Noteshik

Privacy Policy

Privacy Policy

We built Noteshik to be a private note-taking tool you can trust. Your notes belong to you — not us. This policy explains exactly what data we collect, why, and how you can control it.

GDPR Compliant CCPA Compliant Last updated: February 26, 2026  ·  Effective: February 26, 2026

Contents

The short version: We collect only what is necessary to run Noteshik. We never sell your data. We never read your notes. Your data is stored on servers we control in Germany. You can delete your account and all data at any time.

1. Who We Are

Noteshik is a note-taking application developed and operated by Traffic2uMarketing. Our backend API and data storage is hosted at noteshik.9gg.app on dedicated servers in Germany.

For all privacy-related inquiries, data access requests, or concerns, please contact our privacy team at support@9gg.app (use the contact form).

When this policy refers to "Noteshik", "we", "us", or "our", it means Traffic2uMarketing as the data controller for your personal data.

2. Data We Collect

We collect the minimum data necessary to provide a reliable, synchronized note-taking service. Here is a complete list:

Account Data

Note Content

Voice Transcription

Device & Sync Data

Security & Server Logs

What We Do NOT Collect

3. How We Use Your Data

Purpose Data Used
Providing the service — storing and syncing your notes Note content, account data, device IDs
Authentication — verifying your identity on login Email, hashed password, JWT tokens
Email verification — confirming account ownership Email address, verification tokens
Voice transcription — converting speech to text Audio (in transit only, not stored)
Security monitoring — detecting and preventing abuse IP address, auth event logs
Security notifications — alerting you to suspicious activity Email address
Customer support — responding to your inquiries Email, contact form data
Service improvements — fixing bugs and improving features Anonymized error logs and aggregate usage patterns (no note content)

We do not use your note content for advertising, AI model training, behavioral profiling, or any purpose other than serving it back to you.

5. Third-Party Services

We use a small number of third-party services to operate Noteshik. We do not use any advertising networks, analytics platforms, or social SDKs.

Groq (Voice Transcription)

When you record audio for transcription, the audio file is transmitted to Groq's API (api.groq.com) over HTTPS using the whisper-large-v3 model. Groq processes the audio to produce a text transcript, which is returned to our server and saved as your note text. Audio data is not retained by Groq after processing per their API terms. Groq is bound by standard contractual clauses for data protection. Review Groq's Privacy Policy for details.

Contabo GmbH (Server Infrastructure)

Our application servers and PostgreSQL database are hosted on dedicated VPS infrastructure provided by Contabo GmbH, located in Frankfurt, Germany. Contabo operates under EU data protection law. Your data never leaves EU infrastructure during normal operations. Review Contabo's Privacy Policy for details.

Let's Encrypt (SSL Certificates)

SSL/TLS certificates are issued by Let's Encrypt (Internet Security Research Group). Certificate issuance involves your domain name only — no personal data. Review Let's Encrypt's Privacy Policy.

Google Play (Billing)

If you purchase a Noteshik subscription through the Google Play Store, payment processing is handled entirely by Google. We receive only a subscription status confirmation — we do not receive your payment card details. Review Google's Privacy Policy for billing data handling.

We do not integrate: Facebook SDK, Google Analytics, Firebase Analytics, Crashlytics, Mixpanel, Segment, Amplitude, Sentry, or any other third-party analytics or crash reporting service that would access your note data.

6. Data Storage & Retention

Where Your Data Is Stored

All user data (notes, account information, device records) is stored in a PostgreSQL database on a dedicated VPS server located in Frankfurt, Germany, operated by Contabo GmbH. The database is not accessible from the public internet. Backups are encrypted and also stored within Germany.

On-Device Storage

The Noteshik app stores a local copy of your notes in SQLite on your device. This enables offline access. This on-device data is protected by your device's own security and encryption features. Deleting the app will remove local data from your device, but your data remains on our servers until you delete your account.

Data Retention Schedule

Data Type Retention Period
Active account data (notes, folders, tags) Retained for the lifetime of your account
Deleted notes (soft-deleted) Immediately soft-deleted; permanently purged from database and backups within 30 days
Account data after account deletion Deleted immediately on self-service request; any residual backups purged within 30 days
Authentication / security logs 30 days rolling window
Voice audio (transcription) Not stored — discarded immediately after transcription
Contact form submissions 12 months (for support resolution tracking)
Billing records (Google Play) Handled by Google; we retain only subscription status (active/inactive)

You can request early deletion of any of your data at any time by contacting support@9gg.app (use the contact form).

7. Data Sharing & Disclosure

We do not sell, rent, or trade your personal data. We do not share your note content with any third party except where strictly required to deliver the service (Groq for audio transcription). We may disclose personal data only in the following limited circumstances:

We will never share your data with advertisers, data brokers, or anyone who would use it for purposes other than operating Noteshik.

