Back to home

Terms of Service

Last revised — 19 September 2026

The agreement between you and TwoNote: what you can expect from the service, what it expects from you, and what happens when something goes wrong.

1. This agreement

These terms govern your use of TwoNote. By creating an account you accept them. If you do not accept them, do not create an account — the application runs locally without one, and nothing obliges you to sync.

You must be at least 15 years old to create an account. Below that age, French law requires a parent or guardian to consent on your behalf.

2. Your password and your recovery code

Read this one before anything else. TwoNote encrypts your notes with a key derived from your password, and we do not hold that key. We cannot reset your password and we cannot recover your notes on your behalf. When you create an account we show you a recovery code, once. It is the only thing that can decrypt your notes if you forget your password, we cannot regenerate it, and we cannot read it. Lose both, and your notes are permanently unreadable — by us as much as by you.

Adding an email address is optional and does not replace the recovery code: it only lets us send you a recovery link, which still requires the code to complete. Export your notes regularly. The application does it in a few clicks, and it is the only real protection against losing your own key.

You are responsible for keeping your credentials to yourself, and for what happens under your account.

If your account was created by an organisation, this section works differently: your organisation may sign you in through its own identity provider, may hold a copy of your key, and may suspend or delete your account. The Privacy Policy, section 5, sets out what that entails. The rest of these terms still binds you personally.

3. Accounts administered by an organisation

When an organisation opens an account for you, it becomes the party that decides how that account is used: who administers it, through which identity provider you sign in, whether it holds a key that opens your notes, and which AI endpoint you may use. We provide the service; the organisation sets its rules.

Anything you keep on such an account may be read by your organisation — including what is personal. Keep personal material on a personal account.

It falls to the organisation, not to us, to inform its members of what it has put in place, and to meet the obligations that come with it where it is their employer. We cannot answer for what an organisation does with a key it holds, and we cannot recover notes on its behalf or yours.

If the organisation removes you from it, your account and its contents remain yours, but an account created without a password can no longer be opened without the organisation’s identity provider. Ask the organisation to delete the copy of your key it holds: only it can.

4. What you may not do with it

Because we cannot read your notes, what you keep privately is between you and the law. What follows applies with full force the moment you make something reachable by someone else — through a share link, a collaborative session, an invitation, or a widget published to the store.

You may not use TwoNote to store, publish or distribute:

  • content depicting the sexual abuse or exploitation of minors;
  • content that incites terrorism, hatred, violence or discrimination, or that denies crimes against humanity;
  • content that harasses, threatens, defames a person, or publishes their private information without consent;
  • works you have no right to distribute, counterfeit goods, or stolen credentials and personal data;
  • malware, phishing pages, or anything built to compromise other people’s systems;
  • unsolicited bulk messaging, or content whose purpose is to drive traffic to any of the above.

Nor may you use the service as a general-purpose file distribution network, run automated processes that degrade it for others, attempt to circumvent storage quotas or rate limits, or probe our systems without our written agreement. Security research is welcome — write to us first, at the address below, and we will not treat you as an attacker.

5. Sharing, and what it makes you responsible for

When you create a share link, you are the one publishing that content, and you answer for it. We record the date and the network address from which the link was created — see the Privacy Policy for how long and why.

A link that allows editing by anyone deserves particular care. Visitors without an account can then write into your document, and files they upload are recorded against your account and count against your storage. You remain the person we can identify. If that is not what you want, share with named accounts, or share read-only.

You can revoke any link at any time from the application, and revocation takes effect immediately, including for sessions already open.

6. The widget store

The store is where people publish small programs — widgets — for other people to install. It is the one public part of TwoNote, and it has two sides: publishing, and installing what someone else published.

Publishing. You publish under your TwoNote username, which is shown in the clear and cannot be replaced by a pseudonym — the point of the store is that an author can be recognised from one version to the next. You are asked to agree to that before anything is sent. What you publish is signed with a key held only by you, and our server adds its own attestation of what it received and when; both are checked again on the installing device. You may publish only what you have the right to publish, and everything in section 3 applies to it, malware most of all. You keep three widgets online at a time on the free plan; withdrawing one frees a place, and maintaining a widget you already published is never limited.

