Notebook · Last updated September 30, 2026
Privacy policy
Notebook is operated by Bryant Hargreaves. For privacy questions or requests, contact help@openrtc.app. This policy covers Notebook at notebook.openrtc.app and its desktop and mobile versions.
What stays on your device
You can write, draw, and run local Python without an account. Notebook documents, code, saved outputs, and thumbnail previews are stored on your device. Browser storage holds local notebooks and preferences; the desktop app also stores its local Python notebooks and runtime files. Exported notebook files remain wherever you save or send them.
Signing in
When you sign in with Google, Google provides basic identity information to Clerk, our authentication provider. This may include your Google account identifier, name, email address, and profile image. Notebook uses the resulting account identity to sign you in, connect your own devices, authorize sharing, and protect access to OpenRTC capabilities. Notebook does not request access to your Google Drive, Gmail, or other Google content. Clerk manages sign-in sessions and related browser cookies or storage.
Notebook's identity service, hosted on Cloudflare, verifies your Clerk session. For native sign-in it stores short-lived sign-in codes and device session token hashes with your account identifier in Cloudflare D1. It also issues short-lived signed identity assertions and sharing authorizations. It does not store notebook documents, images, or code outputs.
Sharing and Python execution
Sharing sends notebook updates directly among authorized participants through OpenRTC. OpenRTC processes the identity, ticket, connection, and usage data needed to admit and route peers. Notebook content is not stored by the Notebook identity service or Clerk. An invitation contains access material in its URL fragment; anyone who receives a valid invitation may join while its capability remains open. Participants can retain their own local copies of shared content.
When a desktop host shares Python, invited participants can run code in that notebook's isolated Jupyter session. Code, inputs, outputs, and imported read-only file copies can therefore be visible to or affected by participants in that shared session. A guest's code may also initiate network requests permitted by the runtime. Locally rendered external media or embeds may contact their providers when opened.
Approved resource downloads
When you approve an external resource download, Notebook requests that URL and caches the downloaded file on your device for that notebook. Remembered permissions are also stored on your device. Desktop downloads go directly from your device to the resource provider. Browser and mobile Python downloads pass through Notebook's Cloudflare-hosted resource broker so sources do not need to support browser cross-origin requests. The broker receives the requested URL and streams the response; it does not receive your notebook document or sign-in credentials. It stores a hash of your IP address with temporary request and byte counters for abuse prevention, removing daily counters older than two days when new requests are processed. You can revoke remembered permissions and remove cached resources in Notebook settings. Copies already supplied to Python remain in its workspace until removed there.
How information is used and retained
Identity and connection data are used to authenticate users, provide device connections and sharing, prevent unauthorized access, operate the service, and diagnose failures. Hosting and connectivity providers may also process technical request data, including IP addresses. Local content remains until you remove it from that device, subject to browser or operating-system storage behavior. Deleting a local notebook does not delete another participant's copy. Native sign-in codes expire after five minutes; native session tokens expire after 30 days or can be invalidated by signing out. Expiration of a token does not by itself state when its database record is purged. Clerk and OpenRTC maintain their own service records under their respective policies.
Your choices
You may use local Notebook features without signing in. You can stop sharing, sign out, delete notebooks from this device, and export a copy. If you shared a notebook, ask recipients to delete their copies separately. For account or privacy requests, contact help@openrtc.app.
Service providers and changes
Notebook uses Google for optional sign-in, Clerk for authentication, Cloudflare for the website and identity service, and OpenRTC for peer connectivity. The app may also fetch release information from GitHub. We will update this page when material data practices change.