Privacy Policy
Last updated: 28 August 2026
Micnoteai is an iOS app that records or imports audio, PDFs and YouTube links, turns them into transcripts and AI-generated summaries, and lets you ask questions about your own notes in a chat. To do that, the content you give the app is uploaded to our backend server, processed there, and stored in your account so it can be synced back to your devices. We do not sell your personal information and the app contains no advertising or ad-tracking SDKs. This policy explains exactly what is collected, why, how long it is kept, and what rights you have over it.
1. Who we are
Micnoteai is developed and operated by Hamid Manafov, an individual developer based in Azerbaijan. For the purposes of the EU/UK General Data Protection Regulation (GDPR), Hamid Manafov is the data controller for the personal data described in this policy.
- Contact for all privacy matters: hamidmanafov7@gmail.com
- In-app support: support@micnoteai.com
- Country of establishment: Azerbaijan
- Postal address: available on request — write to the privacy address above
We are a one-person operation and are not required to appoint a Data Protection Officer. Privacy requests are handled directly by the developer at the email address above. No representative in the EU or the UK under Article 27 GDPR is currently appointed; please address all requests to hamidmanafov7@gmail.com, which is monitored by the developer personally.
2. Scope of this policy
This policy applies to the Micnoteai iOS application (bundle identifier com.hamidmanafov.Micnoteai, App Store ID 6746268622) and to the backend services it talks to at api.micnoteai.com and api.hamidmanafov.com. It also covers this website, micnoteai.com, where this policy is published.
It does not apply to:
- Apple. Your App Store account, App Store purchases, Sign in with Apple, iCloud and push notification delivery are governed by Apple's own privacy policy. We receive only what Apple passes to us, described in section 3.
- Google. If you choose Google Sign-In, Google's handling of your Google Account is governed by Google's privacy policy.
- Third-party content you point the app at. If you submit a YouTube link, the video is fetched and processed on our side; YouTube's own terms and privacy policy still apply to your use of YouTube.
- Other websites that this policy or the app may link to.
The app is not designed for or directed at children. You must be at least 13 years old to create an account, and at least 16 in the European Economic Area, the UK and Switzerland, or the higher minimum age of digital consent set by your own country (see section 13). We do not knowingly collect personal data from children; if you believe a child has created an account, contact us and we will delete it.
3. Information we collect
The table below lists every category of personal data the app handles, where it comes from, why we need it, and — for users in the EU/UK — the legal basis under Article 6 GDPR. The app has no email/password sign-up: you can only sign in with Apple or Google, so we never receive or store a password.
| Data category | Examples | Source | Why we collect it | Legal basis (GDPR) |
|---|---|---|---|---|
| Account & identity data | Account ID, email address, full name, locale, time zone, account creation/update dates, premium status | Returned by Apple or Google when you sign in, then stored by our backend. Sign in with Apple requests only your name and email; if you use Apple's "Hide My Email", we only ever see the relay address. | To create and identify your account, sync your notes across devices, and reply to support requests | Art. 6(1)(b) — performance of a contract (providing the app to you) |
| Authentication credentials | Access token, refresh token, user ID, single-use sign-in nonce and state values | Issued by our backend during sign-in; stored on your device in the iOS Keychain (accessible only after first unlock, this device only) | To keep you signed in securely and to protect sign-in against replay and interception attacks | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interests in account security |
| Audio recordings | .m4a recordings you make in the app or audio files you import, plus title, duration and language |
Created by you in the app (microphone) or chosen by you from your device. Uploaded to our backend for processing. | To transcribe and summarise the recording — this is the core function of the app | Art. 6(1)(b) — contract |
| Imported documents and links | PDF files you import; YouTube URLs you paste | Provided by you and uploaded/submitted to our backend. For a YouTube link, the app also asks Google directly for the video's title and thumbnail to show you a preview, which means your IP address reaches Google (see section 7). | To extract the text and produce a summary you asked for | Art. 6(1)(b) — contract |
| Note content (transcripts and summaries) | Transcript text and timed segments, AI summary, note title, detected transcript/summary language, speaker names you assign, folders, pin and archive flags, processing status and error details | Generated by our processing pipeline from the content you submit, plus edits you make. Stored on our backend and mirrored to an offline cache on your device. | To show you your notes, let you edit and organise them, and sync them between your devices | Art. 6(1)(b) — contract |
| AI chat content | The questions you type in a note's chat and the conversation history sent with them | Typed by you; sent to our backend, which forwards it to an AI provider together with the relevant note | To answer your questions about your own note | Art. 6(1)(b) — contract |
