Charon

Privacy is a local contract

Charon works without an account, sync service, analytics, or content upload.

Workspace ownership

Notes, Tags, and managed Attachment copies stay in the local Workspace you choose. React never reads Workspace files or Attachment bytes directly.

Selected text

On supported macOS builds, Accessibility reads selected text. If direct access returns nothing, one bounded source Copy may place that selection briefly on the system clipboard, where a clipboard manager could see it. Charon restores prior clipboard contents only when no concurrent write occurred.

Explicit copy

Copy as Markdown writes Note text, optional Tags, and canonical paths to managed Attachment copies. It does not copy Attachment bytes, upload content, paste, or change Note state.

Deletion limits

A successful permanent Delete removes active Markdown and managed Attachment bytes from the Workspace and normal completed Charon transaction backups. Operating-system snapshots, external backups, and synchronized-folder histories remain outside that guarantee.

Legacy files

Schema v1 content is moved to a visible user-owned legacy Markdown archive during migration. It is not merged silently into active Notes.

This site

This static site is served as ordinary files by Cloudflare Workers Static Assets. Cloudflare processes ordinary connection metadata to deliver it. Charon enables no Web Analytics or persistent Worker observability and adds no account, form, tracker, advertising script, runtime API, third-party embed, or production Access cookie.