Privacy Policy

Last updated 19 August 2026

PentNotes (“we”, “us”) is a note-taking workspace for penetration testers. This page explains what data we collect when you use it, how it's stored, and what we do — and don't do — with it.

What we collect

Creating an account and using PentNotes involves the following data:

  • Your email address, used for sign-in (password, or magic link).
  • The content you create — engagement names, notes, network map data, host records, and any files you upload as evidence.
  • Standard authentication cookies used to keep you signed in. We don't use cookies for advertising or cross-site tracking.

We don't run analytics or advertising trackers on this site.

How it's stored

Account and engagement data is stored in a hosted Postgres database and file storage bucket, scoped to your account with row-level security — other users cannot query or read your data through the application. Uploaded evidence files are stored in the same infrastructure, isolated per account.

What we don't do

  • We don't sell your data.
  • We don't share your data with third parties for marketing purposes.
  • We don't use your engagement content to train AI or machine-learning models.

Deleting your data

You can delete individual engagements, files, and notes directly in the app at any time. To delete your account and all associated data, contact us at [your support/contact email].

Changes to this policy

If this policy changes in a way that affects how your data is handled, we'll update the date at the top of this page.

Contact

Questions about this policy or your data can be sent to [your support/contact email].