| Onboarding preferences | Preferred language, your stated goals, profession, and the display name you enter during onboarding | Entered by you. Stored locally on your device (UserDefaults); the display name may also be saved to your profile on our backend. |
To tailor the app's language and initial setup to you | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interests in a usable first-run experience |
| Device & technical data | Push notification device token and a hash used to detect re-registration, app badge count, app version, device model, operating system version, coarse locale/region | Generated by your device and the app; the push token comes from Apple Push Notification service | To deliver notifications about your notes finishing processing, and to keep the app working correctly across device and OS versions | Art. 6(1)(b) — contract (notifications you enabled); Art. 6(1)(f) — legitimate interests in operating the service |
| IP address | The IP address your device connects from | Seen by our servers on every request, as it is by any internet service | We do not store it. It is not written to any database table, and it is not used to identify or profile you. It appears only in short-lived rotating server logs. Usage limits and rate limiting are counted against your account, not your IP address. | Art. 6(1)(f) — legitimate interests in operating and protecting the service |
| Purchase & subscription data | Whether you have an active premium subscription, subscription product and status, usage limits and counters, an anonymous purchase identifier linked to your account | Apple's App Store handles the payment; subscription state reaches us through RevenueCat and our backend. We never receive your card number or billing address. | To unlock the features you paid for, enforce free-tier limits, and handle restore-purchases and refunds | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation (tax and consumer-law record keeping) |
| Product analytics & diagnostics | In-app events such as screens opened, notes created, paywall shown/dismissed, feature usage; a pseudonymous analytics ID; app and device metadata attached to those events | Collected by the app through PostHog, hosted in the EU (Frankfurt). Contains no recording audio, transcript text or chat content. | To understand which features are used, find crashes and broken flows, and decide what to improve | Art. 6(1)(f) — legitimate interests in improving and maintaining the app. You can switch analytics off in the app at any time (see section 16). |
| Support correspondence | Your email address and whatever you write to us | Sent by you by email | To answer your question or handle your privacy request | Art. 6(1)(f) — legitimate interests; Art. 6(1)(c) — legal obligation for rights requests |
Special-category data. We do not ask for and do not intentionally collect sensitive data (health, biometric, religious, political or sexual-orientation data). However, a recording is whatever you recorded — if you record a medical appointment or a personal conversation, that content may contain sensitive information about you or others. Please only record where you are legally allowed to (see section 5).
Using the app without an account. The app lets you browse onboarding as a guest, but no account is created and the app returns you to the sign-in screen. Practically, an account is required to create and process notes.
What we do not collect. We do not collect passwords, precise or background location, contacts, photos beyond the file you explicitly import, advertising identifiers (IDFA), or any data for advertising or cross-app tracking. The app contains no advertising SDKs.
4. How we use your information
We use the data described above only for the following purposes:
- To provide the core service — receiving your audio, PDF or YouTube link, transcribing it, generating a summary, and storing the resulting note in your account.
- To sync and display your notes across your devices, including keeping an offline copy on the device so your notes are readable without a connection.
- To run the AI chat so you can ask questions about a specific note.
- To manage your account — signing you in, keeping the session alive with refresh tokens, letting you sign out of one or all devices, and deleting your account when you ask.
- To handle subscriptions — checking whether you have premium, applying free-tier usage limits, and restoring purchases.
- To notify you when a note has finished processing or failed, if you allowed notifications.
- To keep the service secure and reliable — preventing replay attacks on sign-in, rate-limiting abuse, retrying failed uploads, and diagnosing errors.
- To improve the app — reviewing pseudonymous product analytics to see which features are used and where flows break.
- To comply with the law — meeting tax, accounting and consumer-protection obligations, and responding to valid legal requests.
We do not:
- sell or share your personal information for money or for cross-context behavioural advertising;
- use your recordings, transcripts, notes or chats to build advertising or marketing profiles;
- make decisions about you that produce legal or similarly significant effects using solely automated processing.
If we ever want to use your data for a genuinely new purpose that is not compatible with the purposes above, we will update this policy and, where the law requires it, ask for your consent first.
5. Audio recordings and transcription
Because audio is the most sensitive thing the app handles, here is precisely what happens to it.
