Privacy Policy
Last updated: August 4, 2026
1. Introduction
This Privacy Policy explains how Noteecard ("we", "our", or "us") collects, uses, stores, and protects your personal information when you use noteecard.com or our mobile applications.
We are committed to transparency and to handling your data responsibly, in compliance with applicable data protection laws including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
By using Noteecard, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of the service.
2. Information We Collect
We collect information in two ways: information you provide directly, and information collected automatically when you use our services.
3. Information You Provide
When you create an account, use our services, or contact us, you may provide:
- Name and email address
- Account credentials (managed via secure authentication providers)
- Content you create within Noteecard (cards, messages, notes, and related library items)
- Contact form submissions and support requests
- Payment-related information (processed via Apple App Store on iOS and Stripe on the web — we never store card details)
- Optional Gmail connection and Contacts access in the iOS app (see Section 4)
4. Optional Gmail (Email in the iOS app)
Email in the Noteecard iOS app is optional and supports Gmail only. It is separate from “Continue with Google” / Google sign-in used for your Noteecard account.
If you turn on Gmail in Settings → Gmail, Google shows a separate consent screen. With your permission, Noteecard may:
- Read messages and metadata in your Gmail Inbox, Sent, Trash, and Spam (including subject, sender, recipients, dates, labels, body text, and attachments you open)
- Mark messages read, move them to Trash, or move them to Spam in your Gmail mailbox
- Send email from your Gmail account when you compose and tap Send
- Suggest recipients from Apple Contacts if you allow Contacts access on the device
How we handle Gmail data:
- Message content is fetched from Google’s Gmail API to display on your device so you can read and manage mail inside Noteecard
- We do not upload your email bodies, attachments, or mailbox contents to Noteecard servers
- OAuth access and refresh tokens are stored only in the iOS Keychain on your device
- We do not sell Gmail data, use it for advertising, or transfer it to third parties for independent use
- Noteecard’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements
You can disconnect anytime in Settings → Gmail (tokens are cleared). Signing out of Noteecard also clears Gmail tokens on that device. You may also revoke access in your Google Account permissions.
5. Automatically Collected Information
When you access Noteecard, we may automatically collect:
- IP address
- Browser type and version
- Operating system and device type
- Pages visited and navigation patterns
- Session duration and frequency of use
- Referral source
- On iOS with Gmail enabled: local unread checks and optional local notification banners on the device (not a copy of your mailbox on our servers)
This data is collected through analytics tools and is used in aggregated form to improve the service. For details on cookies specifically, please refer to our Cookie Policy.
6. Country Detection (IP-Based Location)
When you create a standard card, we may use your IP address to estimate your country of origin using a third-party geolocation service (ipapi.co). This is used solely to display the appropriate country flag on your card.
We do not store your precise location. Only the country code is retained, and only in connection with the card you create.
7. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve Noteecard's core functionality
- Authenticate your identity and manage your account
- Process payments securely through Apple (iOS) and Stripe (web)
- Personalize your experience and preferences
- Communicate important service updates
- Monitor platform security and prevent abuse
- Analyze aggregated usage data to improve performance
- Enforce our Terms of Service and community standards
- Detect, prevent, and investigate abuse, fraud, or security threats
- Remove or restrict content that violates our policies or applicable law
- If you opt in on iOS: show your Gmail mailbox in the app and send mail via Google’s Gmail API (Section 4)
We do not sell, rent, or trade your personal data to third parties. Gmail access is optional and can be disconnected anytime in the iOS app Settings.
8. Security & Encryption
This section describes how Noteecard protects encrypted card content.
Encryption of Encrypted Cards
- Encrypted cards are protected using AES-256 encryption.
- Messages are encrypted before storage.
- Only someone with the correct PIN can decrypt the message.
- We do not store your PIN.
Key Derivation
- The PIN is transformed into a cryptographic key using PBKDF2 with SHA-256 and 100,000 iterations.
- This makes brute-force attacks computationally impractical.
Zero-Knowledge Design
- Encrypted messages are stored in encrypted form.
- Noteecard cannot access or decrypt encrypted card content.