You keep every right over the widget you wrote. Publishing grants us only what distributing it requires: storing it, showing it in the catalogue, and serving it to whoever installs it, for as long as it is published. It also grants anyone with an account a non-exclusive right to install the widget and run it for their own use — without which the store would be handing out code nobody had the right to run. You grant nothing beyond that: no right to modify it, and none to redistribute it. Withdrawing it ends that, for the catalogue and for new installs, and closing your account erases it from our side altogether. Neither can reach the copies already installed, which belong to the people who installed them.

Installing. A widget is someone else's code, running in your browser. We do not write it, we do not audit it, and a verified badge means a human looked at it — not that it is safe. Before installing, you are shown the permissions it asks for, and the application checks the code against them and tells you where they disagree. Grant them only if the widget has an obvious reason to need them. This is the one place in TwoNote where what you run comes from a stranger, and it is your decision.

Moderation. Anyone with an account can report a widget from the store itself, giving a reason. Enough open reports hide a widget automatically, pending review. We can mark a widget as verified, and we can remove one — for a breach of section 3, for a report we uphold, or where the law requires it. A removal is explained to its author, who can contest it by writing to us. We moderate what is published in the store; we do not moderate widgets you write for yourself, which are notes like any other and which we cannot read.

7. Reporting content, and what we do about it

Anyone can report content reachable through TwoNote, with or without an account, using the contact form or by writing to contact@twonote.ink. Send us the share link and tell us what is wrong with it. We record the date your report arrives; that date is what our response time is measured against.

What we can do is act on access, not on content: we can revoke a share link, remove a widget from the store, and suspend the account behind either. We cannot edit, redact or inspect notes that have not been shared, because they are encrypted and we have no key — a published widget is the exception, since it reaches us in the clear. A report about something we cannot reach will be answered honestly to that effect.

If we act against your content or your account, we tell you what we did and why, at the address attached to your account if you gave us one. You can contest it by replying, and we will look again.

8. Suspension and closing an account

We may revoke a share link, remove a widget from the store, or suspend an account, where section 3 has been breached or where we are required to by law. A suspension cuts access and revokes the links the account had published; it deletes nothing, and it can be lifted. Where the breach is minor or accidental, we will normally revoke the link or take the widget down and write to you before going further.

You may close your account whenever you like, from the settings. Doing so erases your data from our database and our object storage, and takes down anything you published to the store. Because we cannot read what we hold, we cannot restore it afterwards — export first if you want to keep anything.

9. What it costs

The service is currently free, with the storage allowance shown on the home page, and no payment is taken. Paid plans are described there but are not open: no payment method is collected and no charge can occur under these terms. When they open, separate terms of sale will set out prices, billing, renewal, cancellation and your right to withdraw, and you will be asked to accept them before anything is charged.

10. Who owns what

Your notes are yours. We claim no right over them, and we could not exercise one if we did — we cannot read them. You grant us only what running the service requires: storing the encrypted bytes and transmitting them between your devices and the people you share with.

The TwoNote name, its interface and its source code are ours. The source is not public: it is held in a private repository, and no right to use, modify, redistribute it or run an instance of it is granted — it is not open-source software. What your browser runs, it can still show you: the code served to your device is readable from that device, which is what lets anyone check the encryption claims made here.

The full terms are published on the licences page at /license, together with the free components the application ships — which remain under their own licences, and which nothing here restricts.

11. Availability and responsibility

TwoNote is provided as it stands, by one person, without a guarantee of uninterrupted service. We may change or discontinue features, and we will give notice where a change would lose you something.

We answer for our own faults, on the terms the law provides, and nothing here removes a right the law gives you as a consumer. Two limits follow from the design rather than from a wish to disclaim: we cannot be held responsible for notes that become unreadable because you lost both your password and your recovery code, since no action of ours could have prevented or repaired it; and we cannot be held responsible for a local copy lost when you clear your browser data. Both are the reason the application exports your notes in a few clicks, and the reason we keep saying so.

12. Changes to these terms

We may change these terms. If a change matters to you — anything touching your obligations, your content, or the continuation of the service — we will tell you in the application at least thirty days before it takes effect, and you are free to close your account in the meantime rather than accept it. Corrections that change no obligation take effect when published, with the date at the top updated.

13. Applicable law

French law applies. If something goes wrong, write to us first at contact@twonote.ink — most things are settled that way. If they are not, and you are a consumer, you may bring the matter before the courts of your place of residence.