Recording
Recording only starts when you tap record, and iOS requires you to grant microphone permission before the app can access the microphone. You can withdraw that permission at any time in iOS Settings → Privacy & Security → Microphone; without it, recording stops working but the rest of the app still functions. The app does not record in the background without your knowledge and does not listen when you are not recording.
Storage on your device
Each recording is written to disk as an .m4a file inside the app's own Documents area, in a folder scoped to your user account. These files are protected by iOS app sandboxing and the device's file-level encryption while the device is locked. The app does not add a second layer of its own encryption on top.
Backup. Once a recording has been uploaded successfully and is kept on the device, the app marks the file as excluded from backup, so it is not copied into your iCloud backup or an iTunes/Finder backup — the copy on our server is the one that survives a device restore. A recording that has not yet been uploaded (for example one still waiting in the offline queue) is not excluded, and is therefore included in your backups according to your own iOS backup settings. The offline note cache is likewise excluded from backup.
Keeping recordings on your device
By default, recordings stay on your device after they have been uploaded. This is deliberate: it lets the app play the original audio back to you instantly, without re-downloading it, and lets you check the transcript against what was actually said. You are in control of it — the app has a "keep local audio" switch in Settings. Turn it off and each recording is deleted from the device as soon as its upload has completed successfully; the note and its transcript are unaffected, and playback then streams from our server instead, which needs a connection. Turning the setting off also clears the audio-to-note mapping for your account. The setting belongs to the device, not to the account, so it applies to whoever is signed in on that device. The app never deletes a local recording before its upload has succeeded.
Upload and processing
To transcribe a recording, the app uploads the audio file to our backend (POST /notes/audio) over an encrypted HTTPS connection, together with the title, duration, language and an idempotency key that stops the same upload being processed twice. If you are offline or the upload fails, the file is placed in a pending-upload queue on the device and retried later — nothing is sent until a connection is available. Imported PDFs are uploaded the same way; a YouTube link is submitted as a URL and fetched on our side.
Retention of audio
On the server, the audio file is retained after processing so that the note can offer audio playback alongside the transcript. It is not deleted immediately after transcription. It is stored in Amazon S3 in the eu-central-1 region (Frankfurt, Germany), and there is no automatic age-based deletion — the file is kept for as long as the note exists. When you delete the note, or your account, the stored file is deleted with it. Playback links handed to your app are signed CloudFront URLs that expire after one hour, so a link cannot be shared or reused indefinitely.
On your device, unless you turn the "keep local audio" setting off, the app keeps a local copy of the recording and a mapping of which file belongs to which note, as described above. Deleting a note deletes its server-side record; deleting your account deletes all local recordings in the background as part of the cleanup described in section 10.
Who can hear your recordings
Your recordings and transcripts are tied to your account and are not shared with other users. They are accessible to our processing pipeline and to the transcription provider used to convert speech to text, and to the developer only where strictly necessary to investigate a fault you have reported. The transcription providers we may use are listed in section 6.
Recording other people
Laws about recording conversations differ by country and by US state — some require every participant's consent. You are responsible for making sure you have the right to record, and for telling the other participants when the law requires it. If someone else's voice ends up in your recording, you are acting as the person who decided to record them.
6. AI features
Micnoteai uses AI models in three places: converting speech to text (transcription), producing the summary of a note, and answering your questions in the note chat.
How content reaches the AI
The app never talks to an AI provider directly. Everything goes through our own backend: the app sends your audio, document or chat message to api.micnoteai.com / api.hamidmanafov.com over HTTPS, and the backend forwards the necessary content to the AI provider under our own API credentials. Your identity is not passed to the AI provider — it receives the content to be processed, not your account details, subject to the one file-name exception noted below.
What is sent
- Transcription: the audio you recorded or imported.
- Summarisation: the transcript or extracted document text of that one note.
- Note chat: the message you typed, the earlier messages in that conversation, and the content of the note you are asking about. Only the note you have open is included — the AI is not given your whole library.
