Andiko

Privacy policy

Last updated 9 October 2026

In short

  • Your documents are saved in your browser.
  • A document reaches our server only when you share it (it is stored until you stop sharing) or export it as a PDF (it is processed and discarded).
  • Images that a document includes from other websites are loaded from those websites.
  • There are no accounts, ads, analytics or tracking cookies, and we don’t sell data.

Who we are

Andiko is run by Octan Group (“we”), the “data controller” responsible for the personal data described here. For anything about privacy, or to report a shared document, email privacy@andiko.app.

Octan Group
KG 566 St, Kigali, Rwanda
Registered in Rwanda, company code (TIN) 106864058

What stays in your browser

These are kept on your device. A document leaves it only when you share or export it, and the two cookies below are sent to our server with each request but hold only a setting. Clearing your browser’s data for this site deletes them, and we cannot recover them.

  • Documents and folders, in your browser’s IndexedDB storage.
  • Preferences in localStorage: theme, view mode, split position, scroll sync, open folders and the last document you opened. If a page closes before your latest edits are saved, they are also kept there until you next open that document.
  • An owner key in localStorage: a random code created the first time you open the editor. It proves to our server that documents you shared came from this browser.
  • Two cookies: andiko_resume (kept for a year) takes you straight back to the editor from the home page, and sidebar_state (kept for a week) remembers whether the sidebar is open. Neither contains anything that identifies you.

All of these are needed for the app to work as you’d expect, so we don’t ask for consent to store them.

What reaches our server

Sharing and PDF export are optional. Everything else works without sending your documents to our server.

Shared documents

When you share a document, we store:

  • its title and full text, updated each time you edit it;
  • a one-way fingerprint (SHA-256 hash) of your owner key, so only your browser can edit it or stop sharing it. The key itself is never stored. The fingerprint is the same for every document you share from one browser, so it links them together. On its own it doesn’t say who you are;
  • when it was shared and last updated.

Anyone with the link can read a shared document, and anyone who opens it can save their own copy in their browser. Copies are outside our control. Shared documents ask search engines not to list them, but links can be passed on, the link itself contains the document’s title, and apps that preview links (such as chat apps) show it too. Don’t share anything you want to keep private.

We keep a shared document until you stop sharing it, delete it, or we remove it under our terms of use. It is then removed from our database straight away, unless the law requires us to keep it, and from our database provider’s restore history within 30 days. If you lose your owner key (for example by clearing your browser data), you can no longer remove it yourself: email privacy@andiko.app with the link, and we will remove it once we’re reasonably satisfied that you shared it.

PDF export

To create a PDF, your browser sends the rendered document to our server. It is turned into a PDF and sent back straight away, and it is not stored. If the document includes images from other websites, our server downloads them to put them in the PDF.

Technical logs

Like any website, our hosting provider records technical details of each request, such as your IP address, browser type and the page requested. These logs are used to keep the service running and secure, and are available to us for 30 days at most. Vercel may also keep its own records of requests, under its privacy policy.

Images and links to other websites

Documents can include images from other websites. Your browser loads these directly from those websites, as on any web page, so they see your IP address and browser type. This includes shared documents: whoever shares one can include an image from a server they control and see when it is opened, and from which IP address. Links in a document lead to other websites, which have their own privacy policies.

When you email us

If you email us, for example to report a shared document or about your data, we receive your email address and what you write. We use them only to deal with your message, and delete them a year after it is resolved, which leaves time for any follow-up.

Why we use this data

  • To provide what you ask for: publishing and updating shared documents, and creating PDFs under our terms of use (performance of a contract).
  • To keep the service secure: technical logs and the limits on shared documents (legitimate interests).
  • To moderate shared documents: reviewing reported documents, and others when we need to keep the service safe, and using the fingerprint to find the other documents of someone who keeps sharing illegal content (our legal obligations, or otherwise our legitimate interest in keeping the service lawful).
  • To answer emails: dealing with reports, privacy requests and other messages (our legal obligations for privacy requests, and otherwise legitimate interests).

We don’t use your data for profiling, advertising or automated decisions.

Who processes it for us

  • Vercel runs the server that creates PDFs and serves shared documents, in its EU (Frankfurt) region. Pages reach you through Vercel’s global network, so your requests may pass through a server near you on the way.
  • Neon stores shared documents in its EU (Frankfurt) region.
  • Our email provider receives and stores the emails you send us.

Vercel and Neon are based in the United States, so their staff may access data from there. Neon processes it only on our instructions, under a data processing agreement that includes the EU Standard Contractual Clauses. Vercel and our email provider handle it under their own terms and privacy policies.

Apart from these providers, we give data to authorities only when the law requires it, or when a shared document suggests a threat to someone’s life or safety.

Your rights

Depending on where you live, you can ask to access, correct or delete your personal data, to restrict or object to how we use it, and to receive a copy of it. The quickest way to delete a shared document is “Stop sharing” in the app. For anything else, email privacy@andiko.app. As there are no accounts, include the link to one of your shared documents: from it, we can find the others shared from the same browser. You can also complain to the data protection authority where we are established, or where you live.

Reporting a shared document

If a shared document is illegal or infringes your rights, use Report on its page or email privacy@andiko.app with the link and what is wrong with it. We review reports and remove documents we find to be illegal or to infringe someone’s rights. The terms of use explain how reports are handled.

Changes

If we change how Andiko handles data, we will update this page and its date. The source code, which shows exactly what is stored, is on GitHub.