NeoNote

Legal

Privacy Policy

Last updated: June 2025 · Beta version

Overview

NeoNote is built on a simple principle: your notes are encrypted before they leave your device. We never have access to the content of your notes. This policy explains what we do collect, why, and how.

1. What we collect

Account data: Your email address and hashed password, used to authenticate you. We do not store your password in plain text.

Encrypted note data: Your note content is encrypted client-side with a key derived from your password before being stored. We store the encrypted ciphertext — we cannot read it.

Note metadata: Unencrypted metadata such as note titles, drive names, creation timestamps, and update timestamps. This metadata is necessary for the app to function (e.g. sorting, navigation).

Usage data: Basic server logs (IP address, request path, timestamp) retained for up to 30 days for security and debugging. We do not use analytics tools that track individual behaviour.

2. How we use your data

We use your data solely to provide the NeoNote service: storing and syncing your notes, sending authentication emails, and maintaining account security. We do not sell your data, share it with advertisers, or use it for profiling.

3. Third-party services

Supabase: We use Supabase (supabase.com) for database storage, authentication, and file storage. Your encrypted data is stored in Supabase's infrastructure. Supabase is GDPR-compliant and SOC 2 Type II certified. See their privacy policy.

Google Drive (optional): If you connect Google Drive for backups, NeoNote requests permission to create files in your Drive. Backups are encrypted before upload — we cannot read them. You can revoke access at any time from your Google account settings or from NeoNote's Settings → Backup.

4. Data retention

Your data is retained for as long as your account is active. When you delete your account, your data is permanently deleted within 30 days. Encrypted backups you have uploaded to Google Drive are not deleted by us — you control those files.

5. Your rights

You have the right to access, export, or delete your data at any time. You can export your notes as a ZIP file from Settings → Backup. To delete your account, contact us at hello@austinacevedo.com or use the account deletion option in Settings (when available).

If you are in the EEA or UK, you may also have rights under GDPR to data portability and to lodge a complaint with your supervisory authority.

6. Cookies

NeoNote uses only functional cookies required for authentication (session tokens set by Supabase). We do not use advertising, tracking, or analytics cookies.

7. Security

All data is transmitted over HTTPS. Note content is encrypted client-side using AES-256-GCM with a key derived from your password via PBKDF2 before transmission. We apply standard security headers and review dependencies for vulnerabilities.

8. Children

NeoNote is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have collected data from a child under 13, contact us and we will delete it promptly.

9. Changes to this policy

We will notify you by email at least 14 days before material changes to this policy take effect. The “Last updated” date at the top always reflects the current version.

10. Contact

Privacy questions or requests: hello@austinacevedo.com