Which providers
Depending on the task, the language and availability, our backend may use any of the following providers. We keep this list up to date when we add or drop one.
| Task | Providers we may use |
|---|---|
| Speech-to-text (transcription) | OpenAI (gpt-4o-mini-transcribe), Google (Gemini), DeepInfra (Whisper large-v3), RunPod (faster-whisper) |
| Summaries, note titles, chat answers, translation | OpenAI or Google Gemini |
| PDF processing | Google Gemini only |
These providers act as our processors: they process the content on our instructions and only to return a result to us. Two details worth knowing:
- They do not learn who you are. We do not send them your name, email address or account identifier — only the audio or document itself, the text needed for the task, and a language code. One technical exception is worth naming: on the OpenAI and DeepInfra transcription paths the audio is uploaded as a file whose file-name field is taken from the last part of its storage link, so if that storage key happens to contain a note or account identifier, that identifier reaches the provider as a file name. Where long audio is split into chunks, the file names are neutral (
chunk_0001.mp3and so on). - RunPod fetches the audio itself. Where transcription runs on RunPod, our backend does not upload the file to it directly; it passes a time-limited signed link and RunPod downloads the audio from our storage using that link. The link expires shortly afterwards.
Training
We do not use your recordings, transcripts, notes or chat messages to train our own AI models, and we do not sell or license them to anyone for that purpose. We use AI providers under business/API terms rather than consumer terms, which ordinarily excludes customer content from provider model training. We cannot promise on their behalf that they are contractually barred from training on the content, and each provider sets its own retention period for abuse monitoring. If this matters to you, read the API terms of the providers listed above before submitting sensitive material.
Accuracy
Transcripts and AI summaries are generated automatically and can be wrong, incomplete, or misattributed to the wrong speaker. They are not a verbatim legal record, and they are not professional advice. Please check anything important against the original recording — which is why the app keeps the audio available.
7. Sharing and disclosure
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so, and we receive no money or other valuable consideration for your data.
We share data only with the service providers listed below, each of which processes it on our instructions and only for the stated purpose.
| Recipient | What is shared | Purpose | Where to find their policy |
|---|---|---|---|
| Apple Inc. | Your App Store account and payment details (handled entirely by Apple — we never see them); the sign-in token if you use Sign in with Apple; your push notification device token and notification payloads | App distribution, subscription payment and billing, Sign in with Apple, delivery of push notifications through Apple Push Notification service | apple.com/legal/privacy |
| Google LLC | Only if you choose Google Sign-In: the sign-in exchange between your Google Account and the app, which returns an ID token to us | Authenticating you with your Google Account | policies.google.com/privacy |
| RevenueCat, Inc. | A purchase identifier linked to your account, your App Store receipt/subscription status, and basic device and app metadata. No recordings, transcripts or chat content. | Managing subscription entitlements, verifying receipts, restoring purchases | revenuecat.com/privacy |
| PostHog (EU Cloud, Frankfurt, Germany) | Pseudonymous product-analytics events, a pseudonymous analytics identifier, and app/device metadata. No audio, transcript text, note content or chat content. | Understanding feature usage and diagnosing broken flows so the app can be improved | posthog.com/privacy |
| AI / transcription providers — we may use OpenAI, Google (Gemini), DeepInfra or RunPod, as set out in section 6 | The content to be processed: your audio for transcription, the note text for summarisation, and your chat message plus that note's content for the note chat, together with a language code. Your name, email address and account identifiers are not passed on, subject to the file-name exception explained in section 6. | Speech-to-text transcription, summary and title generation, translation, answering your questions about a note, PDF processing (Gemini only) | openai.com/policies, policies.google.com/privacy, deepinfra.com/privacy, runpod.io/legal/privacy-policy |
| Hetzner Online GmbH (European Union) | Everything our application servers and databases hold: the account record, transcripts, summaries, note metadata and chat history | Running the API servers, PostgreSQL database and Redis behind api.micnoteai.com and api.hamidmanafov.com |
hetzner.com/legal/privacy-policy |
Amazon Web Services (S3 and CloudFront, region eu-central-1 — Frankfurt, Germany) |
Your uploaded audio files and PDF documents | Storing the files your notes are made from and delivering them back to you over time-limited signed links | aws.amazon.com/privacy |
| YouTube / Google LLC | The video URL you paste. Two separate requests reach Google: our backend fetches the video's content, and — before you confirm — your device itself asks Google's public oEmbed endpoint (youtube.com/oembed) for the video's title and channel name and downloads the thumbnail image from img.youtube.com. Those two requests come from your device, so your IP address, approximate device/browser metadata and the video ID reach Google. No account identifier, recording, transcript or note content is sent. |
Retrieving the video you asked us to summarise, and showing you a preview card with the video's title and thumbnail so you can confirm you pasted the right link | policies.google.com/privacy |
We may additionally disclose personal data:
- To comply with the law — in response to a valid court order, subpoena or other binding legal request, or to establish, exercise or defend legal claims. We will tell you about such a request unless we are legally prohibited from doing so.
