# How does PrivacyNotes handle GDPR and my data rights? Mostly by holding as little as possible. Sign up with a phrase and there is no name, email, or identity on file to request: your data is ciphertext under a random public key, hosted in Zurich, Switzerland. Sign in with Google, Apple, or GitHub and exactly one identifier exists - the email behind that login, linked to that key. Billing details for Pro live with [Paddle](https://www.paddle.com), the merchant of record, not with us. Every right is self-serve and immediate, no request form needed: access and portability are Settings > Import & Export (full export in open formats), erasure is Settings > Account > "Delete account & data..." with no retention window, and rectification is editing your notes. The formal version, including how to reach us for anything the app cannot do itself, lives in the [privacy policy](https://lifetimelabs.dev/privacy/). ## Read the source - SECURITY.md: What we measure -> https://privacynotes.app/docs/security.md (source: https://github.com/LifetimeLabsDev/PrivacyNotes.app/blob/main/SECURITY.md#what-we-measure) --- Source: https://privacynotes.app/help/data-rights