Privacy Policy

Last updated: April 9, 2026

1. Introduction

AtanNote ("we," "us," or "our") operates the AtanNote application and related services across web, iOS, and Android platforms (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using AtanNote, you agree to the collection and use of information in accordance with this policy. If we make material changes, we will notify you via email or an in-app notice before the changes take effect.

2. Information We Collect

2.1 Account Information

When you create an account we may collect:

  • Email address — provided directly or via Google Sign-In (OAuth)
  • Display name — chosen by you during signup
  • Profile photo — optionally uploaded from your device's photo library
  • Authentication tokens — session tokens managed by our authentication provider

2.2 Guest Accounts

You may use AtanNote as a guest without providing an email address. Guest accounts store a display name only and are limited to 5 notes. Guest data is retained until the account is upgraded to a full account or deleted.

2.3 Voice & Audio Data

When you use our voice recording features, your device records audio using the microphone. Audio recordings are transmitted to our servers for transcription via Google Gemini. Audio data is processed in memory and is deleted immediately after transcription is complete. We do not retain audio files on our servers. Only the resulting text transcription is saved.

2.4 Notes, Chat & AI-Generated Content

We store the following content you create or that is generated on your behalf:

  • Notes (original transcriptions and AI-refined text)
  • Note version history
  • Vector embeddings generated for semantic search
  • AI Assistant chat sessions (messages, titles, summaries, and any images you share in chat)

2.5 User Preferences

We store your preferences to personalize the Service, including:

  • Default transcription language
  • Preferred writing style
  • Selected use case (from onboarding)
  • Theme preference (light/dark mode)

2.6 Usage & Analytics Data

We collect limited analytics data to improve the Service. This includes:

  • Onboarding completion events (language selected, use case, duration)
  • Feature usage patterns
  • Device type and operating system

Analytics are collected using our own first-party system hosted on our infrastructure. We do not use third-party analytics services such as Google Analytics, Firebase Analytics, Mixpanel, or similar tools.

2.7 Payment & Subscription Information

Payments are processed by Apple App Store (iOS), Google Play (Android), or Stripe (web). We never receive or store your full credit card number. We may receive limited billing details (e.g., last four digits, billing country) from these providers for record-keeping.

Subscription status, plan type, and billing period dates are stored in your account profile to manage your access to premium features.

2.8 Feedback Data

If you submit feedback through the app, we collect your star rating, message text, and the screen from which you submitted it. Feedback is linked to your user account.

2.9 Device Permissions

AtanNote may request the following device permissions:

  • Microphone — required for voice recording and transcription
  • Photo Library (iOS) — used only if you choose to set a profile photo
  • Notifications (Android) — used only to display a persistent notification during active background recording

We do not request access to your location, contacts, calendar, camera, or health data.

3. How We Use Your Information

  • Transcribe audio recordings into text using AI
  • Refine and format your notes using AI-powered writing styles
  • Generate vector embeddings to power semantic search and the AI Assistant
  • Provide AI Assistant chat functionality with context from your notes
  • Deliver, maintain, and improve the Service
  • Process payments and manage subscriptions
  • Provide customer support
  • Analyze aggregated usage patterns to improve features and performance
  • Send important service-related communications

4. Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:

  • Contract performance — to provide the Service you signed up for (account management, transcription, note storage)
  • Legitimate interests — to improve the Service, prevent fraud, and ensure security
  • Consent — where you have given explicit consent, such as granting microphone access or opting into optional features
  • Legal obligation — to comply with applicable laws and regulations

5. AI Processing & Third-Party AI Services

AtanNote uses third-party AI services to process your content. Specifically:

  • Google Gemini API — processes your audio recordings for transcription, refines text, and generates vector embeddings for search. Audio and text are processed via the API in real-time.
  • Brave Search API — when the AI Assistant performs web searches on your behalf, your search queries are sent to Brave Search.

Your data sent to these AI services is processed according to their respective API terms and is not used to train their AI models. Data is transmitted securely via encrypted connections and is not retained by these providers beyond the duration of the API request.