- To protect people — where disclosure is necessary to prevent fraud, abuse of the service, or a serious threat to someone's safety.
- In a business transfer — if the app is ever sold or transferred, your data may pass to the acquirer, who would remain bound by this policy until you are notified of any change. You would be told before your data became subject to a different policy.
8. Data retention
We keep personal data only for as long as we need it for the purpose it was collected for. In practice that means:
| Data | How long we keep it |
|---|---|
| Account record (ID, email, name, locale, time zone, premium flag) | For as long as your account exists. Deleted when you delete your account. |
| Uploaded audio recordings (server side) | Kept in Amazon S3 (Frankfurt) for as long as the note exists, so the note can play the audio back. There is no automatic age-based deletion. Deleted immediately when you delete the note or your account. |
| Uploaded PDFs and submitted YouTube links | Retained with the note they produced, on the same basis as audio — no automatic expiry. Deleted immediately with the note or the account. |
| Transcripts, summaries, note titles, folders, speaker names | For as long as the note exists in your account. Deleted when you delete the note or your account. |
| AI chat messages | Retained with the note they belong to, with no automatic expiry. Deleted when you delete the note or your account. |
| AI usage metering (counters and token counts — no content) | 365 days. |
| Internal processing-queue records | Completed job dispatch rows are removed after 7 days; short-lived cache entries expire within minutes. |
| Local copies on your device (audio files, offline note cache, audio-to-note mapping, speaker names, pending upload queue) | Until you delete the note, turn off local audio retention, sign out, delete your account, or delete the app. Deleting the app removes all of it. |
| Access and refresh tokens in the Keychain | Until they expire or you sign out; removed from the Keychain on sign-out and on account deletion. |
| Onboarding answers and app settings (device-local) | Until you delete your account (which clears them) or delete the app. |
| Push notification device token | While notifications are enabled and your account exists; invalidated when Apple revokes the token or you delete the account. |
| Purchase and subscription records | For the life of the subscription, then for as long as tax and accounting law requires (commonly up to 7 years). Apple and RevenueCat keep their own records under their own policies. |
| Product analytics events | Kept by PostHog on its EU Cloud for the retention period configured for our project, and deleted automatically by PostHog once that period expires. Events are pseudonymous and are not linked back to your notes. |
| Support emails | Up to 24 months after the conversation ends, so we can follow up on recurring issues. |
| Server logs | Rotating container logs only — roughly 30 MB per service, overwritten as new entries arrive. There is no central long-term log store. The logs are not designed to hold note content and do not contain transcripts, summaries, chat messages or email addresses in normal operation. One narrow exception: if a transcription provider returns a response our service cannot parse, the first 500 characters of that response — which may include transcript text — are written to the error log, where they are overwritten with the rest of the rotating logs. |
| Internal audit log (security and abuse prevention) | Retained after account deletion. It holds the user identifier, the note title and the first 100 characters of the note text — see the limitations below the table. |
| AI processing job records | Contain the transcript and summary text while a note is being processed. Completed and failed job records are deleted after 30 days in any case, and a deletion is requested for all of them as soon as you delete your account — see the limitations below the table. |
| Subscription event records and account-deletion queue records | Retain the user identifier after the account is deleted, for billing reconciliation and to prove the deletion was carried out. |
Limitations we want you to know about
Deleting a note or an account removes the note itself, and the audio or document it came from, everywhere we store them as your notes. Three internal records need a fuller explanation, and we would rather tell you than let you assume otherwise:
- AI processing job records. When a note is processed, our AI service writes a job record that holds the text it was given and the transcript, title and summary it produced. When you delete your account, our note service enqueues a purge instruction that asks the AI service to delete every job record belonging to you, and the whole record — input text and generated output alike — is removed. In normal operation this happens within seconds of your deletion. If the AI service is briefly unreachable, the instruction is retried automatically, up to 50 times with a backoff that grows from 15 seconds to 5 minutes, so a temporary outage does not lose the deletion. We cannot promise it always succeeds: if the AI service rejects the instruction, or the retries are exhausted, the purge is marked as failed and those records remain until someone acts on it, because there is no further automatic recovery. Separately, and regardless of account deletion, completed and failed job records are deleted after 30 days; a record left in a state that is neither completed nor failed is not covered by that cleanup. If you want to be sure, email hamidmanafov7@gmail.com and we will check and remove the job records associated with your account. Copies of content that have already been sent to the AI providers listed in section 6 are held under those providers' own retention terms, which we cannot shorten or delete on your behalf.
