Legal

Privacy policy

Short version: the app collects nothing. The website stores the email you give the waitlist and counts page views without cookies. Purchases are handled by a merchant of record.

Effective 2026-10-01. Data controller: Rohith Katta, India.

1. Who we are

AsItIs Markdown is made by Rohith Katta ("we"), an individual based in India. For privacy questions and grievances, contact privacy@asitis.app; the founder answers personally.

2. The desktop app

The AsItIs desktop app does not collect, transmit or store any personal data. It makes no network connections by default. The complete list of addresses it can contact, and what each sends, is on the Network activity page:

  • Optional update check (off until you turn it on): sends your platform, CPU architecture and app version. No identifier. We see aggregate counts only.
  • Licence resend page: a web page you open in your browser to have your licence emailed again. Your email address is used for that one email and rate limiting.

Your documents never leave your machine through the app. Licence files are verified locally. There is no account.

3. The website (asitis.app)

Waitlist

If you join the waitlist, your email address and the plan you were interested in are stored by Buttondown (Buttondown, LLC, United States) on our behalf. We use it to send you at most a few emails about the beta and releases. Every email has an unsubscribe link, which deletes you from the list. Legal basis (GDPR): consent. Retention: until you unsubscribe or 24 months of inactivity.

Analytics

We use Plausible Analytics (Plausible Insights OU, Estonia, hosted in the EU), which sets no cookies and stores no personal identifiers. It records page URL, referrer, browser type, device type and country, derived from a request that is not stored. We use it to count visits. Legal basis: legitimate interest in knowing whether the site works. No opt-out is needed because no personal data is collected; you can block the script with any content blocker without breaking the site.

Hosting

The site is served by Cloudflare Pages (Cloudflare, Inc., United States, with data centres worldwide). Cloudflare processes IP addresses and request logs to serve and protect the site. We do not have access to individual logs.

Email

If you write to us, we keep the correspondence to answer you and for as long as a support history is useful, at most 3 years.

4. Purchases

Pro and Firm licences are sold by a merchant of record (planned: Paddle.com Market Ltd, United Kingdom), which handles payment, invoicing, tax and refunds under its own privacy policy. We receive your name, email address, country and the licence purchased, and use them to issue the licence file, send it by email (via Resend, Inc., United States), honour refunds and keep the records that tax law requires (for as long as Indian tax law requires, generally up to 8 years). Legal basis: performance of a contract and legal obligation.

5. Data we never collect

Document contents, file names, file paths, what you open, how often you open the app, crash dumps, keystrokes, clipboard, IP addresses inside the app. If a future version adds an optional feature that changes this, it will be off by default, described here first, and listed on the Network activity page.

6. Your rights

Under India's Digital Personal Data Protection Act, 2023 and its Rules and, where it applies, the EU and UK GDPR, you can ask us for a summary of the personal data we hold about you, ask us to correct, complete or erase it, withdraw consent at any time, nominate someone to exercise these rights for you, and raise a grievance. Email privacy@asitis.app; we answer within 30 days. EU and UK residents may also complain to their supervisory authority. If we do not resolve a grievance, residents of India may approach the Data Protection Board of India.

7. International transfers

Buttondown, Cloudflare, Resend and the merchant of record process data outside India and the EU. Transfers rely on the providers' standard contractual clauses and equivalent safeguards. We choose providers with published data processing agreements.

8. Security and breaches

We hold little data by design. Access to the waitlist, analytics and licence records is limited to the founder and protected by two-factor authentication. If a breach affects you, we will notify the Data Protection Board of India without delay (with a detailed report within 72 hours) and, where the GDPR applies, the relevant supervisory authority within 72 hours, and affected individuals without undue delay, and any applicable EU or UK authority within 72 hours.

9. Children

The site and app are not directed at children (anyone under 18 in India, or under 16 in the EU), and we do not knowingly collect their data.

10. Changes

Changes to this policy are dated at the top and listed in the changelog. Material changes to what the app can send are announced before they ship.