Privacy Policy
Last updated: September 9, 2026
1. Introduction
This Privacy Policy explains how Noteecard (“we”, “our”, or “us”) collects, uses, stores, and protects your personal information when you use the Noteecard iOS app and related services, including noteecard.com. We are committed to transparency and to handling your data responsibly, in compliance with applicable data protection laws including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA). By using Noteecard, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of the app.
2. Information We Collect
We collect information in two ways: information you provide directly, and information collected automatically when you use the app.
3. Information You Provide
When you create an account, use the app, or contact us, you may provide: • Name and email address • Account credentials (managed via secure authentication providers such as Apple or Google) • Content you create within Noteecard, including Cards, Notes, Tasks, Journal entries, Inbox pins, tags, and optional reminder / due-date metadata • Support requests and feedback • Payment-related information (processed via Apple App Store on iOS and Stripe on the web — we never store card details) Your private library (Notes, Tasks, Journal, Inbox pins, and related metadata) is stored in your account so you can access it across devices. Encrypted Cards remain separately protected by PIN encryption as described in Section 8.
5. Automatically Collected Information
When you use the Noteecard app, we may automatically collect: • Device type and operating system version • App version and build • Approximate usage patterns (for example, session frequency) in aggregated form • IP address (used where needed for security, abuse prevention, or country detection described below) • Where you enable reminders: local notification scheduling on this device This data helps us keep the app reliable and improve the product. For website cookies specifically, see Cookie Policy in Settings.
6. Country Detection (IP-Based Location)
When you create a standard card, we may use your IP address to estimate your country of origin using a third-party geolocation service (ipapi.co). This is used solely to display the appropriate country flag on your card. We do not store your precise location. Only the country code is retained, and only in connection with the card you create.
7. How We Use Your Information
We use the information we collect to: • Provide, maintain, and improve Noteecard’s core functionality • Authenticate your identity and manage your account • Store and sync your private library (Notes, Tasks, Journal, Cards, Inbox pins) across your signed-in devices • Schedule optional reminders / due dates you set on Notes, Tasks, or Journal entries (local notifications on this device) • Process purchases securely through Apple (iOS) and Stripe (web) • Personalize your experience and preferences • Communicate important service updates • Monitor platform security and prevent abuse • Analyze aggregated usage data to improve performance • Enforce our Terms of Service and community standards • Detect, prevent, and investigate abuse, fraud, or security threats • Remove or restrict content that violates our policies or applicable law We do not sell, rent, or trade your personal data to third parties.
7A. Ideas analysis
If you tap New ideas in Ideas, Noteecard prepares a small set of practical suggestions, at most once every 7 days, from your Notes, Tasks, Journal entries, tags, reminders, eligible Cards, and Saved cards. Saved cards may be older than the weekly period because saving a card is treated as a signal that it matters to you. Ideas are not generated automatically by the user-facing page. This is automated processing: Noteecard staff do not read your library to prepare Ideas. The relevant text is sent from our secure backend to our AI provider only to generate the requested suggestions. We do not store the raw prompt or a second copy of your library; we store the generated Ideas report, its date, and high-level source counts. Encrypted Card content is excluded and is not sent to the AI provider, including when an encrypted Card is in Saved. The AI provider receives the minimum content needed for this feature. OpenAI states that API data is not used to train its models unless the customer opts in; its current API data controls also describe default abuse-monitoring retention of up to 30 days. Ideas suggestions are supportive prompts only and do not diagnose depression or any other condition. If writing suggests immediate danger, the app may recommend local emergency services or crisis support, but it is not a replacement for professional help. The generated result is shown inside the Ideas page as practical suggestions only. It is not emailed automatically.
7B. Public Prompt Responses & Social Sharing
Some Home prompts, including Today’s idea and Theme of the month, may invite you to create a public response Card. Responses submitted through these features are processed as public content rather than private library content. We may publish the response text, public card number, display username, date, and other selected card metadata on noteecard.com, public share pages, RSS feeds, and Noteecard’s official social-media accounts. We may use third-party publishing or distribution services, such as dlvr.it or a similar service, to send public responses to social-media accounts. This processing is based on your decision to submit a response through a public prompt flow. Do not include personal, confidential, or sensitive information, or information about another person, in a public response unless you are comfortable with it being distributed publicly. Public prompt responses are separate from private Notes, Tasks, Journal entries, private Cards, and encrypted Cards. You may delete a public response through the available Noteecard controls. We will remove it from our own database, public pages, and feeds within a reasonable timeframe where practicable, but we cannot recall copies, caches, screenshots, RSS imports, or social-media posts already created or stored by third parties.
