privacy address with the subject line described in §19.
We aim to respond to email enquiries as soon as we reasonably can, but we do not commit to any specific response time and are under no obligation to reply to every message. Time-sensitive issues — for example a withdrawal request under §20, a billing dispute, a DMCA notice, or a privacy / data-deletion request — are prioritized; general feedback and feature requests may go unanswered. Nothing in this section limits any right you have under mandatory consumer-protection law.
Schedule A — Service limits
Incorporated into these Terms by reference (see §4, §8, and §10). The same canonical reference is also published at /limits and forms Schedule A of the End-User License Agreement; all three surfaces render from the same source so the values cannot drift from what the application actually enforces.
1. Account
- Minimum age: 16 years.
- Password: 8–128 characters, must include at least one uppercase letter, one lowercase letter, one digit, and one special character (
!@#$%^&*()<>?"{}[]). - Profile name: up to 80 characters. Bio: up to 500 characters.
- Disposable / throwaway email domains are not accepted at signup.
2. Notes per account, by tier
Free and Paid use a single shared cap for both note formats. Dev and Dev-pro split the cap by format (rich-text vs plain-text) so a writer who fills their plain quota doesn't lose access to rich-text notes.
| Tier | Rich notes | Plain notes | Storage | API access | Active API tokens |
|---|---|---|---|---|---|
| Free | shared 10 | no per-account cap | no | 0 | |
| Paid | shared 1,000 | no per-account cap | no | 0 | |
| Dev | 1,000 | 10,000 | 15 GB | yes | 1 |
| Dev-pro | 1,000 | 30,000 | 30 GB | yes | 10 |
Deleting a note frees its slot — the cap counts active notes, not lifetime creations. A user whose subscription has lapsed enters read-only mode: existing notes remain readable and exportable forever, but new writes are blocked until they resubscribe.
3. Per-note size limits
- Title: up to 200 characters; control characters (CR/LF, NUL, etc.) are stripped on save.
- Rich-text body, plain-text projection: 1 MB on every tier.
- Rich-text body, raw HTML: 2 MB (defence against markup-inflation as a storage bypass).
-
Plain-text note body:
- Free / Paid: 1 MB per note.
- Dev: 1.5 MB per note.
- Dev-pro: 3 MB per note.
- Note format is immutable after creation — a rich note cannot become a plain note (or vice versa) without delete-and-recreate.
4. Per-note version history
- Up to 5 snapshots are kept per note. When a newer save lands beyond the cap, the oldest snapshot is permanently deleted.
- Capture is debounced. Saves within ~10 minutes of each other share a single snapshot, so a burst of autosaves doesn't burn through the 5-snapshot window inside one editing session.
- Append-only notes do not generate snapshots — appends are additive, not destructive, so there is nothing to roll back to.
- Snapshots are accessed via the History link on any editable note and can be restored with one click. The restore captures your current content as a fresh snapshot first, so it is itself reversible within the same 5-snapshot window.
5. Folders
- Up to 100 folders per account (one is seeded as "My First Folder" at signup).
- Folder name: up to 80 characters; folder names must be unique within an account (case-insensitive).
6. API (Dev and Dev-pro tiers)
Per-token, per-minute. Each request consumes one slot in the matching bucket; X-RateLimit-* headers on every successful response let clients pace themselves before they trip a 429.
| Bucket | Dev | Dev-pro | Counts |
|---|---|---|---|
| Reads | 600/min | 2,000/min | GET, HEAD on /api/v1/* |
| Writes | 60/min | 200/min | POST/PATCH/PUT/DELETE on /api/v1/* (excluding append + bulk) |
| Appends | 300/min | 1,000/min | POST /api/v1/notes/:id/append and the by-filename variant |
- API creates and updates are plain-text only; rich-text notes belong to the browser/Trix flow.
- Bulk endpoint (Dev-pro only): up to 50 notes per call. Counts as one event against the writes bucket regardless of the batch size.
- Pagination: 50 per page by default, up to 200 via
?limit=N. - Stream-addressed filename: up to 200 bytes; no slashes, no control or invisible characters.
- API tokens: default expiry of 90 days when no expiry is set; user-set expiry can be at most 1 year from now. Tokens revoked manually, or automatically when the account loses API access.
- Anonymous / bad-token requests on
/api/v1/*: 60/min/IP. - Request body: oversized writes (over 3 MB for API, 2 MB for browser) are rejected at the HTTP boundary before parsing.
7. Browser-surface rate limits
Designed for legitimate human pacing. Authenticated limits key off the user; anonymous limits key off the IP. 429 rate_limited responses include a Retry-After header so clients can back off cleanly.
- Sign-in: 10/min/IP, 5/20 min per email.
- Sign-up: 5/hour/IP.
- Password reset: 5/hour/IP, 5/hour per email.
- Confirmation resend: 5/hour/IP, 5/hour per email.
- Account email change: 3/day per account, 3/day per target email — protects unrelated mailboxes from being used as a confirmation-spam target.
- Other account updates (name / bio): 10/hour per account.
- Note saves / autosave: 30/min per account.
- Per-note PDF / DOCX / TXT downloads: 10/min per account.
- Full-account export: 2/hour per account; the archive is built in the background and the download link is emailed to you (see §7).
- Billing portal / plan-change: 5/min per account.
- Health probe (
/up/deep): 60/min/IP. - Webhook deliveries (
/webhooks/lemon_squeezy): 100/min/IP.
8. Full-account export
- Triggered from Options → Download all; archive is built off-request by a background worker.
- A one-time download link is emailed to the address on your account when the archive is ready (usually a few minutes).
- The link is valid for 24 hours from the moment the build completes; after that the file is removed from our servers and you'll need to request a fresh export.
- The link only works while signed in to your own account, so a forwarded email cannot be used by anyone else to download your notes.
- The archive contains
.txt,.docx, and.pdfrenderings of every rich-text note (or.txtonly in software-development mode).
9. Inbound webhooks
- Lemon Squeezy webhooks only; no public webhook surface for end users.
- HMAC-SHA256 signature verification on
X-Signature; unsigned or tampered payloads are rejected with 401 before parsing. - Payload cap: 1 MB. Real LS payloads are well under 10 KB; oversized requests are dropped at the HTTP boundary.
- Replays of an already-applied delivery are acknowledged with 200 but produce no side effects (signature uniqueness is enforced by a database index).