Vigil Wiki Privacy Policy
Effective date: May 28, 2026
Last updated: May 28, 2026
This Privacy Policy explains how Vigil Wiki ("Vigil Wiki," "vigil.wiki," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the vigil.wiki website, web application, public note pages, and Model Context Protocol ("MCP") integrations for services such as Claude, ChatGPT, and other compatible agents (collectively, the "Service").
Vigil Wiki is a private note-keeping and note-sharing app. It is designed for notes, drafts, markdown, links, tags, groups, and related text material. It is not an advertising network, tracking product, file hosting service, media locker, backup drive, or password manager.
1. Summary
- We do not show advertisements.
- We do not sell your personal information.
- We do not use private notes to train our own AI models.
- We do not use cross-site advertising trackers.
- We collect only the information needed to provide accounts, notes, publishing, subscription status, support, security, and MCP access that you choose to enable.
- Private notes are private unless you publish them, share them through an authorized integration, or otherwise disclose them.
- Published notes are publicly accessible on the web and may be copied, indexed, archived, cached, or quoted by others.
2. Information we collect
2.1 Account information
When you create or use an account, we may collect and store information such as:
- email address;
- username, display name, or account identifier;
- authentication provider identifiers;
- account settings;
- subscription status; and
- dates related to account creation, login, subscription, cancellation, or deletion.
We do not ask for payment card numbers, government identifiers, health records, passwords for other services, API keys, or other restricted data. Do not store those categories of information in Vigil Wiki notes.
2.2 Note content and note metadata
The Service stores the text content and metadata needed to operate a notebook, including:
- note titles, slugs, markdown content, rendered note content, and revisions or autosave state where supported;
- groups, tags, backlinks, wikilinks, note relationships, and organization data;
- note visibility status, including whether a note is private, published, or unpublished;
- public note URLs;
- timestamps for creation, update, publish, unpublish, and deletion events; and
- other data needed to search, edit, organize, publish, and display notes.
2.3 Published notes
If you publish a note, the note is made available as a public web page at a vigil.wiki URL. Published notes are anonymously readable without authentication. Public note pages may include note content, title, slug, tags, update information, links, and other public display metadata.
Unpublishing a note removes the public version from the Service, but we cannot control copies, screenshots, browser caches, search-engine indexes, archival services, third-party summaries, or links created by others while the note was public.
2.4 MCP and connected-agent data
If you connect Vigil Wiki to an AI client or agent through MCP, OAuth, or another authorized connection, we collect and store information needed to provide that connection, such as:
- authorization records;
- access scopes granted by you, such as
notes:read,notes:write, andnotes:publish; - integration identifiers;
- token or session records needed to keep the connection working;
- permission settings, including any account-level toggle that gates private-note reads; and
- logs needed to debug, secure, and operate the integration.
When an authorized agent uses Vigil Wiki tools, Vigil Wiki may return note data to that agent according to the permissions you granted and the specific action requested. The AI client or agent may process that data under its own terms and privacy policy. You should review the policies of Claude, ChatGPT, or any other agent before connecting Vigil Wiki.
2.5 Subscription and billing data
The web app is free to use as a personal notebook. MCP access may require a paid subscription. Paid MCP access is currently priced at $3.99 per month or $29.99 per year, unless a different price is shown to you before purchase.
Payments are processed by a third-party payment provider. We may receive and store billing-related information such as customer ID, subscription ID, plan, renewal status, payment status, invoice metadata, tax status, and limited billing contact details. We do not intentionally store full credit card numbers in Vigil Wiki.
2.6 Local device data
Vigil Wiki may store local preferences in your browser, such as theme choice, editor settings, or UI state. For example, theme preferences may be stored in localStorage so the site can apply the selected theme before the page paints. This local storage is not used for advertising tracking.
2.7 Operational, security, and abuse-prevention data
To operate and protect the Service, we may process limited operational logs such as:
- IP address;
- user agent;
- request path or endpoint;
- timestamps;
- error logs;
- rate-limit events;
- authentication events;
- security events; and
- abuse or Terms-enforcement records.
We use this data to keep the Service reliable, prevent abuse, diagnose problems, enforce our Terms, and comply with legal obligations. We do not use this data for behavioral advertising or cross-site tracking.
2.8 Support communications
If you contact us, we collect the information you provide, such as your email address, message content, screenshots, bug reports, and any related account details needed to respond.
3. How we use information
We use information to:
- create, authenticate, and secure accounts;
- provide note editing, autosave, search, backlinks, tags, groups, themes, and publishing;
- provide and enforce MCP permissions and connected-agent access;
- return only the note data needed for a requested MCP action;
- process subscription status and billing records;
- provide support;
- prevent spam, abuse, copyright infringement, unauthorized binary storage, and illegal or harmful use;
- detect, investigate, and respond to security incidents;
- comply with law, court orders, government requests, tax obligations, and rights-enforcement requests;
- improve reliability, performance, and usability; and
- enforce our Terms of Use.
