Last updated: February 21, 2026
Privacy Policy
Your privacy is the foundation of SNotes. This policy explains what data we collect, why we collect it, and how we protect it — in plain language.
1. Data Controller
The data controller responsible for your personal data is:
2. Data We Collect
We collect only the data necessary to provide the Service:
- Account data: your email address and name when you register
- Note content: the notes and data you create within the app, stored encrypted on our servers
- Usage data: anonymized analytics such as feature interactions and session duration, to help improve the product
- Technical data: IP address, browser type, and device information for security and service operation
- Payment data: when paid plans are available, payment is processed by a PCI-DSS-compliant third party; we do not store full card details
3. Legal Basis for Processing
We process your data on the following legal bases under GDPR Art. 6:
- Contract (Art. 6(1)(b)): to create your account and provide the core note-taking service
- Legitimate interests (Art. 6(1)(f)): to ensure security, prevent fraud, and improve our product
- Consent (Art. 6(1)(a)): to send you product updates and newsletters — you can withdraw consent at any time
- Legal obligation (Art. 6(1)(c)): to comply with applicable law, including tax and accounting requirements
4. How We Use Your Data
We use your data to:
- Provide, maintain, and improve the SNotes platform
- Authenticate your account and protect it from unauthorized access
- Send you essential service communications (e.g. account confirmation, security alerts)
- Send product updates and newsletters, if you have given consent
- Comply with legal and regulatory obligations
We do not sell your data. We do not use your note content to train AI models. Ever.
5. Data Retention
We retain your account data and note content for as long as your account is active. If you delete your account, all associated personal data is permanently deleted within 30 days. Anonymized analytics data may be retained for up to 24 months. Backup copies may persist for up to 90 days before being fully purged.
6. Data Security
We take data security seriously. All data is transmitted via SSL/TLS encryption and stored encrypted at rest on servers located exclusively within the European Union (operated by Hetzner, a German provider). Access to production systems is restricted to authorized personnel and protected by multi-factor authentication.
7. Your Rights Under GDPR
As a data subject under the GDPR, you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: correct any inaccurate or incomplete data
- Erasure: request deletion of your personal data ("right to be forgotten")
- Portability: receive your data in a machine-readable format
- Restriction: request that we limit how we process your data
- Objection: object to processing based on legitimate interests
- Withdraw consent: unsubscribe from marketing at any time
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
8. Cookies
We use only strictly necessary cookies to operate the Service — specifically, a session cookie to keep you logged in and a CSRF token for security. We do not use advertising cookies or third-party tracking cookies.
9. Subprocessors & Third Parties
We use a limited number of third-party services, all bound by data processing agreements and GDPR-compliant:
- Hetzner Online GmbH (Germany, EU) — server infrastructure
- netcup GmbH (Germany, EU) — server infrastructure
- Cloudflare, Inc. (global) — DNS and DDoS protection
- BunnyWay d.o.o. (bunny.net) (Slovenia, EU) — encrypted media file storage on EU servers (Frankfurt/Falkenstein, Germany and Stockholm, Sweden)
- MailerLite (Ireland, EU) — newsletter delivery. We share only your email address for the sole purpose of sending you newsletters you have subscribed to. No other personal data is transmitted. You can unsubscribe at any time via the link in every email.
- Paddle — payment processing and merchant of record (when paid plans are available), subject to their own privacy policy
We do not share your personal data with any other third parties, except where required by law.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice within the Service. The date at the top of this page always reflects the most recent update.
11. Contact
For any privacy-related questions or requests, please contact us at [email protected].