8. Security & Encryption
Encrypted cards are protected using AES-256 encryption. Messages are encrypted before storage. Only someone with the correct PIN can decrypt the message. We do not store your PIN. The PIN is transformed into a cryptographic key using PBKDF2 with SHA-256 and 100,000 iterations, which makes brute-force attacks computationally impractical. Encrypted messages are stored in encrypted form. Noteecard cannot access or decrypt encrypted card content. If a PIN is forgotten, the message cannot be recovered — this is intentional to preserve privacy. Notes, Tasks, Journal entries, Inbox pins, and related metadata are stored in your account so they can sync across devices. These items are account-private (visible to you when signed in) and protected with industry-standard infrastructure security, but they are not PIN-encrypted like encrypted Cards. You can delete individual items or delete your account to remove this data. Encrypted content may still be removed if it violates our Terms of Service, even if its contents are not readable by us, based on metadata, reports, or abuse detection mechanisms.
9. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process personal data under the following legal bases: • Consent — where you have given explicit permission • Contractual necessity — where processing is required to deliver the service you requested • Legitimate interest — where processing is necessary for platform security, fraud prevention, or service improvement, balanced against your rights • Legal obligation — where we are required to process data by applicable law You may withdraw consent at any time without affecting the lawfulness of prior processing.
10. Payments
Purchases in the iOS app are processed via the Apple App Store. Purchases on the web (including credit top-ups on app.noteecard.com) are processed via Stripe. Noteecard does not collect, store, or have access to your credit card number, CVV, or banking details. Payment card data is handled by the respective payment processor (Apple or Stripe). We receive only a transaction confirmation and a tokenized reference for record-keeping — for example an Apple transaction ID or a Stripe Checkout session / payment reference.
11. Data Storage & Security
Your data is stored on secure infrastructure. We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and monitoring. While no system can guarantee absolute security, we take reasonable and appropriate measures to protect your information.
12. Data Retention
We retain your personal data only as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Cards, Notes, Tasks, Journal entries, Inbox pins, and related reminder metadata are retained for as long as the platform operates, until you delete them, or until they are removed due to a violation of our Terms of Service or applicable law. Account data is retained until you delete your account. Upon account deletion, your personal data is removed within a reasonable timeframe, except where retention is required by law.
13. Your Rights
Depending on your location, you may have rights to access, rectify, erase, port, restrict, or object to processing of your personal data, and to withdraw consent where processing is based on consent. For EU/EEA users, these rights are guaranteed under GDPR. For California residents, additional rights under CCPA/CPRA may apply. Noteecard does not sell personal data. To exercise any of these rights, contact us at info@noteecard.com. We will respond within the timeframe required by applicable law. Some rights may be limited where processing is necessary for legal compliance, security, fraud prevention, or enforcement of our Terms of Service.
14. International Transfers
Your data may be processed in countries other than your country of residence. Where required, we implement appropriate safeguards — such as Standard Contractual Clauses (SCCs) — to protect your data in accordance with applicable law.
15. Third-Party Services
We use a limited number of third-party services to operate Noteecard: • Apple App Store — payment processing for iOS purchases • Stripe — payment processing for web purchases and optional read-only finance data for connected developer accounts • Apple and Google — optional sign-in providers • Supabase — backend infrastructure, authentication, data storage, and realtime sync • OpenAI API — automated Ideas suggestions, only when you explicitly use Ideas • ipapi.co — IP-based country detection for standard cards • Unsplash — optional Daily Escape photography and attribution metadata • Sentry — app error reporting and technical diagnostics • GitHub — optional read-only developer activity connection • Resend — optional developer email connection for reading and sending email • Vercel — optional read-only developer connection for projects and deployment activity • Bundled audio and video — local Daily Escape media These providers process data in accordance with their own privacy policies. We do not share personal data beyond what is necessary for service delivery, unless required by law.
15A. Daily Content, Images & Quotes
The Home screen may display optional daily content such as Daily art, Famous quote, Eco Tips, Fun Facts, and World Days. This content is informational and is not created from, or personalized using, your private Notes, Tasks, Journal entries, or Cards. Artwork images may be sourced from public collections, including The Metropolitan Museum of Art’s Open Access collection, and may be mirrored or cached in Noteecard’s public content storage so they can load reliably. The artwork title, artist, year, source, license, and credit are shown where available. Noteecard does not claim ownership of third-party artwork or quote text. Loading this daily content does not require sending your personal information to the artwork or quote source. A cached image may remain on your device until the app or its cache is refreshed. You can disable individual daily-content categories in Settings → Home.