We do not use private notes for advertising. We do not sell private notes, account information, or usage data.
4. How information is shared
We share information only as described below.
4.1 Service providers
We may share information with vendors that help us operate the Service, such as hosting providers, database providers, email providers, authentication providers, payment processors, logging/error-monitoring providers, security providers, and customer-support tools. These providers may process information only for the services they provide to us.
4.2 Connected AI clients and agents
If you authorize a Claude, ChatGPT, or other MCP-compatible client to access Vigil Wiki, we may share note data and metadata with that client according to the scopes, permissions, and tool calls you allow. For example, a read tool may return note content, search results, tags, or note metadata; a write tool may create or update notes; and a publish tool may make a note public.
We do not control how third-party AI clients process data after they receive it. Their own terms and privacy policies apply.
4.3 Public publishing
When you publish a note, the published note is shared publicly. Anyone with the URL may view it, and it may be indexed or copied by third parties.
4.4 Legal, safety, and rights protection
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with applicable law or legal process;
- respond to lawful requests by public authorities;
- protect the rights, privacy, safety, or property of Vigil Wiki, users, or the public;
- investigate security incidents, fraud, spam, or abuse;
- enforce our Terms of Use;
- respond to copyright, trademark, privacy, or other rights claims; or
- prevent illegal use of the Service.
4.5 Business transfers
If Vigil Wiki is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to this Privacy Policy or a policy that provides materially similar protections.
5. Data retention
We retain information only as long as needed for the purposes described in this Privacy Policy, unless a longer period is required for legal, security, tax, accounting, dispute-resolution, or abuse-prevention reasons.
Typical retention periods are:
- Private notes: retained until you delete them or delete your account, unless retained in backups or for legal/security reasons.
- Published notes: retained while published. If unpublished, the public page is removed from the Service, but third-party copies may remain outside our control.
- Deleted notes and deleted account content: removed from active systems within a reasonable period, normally within 30 days, unless retention is needed for legal, security, or abuse-prevention reasons.
- Backups: may retain deleted data for up to 90 days before ordinary backup rotation removes it.
- MCP authorization records and tokens: retained until you revoke the connection, delete your account, or the records are no longer needed, subject to backup retention.
- Operational and security logs: normally retained for up to 30 days, and longer where needed to investigate abuse, security incidents, service reliability, or legal compliance.
- Billing, invoice, tax, and accounting records: retained as long as needed for accounting, tax, chargeback, fraud-prevention, and legal obligations, which may be up to 7 years or longer if required by law.
- Support communications: retained as long as needed to resolve your request and maintain accurate support, safety, and dispute records.
6. User controls and choices
You may use the Service controls to:
- create, edit, and delete notes;
- publish and unpublish notes;
- manage tags, groups, and note metadata;
- manage account settings;
- enable or disable private-note reads for MCP access where supported;
- grant or revoke connected-agent permissions;
- cancel a paid subscription; and
- request account deletion.
You may also contact us to request access, correction, deletion, or export of personal information, subject to identity verification and legal limits.
7. MCP privacy and permission principles
Vigil Wiki integrations are intended to follow least-privilege principles:
- MCP tools should request only data needed for the requested note action.
- Read-only tools should retrieve or list relevant note data without modifying notes.
- Write tools should be clearly separated from read tools.
- Publish tools should be treated as public-output actions because they can make private content visible on the public web.
- Vigil Wiki should not request your full chat transcript, raw conversation history, precise location, payment card data, government identifiers, protected health information, authentication secrets, or unrelated profile data through an MCP tool.
Do not grant MCP permissions to any client or agent you do not trust.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. However, no internet service, cloud database, browser storage mechanism, or authentication system is perfectly secure.
Unless we expressly state otherwise, Vigil Wiki is not an end-to-end encrypted vault. Do not store passwords, API keys, private cryptographic keys, payment card data, medical records, government identifiers, or other highly sensitive information in Vigil Wiki.
9. Children and minors
Vigil Wiki is not directed to children under 13. You may not use the Service if you are under 13. If you are under the age of majority in your jurisdiction, you may use the Service only with permission and supervision from a parent or legal guardian.
10. International users
Vigil Wiki may process and store information in countries where we or our service providers operate. Those countries may have data-protection laws different from the laws of your location. By using the Service, you understand that your information may be processed in those countries, subject to this Privacy Policy.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy, updating the effective date, or using another reasonable method. Your continued use of the Service after the updated policy takes effect means you accept the updated policy, to the extent permitted by law.
12. Contact
For privacy questions, requests, or concerns, contact:
Privacy: privacy@vigil.wiki
Support: support@vigil.wiki
Copyright: copyright@vigil.wiki