The short version
- We have no user accounts and no passwords.
- We never store the contents of your Notion workspace on our servers.
- Your Notion authorization is held only in an encrypted, browser-side cookie that our server can read but your browser’s scripts and other sites cannot — unless you opt into automatic scheduled backups, in which case we also hold an encrypted copy so backups can run while you’re away (section 4).
- Our only analytics is Cloudflare Web Analytics — cookieless, privacy-first visit counts. We set no tracking cookies, do no cross-site tracking, and our analytics never sees your Notion content.
- Payments are handled entirely by Dodo Payments, our reseller; we keep nothing about your subscription on our servers.
1.Who we are
Restora (“Restora”, “we”, “us”) is an independent backup-and-restore tool for Notion, operated by Restora. Restora is not affiliated with, endorsed by, or sponsored by Notion Labs, Inc. For the purposes of data-protection law, the operator is the data controller for the limited processing described here. You can reach us at support@restora.cc.
2.What this policy covers
This policy covers the Restora web application and these policy pages. It does not cover Notion or Dodo Payments, who process your data under their own privacy policies (see sections 7 and 8). When you connect Notion or pay through Dodo Payments, their terms and privacy policies also apply to you.
3.What we don’t collect
Restora is built to need as little of your data as possible. We do not:
- create accounts or store passwords — you connect through Notion’s OAuth instead;
- run advertising, cross-site tracking, or any analytics that uses cookies or identifies you personally;
- set tracking or advertising cookies;
- keep server-side logs of your Notion content or of your access token.
The one thing we do measure is usage: we use Cloudflare Web Analytics, a cookieless, privacy-first tool, to count page visits and see which features are used so we can improve the product. It sets no cookies, does not track you across sites, does not build a profile of you, and never has access to your Notion content or your access token. See section 8.
There is one place where we do process information you send us on purpose: in-app feedback. If you submit feedback, we process the information you provide — your message, the Restora screen you were on, and your email address if you choose to give one. If you choose to attach a screenshot, it may contain workspace content and will be sent through our email provider (see section 8) so we can review your report. Screenshots are never collected automatically: nothing is captured unless you attach it yourself, and feedback is never sent unless you send it. This is separate from, and does not change, the fact that we do not store the contents of your Notion workspace.
4.Your Notion connection and access token
When you connect Notion, Notion issues an access token (and a refresh token) to the Restora integration. We handle that token as follows:
- it is encrypted with AES-256-GCM and stored only inside a cookie in your browser;
- the cookie is HttpOnly (your browser’s scripts and other websites cannot read it), Secure (sent only over HTTPS), and SameSite=Lax;
- only our server holds the key that can decrypt it, and it does so transiently, in memory, to make the Notion API calls you ask for;
- the token is never written to any database or file on our servers, never returned to your browser as readable data, and never logged;
- when the access token nears expiry we refresh it with Notion and re-encrypt the new token back into the cookie.
The cookie expires after at most 30 days, and is cleared when you log out.
If you turn on automatic (scheduled) backups — an optional, opt-in Pro feature — a small amount of additional data is stored on our servers so backups can run while you’re not there:
- your Notion access/refresh token, and your Google Drive or S3 connection credentials, each encrypted with AES-256-GCM under a separate encryption key (distinct from the session-cookie key above) and decrypted only transiently, in memory, for the duration of a scheduled run;
- schedule settings (frequency, destination, which databases/pages by id — never titles or content);
- run history (when a backup ran, whether it succeeded, byte/row counts) and, so we can tell you what changed between backups, a structural summary of each backup — your databases’ and properties’ names and types, view and row counts, and page ids. This never includes page content or property values. Drift alerts and the change feed are built from this summary;
- your backup files themselves are never stored by us — they stream straight to your own Google Drive or S3 bucket, the same as the manual/CLI paths described in section 5.
You can disconnect a Google Drive or S3 destination at any time from the app, which removes that destination’s stored credentials immediately. To delete all Protection Center data associated with your workspace (including your vaulted Notion connection and run history), email us at privacy@restora.cc and we will remove it. This section does not apply if you only use manual backups, the CLI, or the free Drift Auditor — those remain exactly as described elsewhere in this policy.
5.How your Notion content is processed
When you run a backup, your Notion content passes through our server only in transit: we read it from Notion and stream it straight to a file that downloads to your device. When you run a restore, the backup file you upload streams through our server straight into Notion. We process this content transiently, in memory, to move it — we do not store it, cache it, or keep a copy.
