Privacy Policy — markd.ly
Last updated: May 13, 2026 · Effective: May 13, 2026
Bravely Studios LLC (“we,” “our,” or “us”) operates the markd.ly application (the “App”). This Privacy Policy explains how we handle information when you use our App.
Introduction
markd.ly is a native markdown editor for macOS, Windows, iOS, and Android. Your documents stay on your device and are never transmitted to us. We collect a small amount of information to process desktop purchases, verify desktop Pro entitlements, deliver desktop updates, and improve the product. The iPhone and Android apps are free local editors and do not require account creation or license activation.
What We Collect
Document contents never leave your device unless you explicitly export or share them yourself.
For desktop purchases and Pro entitlement: when you buy markd.ly Pro on bravely.dev, we collect your Bravely Account identifier, contact email, and transaction identifier so we can activate the desktop lifetime license on Mac and Windows. Payment card details and billing information are handled exclusively by our merchant-of-record billing provider — we never see or store them. If you buy the Mac App Store build, Apple handles the transaction and we receive only the entitlement state needed to unlock Pro.
For product analytics: the desktop and mobile apps can send aggregate usage events (feature adoption, error rates, session length) so we can improve the editor. Events are keyed by an anonymous device identifier. If you activate a desktop web purchase, desktop entitlement reconciliation may associate events with your Bravely Account so we can troubleshoot license issues. Document contents, file names, folder paths, and text you type into the editor are never sent to analytics.
For automatic updates: the desktop apps periodically fetch an appcast feed from bravely.dev to check for new versions. This request is anonymous and contains only your app version and operating system version.
License Activation & Entitlement Checks
The direct-download Mac and Windows apps can send your email to bravely.dev/api/markdly/activate to confirm a desktop purchase is valid. On launch, those desktop apps may send the same email to bravely.dev/api/markdly/license-status to revalidate — this catches refunds and other entitlement changes. Both requests include only your email and the platform identifier. Your email is used solely to perform the entitlement lookup against our desktop billing systems; no document data, device telemetry, or browsing data is sent. If the desktop app cannot reach our servers, it falls back to a seven-day offline grace period using the locally cached activation state. The iPhone and Android editors do not use these endpoints.
Document Data
Your markdown files, drafts, snippets, and exports are stored locally on your device. markd.ly does not upload or sync your documents to any server. The app accesses only the files and folders you explicitly open. Encrypted documents (Pro) are encrypted with AES-GCM using a passphrase you choose — we cannot recover the passphrase and we never see the plaintext.
What We Do Not Collect
We do not collect any of the following:
• Your document contents, file names, folder paths, or text you type
• Your location
• Your contacts, calendar, or other system data
• Payment card numbers or billing details (handled by the platform that billed you)
• Advertising identifiers (IDFA, GAID)
• Web browsing history from outside the app
Opting Out of Analytics
You can disable product analytics at any time in Settings → Privacy on each platform. When disabled, no analytics events are sent from that device. Desktop license activation, entitlement checks, and update checks are required for desktop Pro and auto-update to function and cannot be disabled while those features are in use; uninstalling the app stops those requests entirely.
Third-Party Services
We share the minimum information required to deliver the product with service providers that handle desktop web payments, app-store purchase handling, desktop entitlement lookup, anonymous product analytics, hosting, downloads, and desktop update delivery. We do not sell your data, and we do not share it for advertising.
Data Retention
Your desktop web-purchase record (Bravely Account identifier, contact email, transaction ID, and entitlement status) is retained for the life of your lifetime purchase so we can honor it on future reinstalls. Analytics events are retained for up to 365 days. You can request deletion of your desktop purchase record or analytics data by emailing support@bravely.dev; we will process the request within 30 days.
Children's Privacy
markd.ly is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Your Privacy Rights
Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live.
• Access — ask what personal data we hold about you and get a copy.
• Correction — ask us to fix data that is wrong or incomplete.
• Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product.
• Portability — ask for your data in a portable, machine-readable format.
• Objection and restriction — ask us to stop or limit certain processing.
• Withdraw consent — where we rely on consent (marketing email, optional analytics), you can withdraw it at any time without affecting processing that already happened.
• Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights.
EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles.
To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.
Legal Basis for Processing
If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR:
• Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support.
• Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding aggregate product usage, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking.
• Consent — marketing email, and optional analytics where a client offers a toggle. You can withdraw consent at any time.
• Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.
International Data Transfers
Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.
California Notice at Collection
For California residents, the categories of personal information we collect for this product are:
• Identifiers — your Bravely Account identifier, email address, and device or installation identifiers.
• Commercial information — records of purchases, subscriptions, entitlements, trials, and refunds.
• Internet or other electronic network activity — aggregate feature-usage events, app version, platform, crash and error reports.
• Coarse geolocation — a country-level signal derived from your network connection, used for consent rules and tax.
• Your content — only the content the product is built to store or sync for you, described in the sections above.
We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract.
We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit. If that ever changes we will update this policy and provide the required opt-out before the practice begins.
Retention is described under "Data Retention" above and, for account-level data, in the Bravely Account privacy policy.
Sub-processors
We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev:
• Cloudflare, Inc. — hosting, the Workers runtime, D1 databases, R2 object storage, and bot protection for bravely.dev and our app subdomains. See cloudflare.com/privacypolicy.
• Google LLC — Firebase Authentication, which backs Bravely Account sign-in (including Sign in with Google). See policies.google.com/privacy.
• Apple Inc. — Sign in with Apple, and App Store purchase and receipt handling for our Apple platform apps. See apple.com/legal/privacy.
• Paddle.com Market Ltd — our merchant of record for purchases made on the web or in our desktop apps. Paddle handles checkout, payment processing, invoicing, and sales tax/VAT. See paddle.com/legal/privacy.
• RevenueCat, Inc. — validates App Store and Google Play receipts and reports subscription lifecycle events so we can unlock what you bought. See revenuecat.com/privacy.
• PostHog Inc. — product analytics for aggregate feature usage and reliability. See posthog.com/privacy.
• Resend Inc. — sends our transactional email (sign-in codes, receipts, password resets, support replies). See resend.com/legal/privacy-policy.
If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.
Security
We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.
How to Contact Us
Bravely Studios LLC
Privacy and data rights: privacy@bravely.dev
Product support: support@bravely.dev
Website: https://bravely.dev
Postal address: available on request to privacy@bravely.dev.