- Internal audit log. For security and abuse prevention we keep an audit log that survives account deletion. It retains your user identifier, the note title and the first 100 characters of the note text — not the full transcript, summary or chat.
- Identifiers in billing and deletion records. Subscription event records received from RevenueCat, and the account-deletion queue records that prove your deletion was carried out, keep your user identifier after the account is gone.
Where we are required to keep something longer than the periods above — for example an invoice we must retain for tax purposes — we keep only that record and stop using it for any other purpose.
9. Data storage and international transfers
Your data is processed primarily in the European Union. The servers behind api.micnoteai.com and api.hamidmanafov.com — the application servers, the PostgreSQL database and Redis — run on Hetzner Online GmbH data centres in the European Union. Your uploaded audio files and PDFs are stored in Amazon S3 in the eu-central-1 region (Frankfurt, Germany) and delivered through CloudFront signed links. Product analytics are stored on PostHog's EU Cloud, also in Frankfurt.
Personal data nevertheless leaves the EEA in two situations. First, the developer is based in Azerbaijan, which is outside the European Economic Area and is not covered by a European Commission adequacy decision, so administrative access to the service takes place from Azerbaijan. Second, some service providers operate outside the EEA — the AI providers listed in section 6, and Apple, Google and RevenueCat, which are US companies. This means your personal data may be transferred to, stored in, or accessed from countries outside your own, including the United States, which may not offer the same level of data protection as your home country.
When we transfer personal data out of the EEA, the UK or Switzerland, we rely on a lawful transfer mechanism under Chapter V GDPR:
- Standard Contractual Clauses (Article 46(2)(c) GDPR), in the European Commission's 2021 form, together with the UK International Data Transfer Addendum where UK data is involved — this is our default basis with service providers;
- an adequacy decision (Article 45 GDPR), where the destination country has one;
- certification under the EU–US Data Privacy Framework, where the provider is certified.
We also carry out a transfer risk assessment where required and apply supplementary measures such as encryption in transit and access controls. You can ask us for a copy of the safeguards that apply to a specific transfer by writing to hamidmanafov7@gmail.com.
10. Your rights under GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights over your personal data. They are free to exercise, and we will respond within one month (extendable by two further months for complex requests, in which case we will tell you why).
- Access (Art. 15) — ask whether we hold data about you and get a copy of it, together with information about how it is used.
- Rectification (Art. 16) — have inaccurate data corrected. You can edit your display name, note titles and note content directly in the app.
- Erasure (Art. 17) — have your data deleted. You can do this yourself at any time (see below).
- Restriction (Art. 18) — ask us to stop processing your data while a dispute about its accuracy or our legal basis is resolved.
- Portability (Art. 20) — receive the data you gave us, and the notes generated from it, in a structured, commonly used, machine-readable format, and have it sent to another provider where technically feasible.
- Objection (Art. 21) — object to processing based on our legitimate interests, including product analytics. We will stop unless we can show compelling legitimate grounds that override your interests.
- Withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw it at any time, without affecting processing that already happened. Withdrawing microphone or notification permission in iOS Settings has immediate effect.
- Not to be subject to automated decision-making (Art. 22) — we do not make decisions with legal or similarly significant effects about you by automated means.
Deleting your account
You can delete your account yourself, without contacting us: open Settings in the app and choose Delete account. The app sends a deletion request to our backend, and the deletion then runs as a chain on the server: your refresh tokens are revoked, the account row is permanently deleted, the linked Apple or Google identifiers and your subscription records are removed, and every note in your account is deleted together with its audio and document files in our file storage. If one of those steps fails — for example because the file storage is briefly unreachable — a background worker retries it automatically until it succeeds, so the deletion is not silently abandoned. Because of those retries, completion can take a short time rather than being instantaneous. The app in parallel clears everything held on the device: the pending upload queue, the local audio-file mapping, saved speaker names, the offline note cache, onboarding and paywall markers, your stored sign-in tokens and user ID in the Keychain, your Google session, your RevenueCat identity, and your analytics identifier. All local audio recordings are deleted in the background as part of the same cleanup.
