Gettable ("the Service", "we", "us") is a personal knowledge management application. A signed-in user can save notes, photos, links, Bible references, tasks, recipes, contacts, habits and calendar events, and can optionally connect health and money accounts. Your hub is private to you by default. Some features let you deliberately share specific items with other people, described under Sharing below.
What we collect
- Account info: email, username, display name, and (optionally) first and last name. Provided by you at sign-up or via Google sign-in.
- Authentication: a salted PBKDF2 hash of your password (we never store your password in plain text), or your Google account identifier when you sign in with Google.
- Your content: the notes, photos, links, tags, and other items you add to your hub. Stored in our database and (for files) in Cloudflare R2 object storage.
- AI-derived metadata: for photos and links you upload, we run AI to extract text, generate a description, and pick topic tags. This data is indexed for search but you control whether to display it.
- Session cookies: a signed HttpOnly cookie used to keep you signed in.
- Advertising and measurement: we use the Meta Pixel and Meta's Conversions API to measure whether our ads lead to signups and purchases. When you visit the site, Meta sets cookies in your browser. When you sign up or buy, we send Meta your email address in hashed form (a one-way scramble, not the address itself), your IP address, your browser user agent, and the plan and amount purchased. Meta may use this to measure and target advertising. See Meta's privacy policy.
How we use it
- To run the service: storing your hub, serving your photos, indexing your content for full-text search.
- To authenticate you on return visits.
- To resolve password resets if you request one (via email).
We do not sell or rent your data. We share signup and purchase events with Meta for advertising measurement, as described above. We never send Meta the contents of your hub. Your notes, photos, links, tasks, recipes, contacts, calendar, health and money data are never shared with any advertiser.
Where it lives
Your hub is stored on Cloudflare infrastructure: D1 (database), R2 (object storage), Vectorize (search index), Workers (application runtime). See Cloudflare's DPA for their data-handling practices.
Subprocessors: Cloudflare Inc. (hosting, database, storage, AI), Anthropic (AI features), Meta Platforms (advertising measurement), Lemon Squeezy (payments), Resend (email delivery), and Google (sign-in and web fonts).
Sharing
Everything you save is private to you unless you deliberately share it. Gettable offers several ways to share, and each one is something you turn on yourself:
- Households: you can group up to five accounts and share items you file under a shared category with those members.
- Per-item sharing: you can share an individual note, task, recipe or contact with another Gettable account.
- Trackers: you can give another person view-only access to a tracker, or create a public mentor link.
- Public links: you can create a share link for an item. Anyone holding that link can view that item without signing in, so treat it as public. You can revoke a link at any time.
We do not share your content with anyone else, and other users cannot see anything you have not shared.
Google sign-in
When you choose "Continue with Google", we receive your Google account email, name, and Google subject identifier, nothing else. We use these solely to create or match your account on Gettable. We never access your Gmail, Drive, Calendar, or any other Google service.
AI processing
Photos you upload are sent to Cloudflare Workers AI (Meta's Llama 3.2 Vision and Llama 3.3 models, running on Cloudflare's infrastructure) to extract text and generate descriptions and tags.
Features that generate or interpret text for you, including Ask AI, recipe suggestions, greeting drafts, suggested note titles and natural-language calendar entry, send the relevant content to Anthropic's API. Only the content needed for that request is sent, and only when you use one of those features.
Neither provider trains on your content. Cloudflare states that it does not use customer content to train models or improve services, and Anthropic's commercial API terms do not train on inputs or outputs.
Your rights
- You can delete any entry from your hub at any time. Deletion removes both the database row and the underlying file from object storage.
- You can sign out, which clears your session.
- You can export everything in your hub as a JSON file at any time, from My account.
- You can delete your entire account from My account. This is immediate and permanent: it removes your account, every item in it, your uploaded files, and your search index entries. We keep no copy. If you would rather we did it for you, email the address below.
- You can opt out of advertising measurement by using a browser that blocks the Meta Pixel, or by contacting us. We will honour any request to stop sending your events to Meta.
Security
All traffic is HTTPS. Passwords are PBKDF2-hashed with per-user salts. Sessions are HMAC-signed. Security reports: see /.well-known/security.txt.
Contact
kevin.mitchell@mainst-group.com