8. Cookies & Local Storage

The Noteshik mobile app does not use browser cookies. It uses the following on-device storage mechanisms:

If you access any Noteshik web pages (such as this privacy policy) through a browser, our web server does not set any tracking cookies. We only use session-based CSRF protection tokens for form submissions, which are not used for tracking.

9. Your Privacy Rights

Regardless of where you live, we honor the following rights for all Noteshik users. If you are in the EEA/UK, these rights are guaranteed by the GDPR.

Right to Access Request a copy of all personal data we hold about you, including your account info, notes, and logs.
Right to Rectification Correct any inaccurate personal data (such as your email address) at any time through the app or by contacting us.
Right to Erasure Request deletion of your account and all associated data. We will process your request within 30 days and confirm when deletion is complete.
Right to Data Portability Request an export of your notes in a machine-readable format (JSON or plain text). Contact support to request an export.
Right to Restriction Ask us to pause processing your data while we address a concern, without requiring full deletion.
Right to Object Object to processing based on legitimate interests (e.g., security logging). We will honor objections unless we have compelling legitimate grounds.
Right to Withdraw Consent Where processing is based on consent (e.g., marketing emails), withdraw consent at any time without affecting prior processing.
Right to Lodge a Complaint If you are in the EEA, you have the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority).

To exercise any of these rights, email support@9gg.app (use the contact form) with the subject line matching your request (e.g., "Data Access Request" or "Account Deletion Request"). We will respond within 30 days. We may ask you to verify your identity before processing sensitive requests.

10. California Residents — CCPA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:

To submit a CCPA request, email support@9gg.app (use the contact form) with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days (extendable to 90 days with notice).

In the past 12 months, Noteshik has not sold any personal information to third parties.

11. Children's Privacy

Noteshik is not designed for or directed at children under the age of 13 (or under 16 in EEA countries where a higher age of digital consent applies). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has created a Noteshik account or provided us with personal data, please contact us immediately at support@9gg.app (use the contact form). We will promptly delete the account and all associated data upon verification of the request.

12. International Data Transfers

Your data is stored on servers located in Germany (EU) and is not routinely transferred outside the EU/EEA. The only case where data may leave the EU is when audio is sent to Groq's API for transcription processing. This transfer is protected by:

If you are concerned about this transfer, you can choose not to use the voice transcription feature. All other Noteshik features process data exclusively within Germany.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes, we will:

Your continued use of Noteshik after material changes become effective constitutes acceptance of the updated policy. If you disagree with changes, you have the right to delete your account before the effective date.

14. Contact Us

For any privacy-related questions, data access requests, or concerns about how we handle your information:

If you are a European resident and have an unresolved complaint, you may also contact your national Data Protection Authority. A list of EU DPA contact details is available at edpb.europa.eu.

15. Google Play Data Safety

The following information is disclosed for the Google Play Data Safety section, in compliance with Google Play policy requirements.

Data Collected

Data TypeCategoryRequired?Purpose
Email addressPersonal infoYesAccount creation, authentication, security alerts
User IDIdentifiersYesIdentify your account within the service
Notes & text contentUser contentYesCore service — storing and syncing your notes
Photos / imagesUser contentNo (optional)Image attachments added by the user to notes
Audio recordingsUser contentNo (optional)Voice-to-text transcription only; not stored after transcription
Device ID (random)Device identifiersYesMulti-device sync; not linked to hardware identifiers

Data Sharing with Third Parties

Audio only: When you use voice transcription, audio is sent to Groq (api.groq.com) for transcription. No other data is shared with third parties. Noteshik does not share your email, notes, or identifiers with any third party.

Security Practices

Independent security review: Noteshik has not undergone a third-party security audit at this time. We follow OWASP best practices and encrypt all data in transit and at rest.

16. Apple App Store Privacy Nutrition Label

The following summarizes the data Noteshik collects for the Apple App Store privacy label, as required by Apple's App Store Review Guidelines.

Data Used to Track You

None. Noteshik does not use any data to track you across apps or websites owned by other companies.

Data Linked to You

The following data types are collected and linked to your identity:

CategoryData TypeUse
Contact InfoEmail addressAccount, authentication, security
IdentifiersUser ID (internal)Account management, sync
User ContentNotes and text contentApp functionality (core service)
User ContentPhotos (optional)App functionality (note attachments)
User ContentAudio data (transient)Voice-to-text transcription; not stored

Data Not Linked to You

For full details, see our complete Privacy Policy. To exercise your privacy rights, contact support@9gg.app (use the contact form).