Because we keep no copy, you are responsible for storing the backup files you download somewhere safe.
6.Cookies and local storage
Restora uses only what it needs to function:
- an encrypted session cookie holding your Notion authorization (described in section 4);
- a short-lived cookie holding an anti-forgery value during the Notion sign-in redirect;
- a single value in your browser’s local storage holding your Dodo Payments subscription id, so the app can re-check your subscription when you return.
We set no analytics, advertising, or cross-site tracking cookies.
7.Billing data (Dodo Payments)
Payments are processed by Dodo Payments, which acts as the Merchant of Record (the reseller of the subscription). Dodo Payments — not Restora — collects and processes your payment details, billing address, and any tax information, under Dodo Payments’s own privacy policy and buyer terms. We do not receive or store your card details. To check whether your subscription is active, our server asks Dodo Payments’s API about your subscription each time you use the tool, and stores nothing about it on our servers; your subscription id lives only in your browser. See Dodo Payments’s policies at dodopayments.com.
8.Third parties and sub-processors
The only third parties involved in running Restora are:
- Notion — the workspace you connect; the source and destination of the data you back up and restore.
- Dodo Payments — our payment reseller and Merchant of Record (billing only).
- Railway — hosts the Restora application (a containerised server in the United States). Your requests and your Notion content pass through Railway’s servers in transit while a backup or restore runs; Restora keeps no database and no stored copy there.
- Cloudflare — provides DNS for our domains, hosts the separate marketing and policy pages (at restora.cc), and provides Cloudflare Web Analytics, the cookieless, privacy-first tool we use to count visits to the web app. It collects aggregate page and performance metrics without cookies and without identifying individuals, and never receives your Notion content or token. The application’s data traffic otherwise goes directly to Railway and is not proxied through Cloudflare.
- Resend — our transactional email provider. It delivers the change-alert and account emails you opt into, and any feedback you send us, including a screenshot if you choose to attach one (see section 3). It does not otherwise receive your Notion content, and never receives your access token.
We do not sell or share your data, and we use no advertising providers. Our only analytics provider is Cloudflare Web Analytics, described above.
9.International data transfers
Restora is operated from the United Arab Emirates and the application is hosted on Railway in the United States; Notion, Dodo Payments, and Cloudflare also operate internationally. Your data may therefore be processed in countries other than your own. Where required, we rely on the transfer protections offered by those providers.
10.Data retention
By default (manual backups, restores, the CLI, and the free Drift Auditor) we retain essentially nothing on our servers: no Notion content and no request logs. The encrypted session cookie lives in your browser and expires after at most 30 days, or immediately when you log out. The subscription id in your browser’s local storage stays until you clear it or use “Remove from this browser.” Billing records are retained by Dodo Payments under its own policy.
If you opt into automatic scheduled backups (section 4), the encrypted connection credentials and schedule/run metadata described there persist in our database until you disconnect that storage destination or delete your Protection Center data, at which point they are removed.
Feedback you send us (section 3) is kept as a support record — your message, the screen you were on, and your reply address if you gave one — until we have dealt with it, and is deleted along with the rest of your data when you delete your Protection Center data. An attached screenshot is not stored on our servers: it is passed straight through to the email and discarded, and we keep only a note of its file size and type. The copy that reaches our support mailbox persists there like any other support email.
11.Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we process your data to: perform the service you requested (running your backups and restores); pursue our legitimate interest in keeping the service secure and preventing abuse; and perform our contract with you for the paid subscription (through Dodo Payments).
12.Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or object to the processing of your personal data. Because Restora stores almost nothing about you:
- you can end our access at any time by disconnecting Restora in your Notion settings and logging out;
- you can clear the subscription id we hold in your browser with “Remove from this browser,” or by clearing your browser storage;
- for any personal or billing data held by Dodo Payments, please contact Dodo Payments, who holds those records.
To make a request or ask a question, contact us at support@restora.cc.
13.Children
Restora is a paid tool intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a minor has used Restora, contact us and we will help.
14.Security
We protect your data with measures including: AES-256-GCM encryption of the Notion token; HttpOnly, Secure, SameSite cookies; no persistent server-side storage of your content or token; and a deliberately small set of third parties. No method of transmission or storage is ever completely secure, and we cannot guarantee absolute security.
15.Changes to this policy
We may update this policy as the product or the law changes. When we do, we will revise the “last updated” date above and, for material changes, surface a notice on this page or in the app.
16.Contact
Questions about this policy or your data: support@restora.cc.