6. Third-Party Service Providers

We share data with the following third-party service providers to operate the Service:

ProviderData SharedPurpose
SupabaseAccount data, notes, embeddings, chat messages, analytics eventsAuthentication, database, file storage, and serverless functions
Google GeminiAudio recordings, note textTranscription, text refinement, embedding generation
Brave SearchSearch queries from AI AssistantWeb search for AI Assistant responses
RevenueCatAnonymous user ID, purchase receipts, subscription statusIn-app subscription management (iOS & Android)
StripeEmail, payment detailsPayment processing (web)
ApplePurchase receiptsIn-app purchase processing (iOS)
Google PlayPurchase receiptsIn-app purchase processing (Android)
Google Sign-InEmail address, authentication tokensAccount authentication (OAuth)

We do not sell your personal data to any third party. Data shared with service providers is limited to what is necessary for them to perform their function.

7. Data Storage & Security

Your data is stored on Supabase infrastructure with encryption in transit (TLS 1.2+) and at rest (AES-256). We implement row-level security policies to ensure your data is only accessible by you. Audio recordings are processed in memory and deleted immediately — they are never written to persistent storage on our servers.

On your device, sensitive data such as authentication tokens and preferences are stored using platform-native encrypted storage (Keychain on iOS, Encrypted SharedPreferences on Android). Cached note data is stored locally in an encrypted database.

While no method of electronic transmission or storage is 100% secure, we strive to use commercially acceptable means to protect your information.

8. Data Retention & Deletion

  • Notes & chat history — retained as long as your account is active. You may delete individual notes or chat sessions at any time from within the app.
  • Audio recordings — deleted immediately after transcription. Not stored on our servers.
  • Analytics data — retained for up to 12 months, then automatically purged.
  • Feedback — retained for product improvement purposes until you request deletion.
  • Account data — if you delete your account, all your personal data, notes, chat history, and embeddings are removed from our systems within 30 days. Some data may persist in encrypted backups for a limited period before being purged.

9. Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate or incomplete data
  • Deletion — request that we delete your personal data
  • Export — receive your data in a portable, machine-readable format
  • Restrict processing — request that we limit how we use your data
  • Data portability — transfer your data to another service
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time

You can exercise your right to deletion and data export directly from the Settings page within the app. For all other requests, contact us at support@atannote.com. We will respond within 30 days.

10. International Data Transfers

Your data may be transferred to and processed in the United States or other countries where our service providers operate. If you are located in the European Economic Area (EEA) or the United Kingdom, we ensure that appropriate safeguards, such as Standard Contractual Clauses, are in place for any transfer of personal data outside these regions.

11. Cookies & Local Storage

AtanNote uses browser local storage and cookies solely for essential functionality:

  • Authentication session tokens
  • Theme preference (light/dark mode)

We do not use third-party advertising cookies, tracking pixels, or fingerprinting technologies. We do not respond to "Do Not Track" browser signals because we do not engage in cross-site tracking.

12. Advertising & Tracking

AtanNote does not display advertisements. We do not use advertising identifiers, tracking pixels, or any form of cross-app or cross-site tracking. We do not share your data with advertising networks or data brokers.

13. Children's Privacy

AtanNote is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA). If we become aware that we have collected data from a child under the applicable age, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at support@atannote.com.

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, how it is used, and what categories of third parties receive it
  • Request deletion of your personal information
  • Opt out of the sale or sharing of your personal information
  • Non-discrimination for exercising your privacy rights

AtanNote does not sell or share your personal information with third parties for advertising or cross-context behavioral advertising purposes. To exercise your California privacy rights, contact us at support@atannote.com.

15. Note Sharing

You may share individual notes via a unique link. Shared notes are accessible to anyone with the link without requiring authentication. You can revoke sharing at any time by disabling the share link from within the app.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by sending an email to the address associated with your account or by displaying a prominent notice within the Service. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

17. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:

AtanNote
Email: support@atannote.com