Effective July 11, 2026
Privacy notice
This notice covers document conversion, accounts, billing, security records, and optional product diagnostics.
Who is responsible
Download to Markdown, operated by th3nolo, is responsible for the application data described here. Send privacy questions or deletion requests to th3nolo@th3nolo.com.
Uploaded files and generated Markdown
- The uploaded source file is processed in a request-scoped temporary directory and deleted when the request ends.
- The generated Markdown, original filename, output filename, file size, source type, page count, processing time, and conversion engine label are stored in the application database.
- Generated Markdown is retained until the operator deletes it or completes a deletion request. There is not yet an automatic time-based deletion policy.
Accounts, security, and billing
The service stores your verified email, name, account timestamps, session records, plan and usage state, conversion ownership, download records, and limited IP address and user-agent data used for abuse prevention and security. Gumroad processes checkout. The application stores the buyer email, product and sale identifiers, subscription state, and entitlement events needed to grant or revoke access. It does not receive full payment-card details.
OCR and service providers
Pages that require OCR may be sent to a specialized OCR processor. Download to Markdown does not use document content to train its own models. The current OCR processor's identity and terms are available on request before you upload sensitive material. Cloudflare provides network and content-delivery services, Contabo provides primary hosting infrastructure, Gumroad provides payment processing, and the optional analytics stack is self-hosted.
Storage location and security
Primary application data is stored on Contabo infrastructure; network requests may pass through Cloudflare. Provider locations and routing can change, so contact us for the current processing location before submitting data with residency requirements. Traffic uses HTTPS. Access to persistent storage is restricted at the infrastructure level, but generated Markdown is not currently protected with per-document application-layer encryption.
Deletion and account requests
Email the address above from the account email and describe whether you want a specific conversion or the account records deleted. Some billing, security, backup, or legal records may need to be retained where required to prevent fraud, resolve disputes, or comply with law. The response will state what was deleted and what, if anything, must remain.
Optional product diagnostics
Optional diagnostics are off until you allow them. Declining does not affect conversion, download, or account use. We collect page paths without query strings, Web Vitals, random visit linkage, click and scroll measurements, and—within separate independent 5% samples—masked heatmaps or session replays. We exclude document contents, filenames, form entries, account details, and sensitive product areas.
Session replay records for a maximum of five minutes. That is the maximum recording duration, not the storage period. Optional diagnostic data is retained for no more than 90 days. Your browser remembers the choice for 180 days. You may withdraw permission through Analytics settings; Do Not Track overrides an earlier permission.