Privacy Policy
This policy explains what ImportThing ("the app," "we") collects, why, and how it is protected. We aim to be fully transparent: everything the app stores or processes is described below. By using the app you agree to this policy.
What the app does
The app lets you import a CSV file into a Notion database you choose. You authorize it through Notion's official sign-in flow, and you decide which pages it may access during that flow.
Information we store
- Your Notion access token — issued by Notion when you connect, scoped only to the pages you grant. Stored encrypted and used solely to perform imports you request.
- Your workspace name and a workspace identifier — the name is displayed in the app so you can see which account is connected, and the identifier (provided by Notion) is how we associate your connection, sessions, and any purchases with your workspace.
- A session identifier — a random value in a cookie that keeps you signed in. It contains no personal data.
- Your plan and purchase entitlements — if paid features are enabled, we store which plan you have (free, single-import credits, or unlimited), how many import credits remain, and whether your free import has been used. This is tied to your workspace identifier so your purchase is honored when you return.
- Payment-confirmation records — when a payment completes, Stripe notifies us and we store the identifier of that payment event so the same purchase is never processed twice. These records contain no card details and no other personal data.
We do not collect names, email addresses, or account passwords ourselves — sign-in is handled entirely by Notion, and payment details by Stripe (see below).
Information we do not store
- Your CSV files and their contents. Rows are processed in memory during an import and then discarded. We never keep, log, or analyze the data you import.
- Payment card details. If paid features are enabled, payments are handled entirely by Stripe. We never see or store your card number.
How your data is protected
- Access tokens are encrypted at rest using AES-256-GCM. The encryption key is held separately from the database, in a secure server environment.
- All connections to the app use HTTPS.
- Session cookies are HTTP-only (unreadable by scripts), SameSite, and marked Secure in production.
- The app requests only the Notion permissions it needs to function.
Abuse prevention and IP addresses
To protect the service from abuse and keep it available for everyone, the app applies rate limits using your network (IP) address. Your IP is processed transiently in memory for this purpose and is not written to our database or kept after the request. Our hosting provider may log standard request metadata (including IP addresses) for security and operational purposes under its own policies.
Our application logs record only error messages, never the contents of your imports, your tokens, or other sensitive data.
Third-party services
- Notion — your data lives in your Notion workspace; the app reads and writes there on your behalf, governed by Notion's own privacy terms.
- Railway — hosts the application and its database, which holds your encrypted token and the other records described above.
- Stripe — securely processes payments if and when paid features are enabled. Your card details are entered on Stripe's systems and are governed by Stripe's privacy policy; we never receive them.
Retention and deletion
Click Disconnect in the app at any time. This revokes the app's access with Notion and permanently deletes your stored access token and your active session from our database. You can also remove the connection directly from your Notion workspace settings. Expired sessions are removed automatically.
For continuity, disconnecting does not automatically erase your plan and purchase records (your entitlements and payment-confirmation identifiers). We keep these so that a paid plan or remaining import credits are still available to you if you reconnect the same workspace. If you would like this purchase data deleted as well, contact us using the details below and we will remove it.
Changes
We may update this policy. Material changes will be reflected by the date at the top of this page.
Contact
Questions or data requests: hello@joshhare.co