← ShareMD

Privacy Policy

Last updated August 17, 2026

ShareMD turns markdown into shareable document pages. This policy describes exactly what the service stores, who else can see it, and how long it is kept. It is written from what the software actually does rather than from a template.

Who runs ShareMD

ShareMD is operated by an independent developer based in Georgia, United States. Questions about this policy, or requests about your data, go to support@getsharemd.com.

What we collect

If you create an account:

  • Your email address and display name.
  • A password, stored only as a salted hash. We never see or store the password itself.
  • If you sign in with Google: your email, name, and profile image from your Google account. Nothing else, and we cannot access anything else in your Google account.
  • Whether your email has been verified, and your default document theme.

Documents you create:

  • The markdown you paste or write, its title, and the theme and font you choose.
  • Whether the document is public-unlisted or private-link, and when it was created and last changed.
  • For private links: a hash of the link token, and if you set one, a salted hash of the password. The token and password themselves are not stored in a form we can read.
  • Email addresses of collaborators you invite, so they can be granted access when they sign in.

Technical data, while you are signed in:

  • A session record containing your IP address and browser user-agent, used to keep you signed in and to let you see and revoke sessions.
  • Standard server logs. These are short-lived and used for debugging and abuse prevention.

What we do not collect

  • No advertising, no advertising identifiers, and no ad networks.
  • No analytics or tracking scripts, and no third-party cookies. The only cookie ShareMD sets is the one that keeps you signed in.
  • No selling or renting of personal data, to anyone, ever.
  • No payment card details. Card data goes directly to Stripe and never touches our servers.

Who else processes your data

ShareMD relies on a small number of services to operate. Each receives only what it needs:

  • DigitalOcean — hosts the server and database, in a data centre in New York, United States. All ShareMD data lives here.
  • Stripe — processes subscription payments. Receives your email and payment details; we store only a customer identifier and your subscription status.
  • Resend — delivers transactional email (verification, password reset). Receives your email address and the message content.
  • Google — only if you choose to sign in with Google, and only to authenticate you.
  • Cloudflare — provides DNS for getsharemd.com.

How long things are kept

  • Documents published without an account are deleted automatically 7 days after they are created.
  • Documents you move to trash are permanently deleted after 30 days.
  • Documents in an account are kept until you delete them or close your account.
  • Sessions expire on their own and can be revoked at any time by signing out.
  • Encrypted database backups are kept for 14 days and then destroyed.

Your choices

  • Access and correct — your account page shows the data we hold about you, and you can change it there.
  • Export — every document is markdown, and you can copy or download it at any time. There is no proprietary format and no export fee.
  • Delete a document — deletion removes it from the database, and the shared link stops working immediately.
  • Delete your account — this removes your account, your documents, and your sessions, and cancels any active subscription first. It cannot be undone.

If you are in the EU, UK, or California, you have additional rights over your personal data including access, correction, deletion, and portability. The controls above cover them, but you are welcome to email instead and we will action it.

Security

Traffic is encrypted in transit with TLS. Passwords are stored as salted hashes. Private-link tokens are stored as hashes and compared in constant time, so a leaked database does not yield working links. The server is firewalled to web and SSH traffic only, and access requires an SSH key.

No system is perfectly secure. A public-unlisted link is unguessable but not secret: anyone who has the URL can open it. If something genuinely needs to be restricted, use a private link with a password, and treat anything you publish as potentially readable by whoever receives the link.

Children

ShareMD is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, email us and we will remove it.

Changes

If this policy changes in a way that materially affects how your data is handled, the updated date above will change and, if you have an account, we will email you. Continuing to use ShareMD after a change means you accept the updated policy.