Skip to content
Sanctuary Reader
HomeTools
PT EN
Open document

Privacy

Privacy Policy

Sanctuary Reader was built to process Markdown documents inside the browser. This policy explains what stays on your device, when external services are contacted, and how to remove the application's local data.

Last updated: June 11, 2026

The short version

Documents opened from a local file or pasted as text are processed in the browser itself. Document content, notes and drafts are not sent to any Sanctuary Reader database.

Depending on the flow you use, the browser may keep a local copy of the current document so you can continue between Reader and Editor, and recover after a reload, an accidentally closed tab, or a resumed editing session.

Remote resources embedded in the Markdown, such as external images referenced by URL, are blocked by default in the reader and in the preview. That reduces automatic calls to third parties when you open local files or paste text.

The site uses Google Analytics 4 for audience measurement, but only if you allow it through the cookie banner. Without your consent the script is not loaded and no measurement cookie is created. You can review or withdraw that choice at any time through the "Cookie settings" link in the footer.

Controller and data protection officer

The controller of the data processed directly by Sanctuary Reader, under Art. 5, VI of the Brazilian General Data Protection Law (LGPD), is Nykel Andersow, the natural person responsible for operating the project in Brazil.

Under Art. 41 of the LGPD, Nykel Andersow also acts as the data protection officer. The contact channel for privacy, data protection and data subject requests is sanctuaryreader.team@gmail.com.

Data processed in the browser

The application may save the following locally, in your own browser:

  • the current document and its title in sessionStorage while reading, editing and moving between screens;
  • a recovery copy of the current document and title in localStorage when you use the live editor or return to the reader after editing;
  • editor drafts kept for recovery in localStorage;
  • interface preferences such as font, layout, language and the guided study panel;
  • notes, cards, pen colour, card ruling and guided study progress;
  • text written during the guided study phases, including recall written from memory, the judgement of your predictions, and the time spent in each section;
  • the spaced repetition schedule of each annotated section, with dates and a history of correct answers;
  • closing notes and local study state tied to the open document;
  • local estimates of storage usage, shown in the reader's About panel.

This data uses keys starting with sanctuary: and stays on the device until the session ends, until you clear the browser's data, or until the application offers a clearing action.

If the document you open contains personal or sensitive data, that content may also be stored locally in the browser on your device. Avoid opening confidential documents on public or shared computers, or on machines you do not control.

To reduce unnecessary retention, Sanctuary Reader automatically removes its own local data after 180 days without activity in this browser.

Loading a document by URL

When you provide a public Markdown URL, the browser makes a direct request to the remote origin. That external origin may receive the technical data normal to any web request, such as IP address and user agent, according to its own rules.

Sanctuary Reader does not send the URL of the loaded document to Google Analytics: the document travels between screens through the browser's local storage and never appears in the address of the measured pages. URL loading requests use a no-referrer policy and send no Sanctuary Reader credentials to the remote origin. The origin you reach may still log the request according to its own practices.

Analytics and tracking

Sanctuary Reader uses Google Analytics 4 to understand how the site is used (pages visited, traffic source, device type). It is activated only after your explicit consent in the cookie banner, on the basis of Art. 7, I of the LGPD. Until you decide, or if you decline, the Google script is not loaded and no measurement cookie is created — browsing works normally without consent.

When allowed, Google Analytics creates the following cookies:

  • _ga — distinguishes visitors in a pseudonymised way; valid for up to 2 years;
  • _ga_<ID> — keeps the measurement session state; valid for up to 2 years.

The configuration applied minimises processing: Google Signals and ad personalisation are disabled, there are no advertising cookies, and Google Analytics 4 does not log or store full IP addresses. Measurement data is pseudonymised and used only in aggregate, to improve the site.

You can withdraw consent at any time through the "Cookie settings" link in the footer of any page. On withdrawal, measurement stops and the Google Analytics cookies created in this browser are removed. Your choice — accept or decline — is recorded only in your browser, in localStorage, without identifying you.

The processor for this activity is Google (Google LLC, USA, and affiliates), under the privacy policy at policies.google.com/privacy. For details on international transfers, see "Hosting, CDN and international transfer".

External services

Sanctuary Reader self-hosts the typefaces and JavaScript libraries the application uses (for example the libraries for Markdown rendering, syntax highlighting and diagrams). Because of that, the browser makes no calls to external CDNs such as Google Fonts or cdnjs while you use the site.

The exceptions are the optional loading of a Markdown document from a public URL you provide — where the browser talks directly to the remote origin, as described in "Loading a document by URL" — and Google Analytics, loaded only with consent, as described in "Analytics and tracking".

External links inside the content remain clickable, but external resources loaded automatically within the document, such as remote images, are blocked by default to reduce involuntary sharing with third parties.

Hosting, CDN and international transfer

The site is delivered by the following processors, under Art. 5, VII of the LGPD:

  • Amazon Web Services (AWS) — static storage in Amazon S3 and distribution through Amazon CloudFront, with points of presence in the Americas, Europe and other regions. Processor policy: aws.amazon.com/privacy.
  • Google (Google LLC and affiliates) — audience measurement through Google Analytics 4, triggered only with your consent, with processing that may take place in the United States and other countries. Processor policy: policies.google.com/privacy.

