Jotbay
Back to the start page

Security

The trust model of Jotbay, in plain words. Each statement here is a statement about the code, and you can read the code.

The trust model

Jotbay has no server. It sends your notes only to the git repository that you selected. There is no telemetry, there is no analytics, and you make no account with this project.

Your credentials

Jotbay does not read your credentials. It does not keep them, and it does not send them. The push operation and the pull operation use your git program and your credential helper. The result is the same as the result of the same commands in your terminal.

The setup uses gh only for the option Create one for me. It makes one repository, under the account that gh uses. The two other setup options do not use gh.

The one connection that Jotbay makes

Jotbay reads api.github.com/repos/<repository>/releases/latest to find a new version. It sends no data with this request, and it keeps the answer for six hours.

Set JOTBAY_TOOL_REPO to a different address, or prevent the connection. All other functions continue to operate. The privacy page lists each connection.

What Jotbay does to your files

Report a vulnerability

Open a security advisory on the repository. You can also send an email to the address on the GitHub profile of the maintainer. Do not open a public issue for a problem that a person can exploit.

You get an answer in one week. This is a personal project. There is no security team, and there is no bounty.

Supported versions

The most recent release only. The command jotbay upgrade moves a machine to that release in one step.