15B. Daily Escape Images (Unsplash)
Daily Escape may display one bright, portrait-oriented nature photograph per day. The image pool and attribution metadata are provided through Noteecard’s public content service and the image URLs are served from Unsplash’s image infrastructure. The app stores and displays the photographer’s name, photographer profile link, and Unsplash photo link so the required attribution remains visible. Tapping the attribution opens the original Unsplash page. Noteecard does not claim ownership of these photographs and does not upload your Notes, Tasks, Journal entries, Cards, account details, or other private content to Unsplash. Loading a Daily Escape image may expose routine network information such as your IP address to the service that delivers the image. Unsplash handles that information under its own privacy policy. Daily Escape image selection is not based on your private library, listening behavior, or personal profile. You can change the displayed Daily Escape photograph using Change. Changing the photograph does not create a personal Unsplash account, post anything to Unsplash, or grant Noteecard access to your Unsplash account.
15C. Daily Escape Music
Daily Escape includes a playlist of instrumental tracks bundled with the app. The player shows the title and artist for each track. Music attribution: • Meanwhile — Scott Buckley — CC BY 4.0 • Echoes — Scott Buckley — CC BY 4.0 • Uprising — Scott Buckley — CC BY 4.0 • Cinema — Alex-Productions — CC BY 3.0 • Disconnected — Pold — CC BY-SA 3.0 • Retroverse, Pt. 2 — Lucjo — CC BY-ND 3.0 • Paradox — KV — CC BY 3.0 The Scott Buckley tracks are credited to scottbuckley.com.au. The other tracks are credited to their respective artists and are distributed under the attribution terms stated above. The audio is included as an unmodified work; Noteecard does not claim ownership of any third-party music. Audio is played by the iOS player on your device. Because these tracks are bundled locally, Daily Escape music does not require an audio streaming request. Noteecard does not record the microphone, upload audio, collect a listening history, or use music playback to personalize your content. The Back, Play/Pause, and Next controls only control the Daily Escape player. The Daily Escape player does not use SoundCloud, SoundCloud OAuth, SoundCloud API credentials, or SoundCloud listening data. No SoundCloud account is created or connected when you use Daily Escape.
15D. Daily Escape Video Loops
Daily Escape may display short, muted nature video loops, including waves on a shore, incoming ocean waves, ocean waves, and a beach drone view. These MP4 clips are bundled locally with the app, loop on the device, and do not make a video-streaming request while you use Daily Escape. The clips are sourced from Coverr’s free stock video library and are used under its stated free-commercial-rights terms. Noteecard does not claim ownership of the video footage. The source library is Coverr (coverr.co), and the clips are used as unmodified background media. Video playback does not use the camera, microphone, location, or your private library. You can switch between Photo and Video and use Change to select another available video loop. Video playback is muted so it does not interfere with Daily Escape music.
15E. Developer Integrations
Noteecard offers optional connections for developers. These integrations are not required for Notes, Tasks, Journal, Cards, Inbox, Ideas, Daily, or Daily Escape. GitHub is used for read-only repository activity that you authorize. Noteecard does not use the connection to write to repositories. Sentry is used for viewing project errors and technical activity. Resend is used for reading receiving activity, reviewing sent messages, and sending email through the Resend account you connect. Stripe is used, when you choose to connect it, to show account balance, available and pending funds, customer records, recent payments, and payouts in My finance. Vercel is used, when you choose to connect it, to show projects and recent deployment activity. Access tokens and API credentials are handled through Noteecard’s secure backend; a Resend API key is also protected in the iOS Keychain. Vercel access uses OAuth and is limited to the read-only permissions granted during connection. Stripe uses a restricted API key beginning with rk_; the key is encrypted in the secure backend and is not returned to the iOS app. Noteecard requests only the data needed for the selected integration and does not create, edit, charge, refund, or transfer funds through these connections. You can disconnect an integration and request removal of its stored connection data from Developer settings. Each provider handles data under its own privacy policy and terms.
16. Children’s Privacy
Noteecard is not directed at children under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that a child has provided personal information without parental consent, we will take steps to delete that information promptly. If you believe a child has submitted personal data to us, please contact info@noteecard.com.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will revise the “Last updated” date above. Continued use of Noteecard after an update constitutes acceptance of the revised policy.
18. Contact
Questions about this Privacy Policy or your personal data: info@noteecard.com