Privacy policy
Your thoughts are personal. We treat them that way.
Effective September 9, 2026
This policy explains how Notes to Self collects, uses, stores, and shares information when you use the app or website.
Information you provide
Notes to Self may process journal text, voice recordings, transcripts, reflections, prompts, and other content you choose to create. When you use Sign in with Apple, we receive an Apple account identifier and, if you choose to share it, your email address. If you join the website waitlist, we store your email address in our private website database for beta access and launch updates. We use FormSubmit to send signup notifications to our team. Earlier beta forms also collected a name and use case.
Optional context
With your permission, the app can read limited Health, Calendar, and Location information to add context to entries and help identify patterns. This may include sleep, workouts, steps, active energy, exercise time, mindful minutes, resting heart rate, heart-rate variability, nearby calendar events, and an approximate place label. These permissions are optional and can be disabled in the app or device settings.
Notes to Self does not write data to Apple Health.
How information is used
We use information to authenticate your account, transcribe recordings, generate reflections and patterns, sync entries across your Apple devices, provide protected sharing when you request it, operate the beta program, troubleshoot errors, and improve reliability and safety.
AI and service providers
After you give in-app consent, audio or journal text is securely sent through our backend to OpenAI for transcription and reflection features. If you enable them, compact Health, Calendar, and Location context may be included in those requests. We ask OpenAI not to store generated reflections as retrievable application records. OpenAI may retain abuse-monitoring logs for up to 30 days under its standard API data controls. OpenAI processes this information on our behalf to provide the requested feature under contractual privacy and security protections; we do not permit it to use journal content for advertising. You can withdraw AI-processing consent in the app at any time. We also rely on Apple for Sign in with Apple, iCloud and CloudKit syncing, and device permissions.
Storage and sharing
Kept entries are stored on your device and may sync through your private iCloud account. Account credentials are stored in the device Keychain. We do not sell personal information, use journal content for targeted advertising, or make entries public. A protected share is created only when you choose to create one; shared content is encrypted before it is uploaded.
Account security and free access
The current app’s core journal features are free. Our backend stores a derived account identifier, session-revocation state, and usage counts to protect your account and limit misuse. Security state may remain after deletion to keep previously issued sessions and links revoked.
Our hosting providers also process technical request information, including request identifiers, response times, status codes, and error details, to operate the service and diagnose problems. These records may be associated with requests from your account. We do not use usage counts or diagnostic records for advertising or tracking across other companies’ apps and websites.
Retention and deletion
Information is retained only as long as needed to provide the app, comply with legal obligations, resolve disputes, and maintain security. You can delete individual entries at any time. You can also permanently delete your account from Profile > Account > Delete account in the app. Account deletion removes your journal entries, saved audio, synced Notes to Self journal data, app credentials, and complimentary-access record. It cannot be undone.
New encrypted protected-share links are associated with a derived account identifier so account deletion can revoke them. They expire after 30 days. Older links cannot be matched to an account. Older server-hosted shares expire automatically; older self-contained links cannot be remotely revoked. A recipient may retain content they have already opened or copied.
Children
Notes to Self is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Security and changes
We use reasonable administrative, technical, and organizational safeguards. No method of storage or transmission is completely secure. We may update this policy as the product changes and will revise the effective date when we do.
Contact
Questions or deletion requests can be sent to support@lumineva.ai.