- If a PIN is forgotten, the message cannot be recovered. This is intentional to preserve privacy.
Infrastructure & Storage
- Encrypted content is stored securely.
- Authentication may use Apple or Google login providers.
- We do not store payment card details.
- Encrypted content may be removed if it violates our Terms of Service, even if its contents are not readable by us, based on metadata, reports, or abuse detection mechanisms.
- Optional Gmail tokens and on-device email display are described in Section 4.
9. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process personal data under the following legal bases:
- Consent — where you have given explicit permission (e.g. analytics, non-essential cookies, optional Gmail / Contacts on iOS)
- Contractual necessity — where processing is required to deliver the service you requested
- Legitimate interest — where processing is necessary for platform security, fraud prevention, or service improvement, balanced against your rights
- Legal obligation — where we are required to process data by applicable law
You may withdraw consent at any time without affecting the lawfulness of prior processing.
10. Payments
Purchases in the iOS app are processed via the Apple App Store.
Purchases on the web (including credit top-ups on app.noteecard.com) are processed via Stripe.
Noteecard does not collect, store, or have access to your credit card number, CVV, or banking details. Payment card data is handled by the respective payment processor (Apple or Stripe).
We receive only a transaction confirmation and a tokenized reference for record-keeping — for example an Apple transaction ID or a Stripe Checkout session / payment reference.
Apple and Stripe process payment data under their own privacy policies and terms.
11. Data Storage & Security
Your data is stored on secure infrastructure. We implement industry-standard security measures including:
- Encryption in transit (TLS) and at rest
- Access controls and authentication requirements for internal systems
- Regular security reviews and monitoring
While no system can guarantee absolute security, we take reasonable and appropriate measures to protect your information.
Gmail message content used for Email in the iOS app remains on-device / with Google as described in Section 4; it is not stored as mailbox content on Noteecard servers.
12. Data Retention
We retain your personal data only as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements.
Card content is retained for as long as the platform operates, until you choose to delete it, or until it is removed due to violation of our Terms of Service or applicable law. Account data is retained until you delete your account.
Gmail OAuth tokens are kept on the device only while Gmail remains connected (or until you sign out). Disconnecting Gmail or signing out clears those tokens from the Keychain.
Upon account deletion, your personal data is removed within a reasonable timeframe, except where retention is required by law.
13. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data
- Portability — request your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent
For EU/EEA users, these rights are guaranteed under GDPR. For California residents, additional rights under CCPA/CPRA may apply, including the right to know what personal information is collected and the right to opt out of the sale of personal information. Noteecard does not sell personal data.
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law.
Please note that the exercise of certain rights may be limited where processing is necessary for legal compliance, security purposes, fraud prevention, or enforcement of our Terms of Service.
14. International Transfers
Your data may be processed in countries other than your country of residence, including countries that may not provide the same level of data protection.
Where required, we implement appropriate safeguards — such as Standard Contractual Clauses (SCCs) — to ensure your data is protected in accordance with applicable law.
15. Third-Party Services
We use a limited number of third-party services to operate and improve Noteecard:
- Apple App Store — payment processing (iOS)
- Stripe — payment processing (web)
- Google Analytics — aggregated traffic analysis
- Pikapod (Umami) — privacy-focused analytics
- ipapi.co — IP-based country detection
- Social login providers (Google, Apple) — authentication
- Google Gmail API — optional mailbox read, manage, and send in the iOS app when you enable Gmail (separate OAuth; see Section 4)
- Apple Contacts — optional recipient suggestions when composing mail in the iOS app
These providers process data in accordance with their own privacy policies. We encourage you to review them.
We do not share personal data beyond what is necessary for service delivery, unless required by law.
16. Children's Privacy
Noteecard is not directed at children under the age of 16 (or the applicable age of consent in your jurisdiction).
We do not knowingly collect personal data from children. If we become aware that a child has provided personal information without parental consent, we will take steps to delete that information promptly.
If you believe a child has submitted personal data to us, please contact [email protected].
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs.
When we make changes, we will revise the "Last updated" date at the top of this page. Continued use of Noteecard after an update constitutes acceptance of the revised policy.
18. Contact Information
If you have questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact: