Privacy Policy
Last updated: August 14, 2026
NoteSpark ("we", "us", "our") operates the NoteSpark web application (the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how long we keep it, and the rights you have over it. It applies to users worldwide and includes specific disclosures for users in the European Economic Area (EEA), the United Kingdom, Switzerland, and California (USA).
We process your data only as necessary to provide the Service, and we design the Service to minimize what we retain. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
- Account information: email address (when you sign up).
- Content you submit: audio/video files you upload, audio you record, URLs you provide for processing, and text you paste.
- Communications: messages you send to our support team.
1.2 Information Automatically Collected
- Usage data: browser type, pages visited, time spent, referring URL, and anonymized IP address (truncated).
- Task metadata: task status, processing duration, media duration, and API cost (for billing and abuse prevention). We do not store the content of processed tasks beyond the retention period described below.
- Essential cookies and local storage: authentication tokens required to keep you signed in. See Section 6.
1.3 Payment Information
Payments are processed by our payment processors (Dodo Payments and/or Stripe). We do not store your credit card number. The processors receive only the information necessary to process the transaction, governed by their own privacy policies.
2. How We Use Your Information
- To provide and maintain the Service (transcription, content generation, export).
- To process subscriptions and send billing-related notices.
- To monitor and improve the Service (aggregated, anonymized usage statistics).
- To detect, prevent, and address fraud, abuse, and technical issues.
- To respond to your support requests.
We do not sell your personal data. We do not use your submitted content to train AI models. We do not share your content with third parties except as described in this policy (e.g., processing by AI providers strictly to perform your request, and where required by law).
3. Data Retention and Deletion
3.1 Submitted Files (Audio/Video)
- Original media files are stored temporarily in encrypted object storage only for the duration of processing.
- Files are permanently deleted immediately after processing completes (or upon task failure).
- A storage lifecycle rule enforces deletion of any residual files within 24 hours as a safety net.
3.2 Generated Content (Transcripts and Drafts)
- Free accounts: generated content (transcripts, structured articles, platform drafts) is retained for 7 days, then permanently deleted.
- Pro accounts: generated content is retained for 90 days, then permanently deleted.
- You can delete any task and its generated content at any time from your dashboard.
- We recommend exporting your content to Markdown (e.g., to your Obsidian vault) for permanent local storage.
3.3 Account Data
- Your email and subscription records are retained while your account is active.
- When you delete your account, all personal data (including all tasks and outputs) is permanently deleted within 30 days. Backup copies are purged within 90 days.
3.4 Processing by Third-Party AI Providers
- We use third-party AI providers (Groq and OpenAI) to perform transcription and text generation.
- These providers process your content under their data processing agreements:
- Groq: zero data retention, does not train on your data.
- OpenAI: API data is not used for training; retained for up to 30 days for abuse monitoring, then deleted.
- We do not use providers that train on your content by default.
4. Where Your Data Is Processed
- Our primary infrastructure (database, file storage, application hosting) is provided by Supabase and Cloudflare, with data stored in Singapore (Asia-Pacific) data centers.
- AI processing (transcription and text generation) is performed by US-based providers (Groq, OpenAI).
- When you submit content, it is transmitted to these US-based AI providers solely for processing your request. These providers do not retain your content beyond their abuse-monitoring periods and do not use it to train their models.
- If you are located in the European Economic Area, United Kingdom, or Switzerland, your data is transferred to Singapore and the United States under appropriate safeguards (Standard Contractual Clauses where applicable).
5. Your Rights
5.1 GDPR (EEA/UK/Switzerland Users)
Legal bases. We process personal data on the following grounds under the GDPR: performance of a contract with you (providing the Service), our legitimate interests (service security, fraud prevention, and product improvement), your consent (where we ask for it), and compliance with legal obligations.
You have the right to:
- Access your personal data.
- Correct inaccurate data.
- Erase your data ("right to be forgotten") — you can delete your account in Settings, which removes all your data.
- Restrict or object to processing.
- Data portability — export your generated content as Markdown at any time; request a machine-readable copy of your account data.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at privacy@notespark.dev. We respond within 30 days.
5.2 CCPA/CPRA (California Users)
You have the right to:
- Know what personal information is collected, used, and disclosed.
- Request deletion of your personal information.
- Opt out of the "sale" or "sharing" of personal information — we do not sell or share your data.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information — we do not process sensitive personal information beyond what is necessary to provide the Service.
- Not be discriminated against for exercising your rights.
To submit a CCPA request, contact us at privacy@notespark.dev or delete your account directly in Settings. We will verify your identity and respond within the timeframe required by law (generally 45 days, extendable as permitted).
5.3 Data Deletion
You can delete your account and all associated data directly from the Settings page. This is an immediate, automated action — no support ticket required. Deletion is verifiable: after deletion you will no longer be able to sign in with that account.
6. Cookies and Local Storage
- We use essential cookies for authentication (session tokens).
- We do not use advertising or third-party tracking cookies.
- We may use privacy-friendly, cookieless analytics (if any) that do not identify you personally.
- If we ever add non-essential cookies, we will show a cookie consent banner and require your consent (GDPR) / provide opt-out (CCPA) as applicable.
7. Security
We implement industry-standard measures including:
- Encryption in transit (TLS 1.2+).
- Encrypted object storage for temporary files.
- Row-level security in our database — you can only access your own data.
- Signed, time-limited upload URLs.
- Principle of least privilege for service credentials.
No method of transmission over the Internet is 100% secure. We strive to use commercially acceptable means to protect your data but cannot guarantee absolute security.
8. Children's Privacy
The Service is not intended for users under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware of such collection, we will delete the data promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the Service at least 7 days before they take effect. Your continued use after the effective date constitutes acceptance.
10. Contact Us
For privacy questions or data requests:
- Email: privacy@notespark.dev
- DMCA / copyright notices: dmca@notespark.dev
Data Controller: NoteSpark. For EEA/UK users, you may also contact your local supervisory authority if you believe your data protection rights have been violated.