Independently of any analytics script, these processors' infrastructure may generate technical access logs. Those logs can include IP address, user agent, the route requested, date, time, and caching or security information. The records serve only to deliver the site, protect the infrastructure, diagnose failures and maintain availability — they are not cross-referenced with other data for profiling or marketing.

Retention of those logs depends on the configuration actually applied in the AWS environment and should be limited to the minimum necessary for delivery, security and diagnosis. If you ask about the operational period currently in force, we will answer based on the configuration of the environment published at that moment.

Delivering the site involves providers that also operate outside Brazil, including the United States. Any international transfers involved in hosting and distributing the site must observe Art. 33 of the LGPD and the applicable ANPD regulation, including ANPD Resolution CD/ANPD No. 19/2024, through the contractual and operational mechanisms appropriate to the environment actually in use. AWS states that it adopts contractual safeguards and security measures compatible with international data operations.

Purposes

The data processed serves the following purposes:

  • opening, rendering, editing and presenting Markdown documents;
  • keeping preferences and the local state of the reading experience;
  • recovering editor drafts where possible;
  • answering messages sent by email.

Legal bases

Depending on the context, processing may rely on the following LGPD bases:

  • performance of the service you requested (Art. 7, V), to open, render, edit and present documents;
  • consent (Art. 7, I), exclusively for audience measurement with Google Analytics — collected freely, informed and unambiguously through the cookie banner, and revocable at any time through the "Cookie settings" link in the footer (Art. 8, §5);
  • the controller's legitimate interest (Art. 7, IX and Art. 10), for technical operation, security, fraud prevention and infrastructure diagnosis — applied only to minimal technical logs, never cross-referenced with other data for profiling;
  • responding to a request you initiate by email, including support and privacy-related requests, based on the context of your demand and, where applicable, on Art. 7, V or the regular exercise of rights.

Retention and deletion

Data in sessionStorage usually lasts until the tab or browser session ends. Data in localStorage may stay longer, until removed by you, by the browser, by an action in the application, or by automatic expiry after 180 days without local activity.

To remove local data, use the "Clear local data" button in the reader's About panel, or clear the site data in your browser for the Sanctuary Reader domain. That removes the sanctuary:* keys saved on the device — including the record of your cookie consent, which will then be requested again.

Google Analytics cookies (_ga and _ga_<ID>) last up to 2 years, but are removed from this browser when you withdraw consent through the "Cookie settings" link in the footer. On Google Analytics servers, event data tied to identifiers is retained for the shortest period the tool offers before aggregation.

Your rights

In line with Art. 18 of the LGPD, you may request at any time: confirmation that processing exists; access to the data; correction of incomplete, inaccurate or outdated data; anonymisation, blocking or deletion of unnecessary or excessive data; portability; deletion of data processed with consent; information about sharing; and withdrawal of consent.

Requests can be sent to sanctuaryreader.team@gmail.com. We answer within 15 calendar days of receiving the request, under Art. 19, §1 of the LGPD. Since most of the data lives only in your browser, many requests can be resolved directly by clearing local data on the device.

Sanctuary Reader makes no automated decisions affecting data subjects, under Art. 20 of the LGPD. There is no profiling, scoring, algorithmic recommendation, or any decision taken solely on the basis of automated processing.

Children and adolescents

Sanctuary Reader is not directed at children (under 12) and does not knowingly collect personal data from children, in observance of Art. 14 of the LGPD. For use by adolescents (between 12 and 18), we recommend the supervision of parents or legal guardians.

If a legal guardian finds that a minor in their care has data processed by the application — including content recorded locally in the browser — and wants to request deletion, they can write to sanctuaryreader.team@gmail.com. Since most of the data lives only on the device, deletion can be carried out immediately through the "Clear local data" action in the reader's About panel.

Security and incidents

The project was built to use HTTPS, sanitisation of rendered HTML, blocking of embedded remote resources by default, a no-referrer policy on remote loads started by the application, and self-hosted JavaScript libraries and fonts. Additional security settings at the CDN edge, such as HSTS and other response headers, depend on the deployment environment and should be verified on each deploy.

In the event of a security incident involving relevant risk or damage to data subjects, we will notify the Brazilian data protection authority (ANPD) and the affected subjects within a reasonable period, under Art. 48 of the LGPD and the applicable ANPD regulation. The notice will include the nature of the affected data, the technical and security measures adopted, the risks related to the incident, and the measures taken to reverse or mitigate its effects.

Changes

This policy may be updated when the product, the external services or the privacy practices change. The update date will be revised on this page.

Sanctuary Reader Free online Markdown editor
HomeMarkdown toolsMarkdown readerAI Markdown viewerMarkdown with MermaidMarkdown from URLPrivacyTermsContact
Sanctuary Reader

Open document

Choose how to load your Markdown document:

error Choose another file, or paste the content instead.

content_paste Paste text

error Paste some Markdown before loading.

link URL
link

info Paste the file link from GitHub or Bitbucket — we convert it to raw for you

privacy_tip The remote source receives your IP and user agent. Sanctuary avoids sending a referrer on this request.

error Check the address, or paste the content instead.

draft

Drop your Markdown or .feature file here

privacy_tipCookies? Only if you want them

We use Google Analytics to understand what works here — but only if you say yes. Prefer to decline? Nothing about your reading changes, and you can revisit the choice any time from the site footer. The details are in the Privacy Policy.