Privacy Policy
Effective 27 July 2026
This explains what NotesLite+ collects when you use NotesLite+, why we collect it, and who else touches it. We have tried to make it specific rather than reassuring - vague privacy policies are usually hiding something.
What we collect
If you only use guest mode: your workspaces and Quick Notes are stored on your device, not on our servers. What reaches us is limited to ordinary request data - IP address, browser type, pages viewed - and anything you deliberately send, such as running an AI summary.
If you create an account, we hold:
- Your email address, display name and profile details. Passwords are stored as bcrypt hashes - we cannot read them.
- If you sign in with Google: your Google account identifier, email and name. We do not receive your Google password.
- Your workspace content - Editor documents, Boards, Canvases - plus uploads and Quick Notes.
- Two-factor secrets and hashed backup codes, if you enable 2FA.
- Collaboration data: invites you send or receive, workspace roles, and your activity feed.
- Plan and billing status. Card numbers go to our payment providers, never to us.
- Usage and diagnostic data: sign-in times, AI runs and their cost, error reports.
If you pre-registered earlier: we no longer run a waitlist, but we still hold the email address you submitted at the time and which part of the page you submitted it from. Nothing else. Ask us and we'll delete it.
Why we use it
- To run the service: signing you in, storing and syncing your work, sending invites.
- To enforce plan limits and process subscription payments.
- To keep accounts secure - detecting abuse, rate-limiting, and supporting two-factor authentication.
- To send transactional email you asked for: verification, password resets, invites, and the single email telling you V4 has opened.
- To understand aggregate usage so we know which features earn their place.
We do not sell your personal data, and we do not use your workspace content to train our own models or anyone else's.
What the AI features send, and where
Nothing is sent to an AI provider until you actively run a summary or open the assistant. There is no background processing of your workspaces.
When you do run one, the text of that workspace's active views is serialised and sent to whichever provider answers first from our fallback chain - currently OpenAI, Groq, Google Gemini and Anthropic Claude. Content beyond roughly 12,000 characters is truncated before sending. We use these providers under their API terms, which do not permit training on data sent through the API.
Summaries are cached against a hash of the content so that regenerating identical content does not re-send it. If you would rather no workspace text ever leave our infrastructure, do not use the AI features - the rest of the product works without them.
How long we keep it
- Account and workspace data: for as long as your account exists.
- Deleted workspaces and deleted accounts: removed from live systems promptly, and from encrypted backups within 30 days as those backups age out.
- Pre-registration emails: until V4 opens, or until you ask to be removed - whichever comes first.
- Billing records: kept as long as tax and accounting law requires, typically several years.
- Diagnostic logs: a short rolling window, normally under 90 days.
Your rights over your data
Whatever country you are in, you can ask us to give you a copy of your data, correct it, or delete it, and you can object to a particular use. Most of this you can do yourself from account settings; for anything you cannot, write to hello@noteslite.xyz and we will respond within 30 days.
If you are in the UK, EU or a similar jurisdiction, you also have the right to complain to your data protection authority. We would appreciate the chance to fix it first.
Security
Traffic is encrypted in transit. Passwords are bcrypt-hashed, two-factor authentication with single-use backup codes is available on every account, and access to production data is limited to those who need it.
No service is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant regulator as the law requires.
Children
NotesLite+ is not intended for children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
Where your data is processed
Our providers operate internationally, so your data may be processed outside the country you live in - including in the United States and the European Union. Where the law requires a transfer safeguard, we rely on our providers' standard contractual clauses.
Changes to this policy
We will update this page when what we do changes, and we will change the effective date at the top. For material changes - a new category of data, or a new purpose - we will tell you by email or in the app before it takes effect. The Terms of Service cover the rest of the relationship.