Account deletion is permanent and cannot be undone: there is no soft delete, no recycle bin and no restore window, so please export anything you want to keep beforehand. Deleting a single note works the same way — the database row and the stored audio or document are removed immediately. The narrow exceptions that survive deletion are listed at the end of section 8. Account deletion does not cancel an active App Store subscription — you must cancel that in iOS Settings → your name → Subscriptions, because only Apple can manage the subscription and any refund.
How to exercise your other rights
Email hamidmanafov7@gmail.com from the address associated with your account and tell us what you want. We may need to ask a question or two to confirm you are the account holder — we do this to stop someone else obtaining or deleting your notes, and we will not ask for more identifying data than we need.
Complaints
If you believe we have handled your data unlawfully, we would like the chance to put it right, so please contact us first. You also have the right to lodge a complaint with a data protection supervisory authority — in the EEA, the authority in the country where you live, work, or where the alleged infringement took place; in the UK, the Information Commissioner's Office (ico.org.uk). A list of EEA authorities is published at edpb.europa.eu.
11. Your rights under CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights described below.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We have not done so in the preceding 12 months, and we do not sell or share the personal information of consumers under 16 years of age. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" link to provide — but if this ever changes, we will update this policy and offer an opt-out before it takes effect.
Categories collected. In the past 12 months we have collected the categories described in section 3, which map to the CCPA categories of identifiers (account ID, email, device and push tokens), customer records (name, email), commercial information (subscription and purchase status), internet or network activity (in-app product analytics), audio and electronic information (your recordings, transcripts and chat content), and inferences drawn from your onboarding answers. The sources, purposes and recipients are set out in sections 3, 4 and 7.
Sensitive personal information. Your recordings and transcripts may contain whatever you chose to record. We use that content only to deliver the service you asked for — transcription, summarisation and chat — and never to infer characteristics about you. We therefore do not use or disclose sensitive personal information for purposes beyond those permitted by CPRA section 1798.121, and no right to limit its use applies.
Your rights are:
- Right to know — request the specific pieces of personal information we hold about you, and the categories collected, the sources, the business purpose, and the categories of third parties they were disclosed to.
- Right to delete — request deletion of your personal information, subject to the exceptions in the statute (for example records we must keep for tax purposes). You can exercise this immediately yourself with Settings → Delete account in the app.
- Right to correct — request correction of inaccurate personal information; most fields are editable directly in the app.
- Right to opt out of sale or sharing — available to you even though we do not sell or share.
- Right to limit the use of sensitive personal information — see the paragraph above.
- Right to non-discrimination — we will never deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We offer no financial incentives in exchange for personal information.
How to submit a request. Email hamidmanafov7@gmail.com with "CCPA request" in the subject line, or use the in-app deletion flow for deletion. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days if we tell you why. We verify requests by matching the email address on the request to the account, and by asking about account details only you would know. An authorised agent may submit a request on your behalf with written permission signed by you, and we may still contact you to confirm it.
12. Device permissions
iOS asks for your permission before the app can use the capabilities below. You can change every one of them later in iOS Settings → Micnoteai, and the app is designed to keep working — with reduced functionality — if you say no.
| Permission | Why the app asks | What happens if you decline |
|---|---|---|
MicrophoneNSMicrophoneUsageDescription |
The prompt says: "This app uses your microphone to record audio notes for transcription and summarization." It is requested the first time you start a recording, and the microphone is used only while a recording is in progress. | You cannot record new audio in the app. You can still import existing audio files and PDFs, submit YouTube links, and read, edit and chat with the notes you already have. |
| Notifications (alerts, sounds, badges) |
To tell you when a note has finished transcribing and summarising, or when processing failed — this can take a while, so you do not have to sit and watch the screen. | No push notifications are delivered and no device token is registered. Processing still runs normally; you simply check the note's status in the app yourself. |
| Files / documents (system file picker) |
When you import an audio file or a PDF, iOS shows its own document picker. The app receives only the single file you choose. | Nothing is imported. The app has no standing access to your files, your iCloud Drive or your photo library — there is no permission to grant or revoke, because access is granted per file by your choice. |
The app does not request access to your location, contacts, calendar, camera, photo library, health data, or the App Tracking Transparency prompt, because it does not track you across other companies' apps or websites.
13. Children's privacy
Micnoteai is not directed at children. The app is intended for users aged 13 and over, and — because we rely on legitimate interests for some processing and on contract for the rest — for users aged 16 and over in the European Economic Area, or the lower age of digital consent set by your own country where that applies.
We do not knowingly collect personal data from children below those ages. We do not ask for a user's age, and sign-in is handled by Apple or Google, which apply their own account age restrictions. If we learn that a child has created an account, we will delete the account and everything stored in it without delay.
If you are a parent or guardian and believe your child has used the app and given us personal data, email hamidmanafov7@gmail.com and we will remove it.
14. Security
We take the following concrete measures to protect your data:
- Encrypted transport. Every connection between the app and our backend, and between the app and third-party services, uses HTTPS with TLS. Audio, documents, transcripts and chat messages are never sent over an unencrypted connection.
- Credentials in the iOS Keychain. Your access token, refresh token and user ID are stored in the system Keychain with the
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnlyprotection class — they are readable only after the device has been unlocked once since boot, and they never leave the device or appear in an iCloud backup. - Hardened sign-in. Sign-in uses single-use nonce and state values issued by our backend, which prevents replay and interception attacks. There is no password to steal, because the app has no password login.
- On-device protection. Recordings, the offline note cache and app settings live inside the app's iOS sandbox, in a folder scoped to your account. Apart from the Keychain items above, the app does not encrypt this data itself: your locally cached transcripts, AI summaries and note titles are held in a plain, unencrypted on-device database (SwiftData/SQLite), and recordings are plain
.m4afiles. They are protected by the same things that protect the rest of your phone — iOS sandboxing, the device's file-level encryption, and your passcode or biometrics — which means that someone who can unlock your device, or who extracts data from an unlocked device, can read them. Set a passcode and keep your device up to date. - Server-side protection — and its limits. Our databases and file storage sit behind access controls and network isolation, and every connection to them is over TLS. We do not apply application-level encryption at rest: the PostgreSQL database and the audio and PDF files in Amazon S3 are protected by the access controls of the hosting and storage platforms rather than by an additional layer of encryption we manage ourselves. Download links for your files are signed and expire after one hour.
- No IP address storage. We do not record your IP address in any database. It appears only in rotating server logs that are overwritten as new entries arrive, and rate limits are enforced per account rather than per IP address.
- No email sending. Our backend sends no email at all — no transactional messages, no marketing. That means there is no email provider holding your address on our behalf, and any email claiming to be from Micnoteai that is not a direct reply to a message you sent us should be treated with suspicion.
- Least-privilege sharing. Third-party services receive only what they need: analytics never receives note content, and AI providers never receive your identity.
- Prompt deletion. Deleting your account clears server-side data and wipes device-side data, including local audio files, in the same operation.
That said, no method of transmission over the internet and no method of electronic storage is 100% secure, and we cannot guarantee absolute security. You can help by keeping your device passcode and your Apple or Google account secure, and by signing out of devices you no longer use — the app offers both "sign out" and "sign out of all devices".
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will notify you directly where the law requires it.
15. Purchases and subscriptions
Micnoteai offers a premium subscription through Apple's In-App Purchase system.
- Apple handles the payment. Your purchase is made with your App Store account. Card numbers, billing addresses and payment processing are entirely Apple's — the developer never receives, sees or stores your payment details.
- What reaches us. Subscription state — whether your premium entitlement is active, which product it is, and whether a purchase should be restored — reaches the app through RevenueCat, which verifies the App Store receipt. RevenueCat links this to an anonymous purchase identifier associated with your account, not to your recordings or notes.
- Free-tier limits. Our backend keeps counters of your usage against the free-tier limits so it knows what to allow. Deleting your account clears them.
- Managing and cancelling. Subscriptions renew automatically until cancelled. Manage or cancel yours in iOS Settings → your name → Subscriptions. We cannot cancel a subscription or issue a refund on your behalf — only Apple can, through reportaproblem.apple.com.
- Restoring purchases. "Restore purchases" asks Apple and RevenueCat to re-check your existing entitlement; no new personal data is collected.
- Records. Signing out resets the RevenueCat identity stored on the device. Purchase records that Apple and we must keep for tax and accounting purposes survive account deletion, as described in section 8.
16. Analytics and diagnostics
The app uses PostHog for product analytics, hosted on PostHog's EU Cloud in Frankfurt, Germany — your analytics data does not leave the EU for this purpose. It is the only analytics tool in the app. There are no advertising SDKs, no attribution or ad-network SDKs, and no cross-app or cross-site tracking.
What is collected: product events such as which screens you opened, that a note was created, that the paywall was shown or dismissed, and which features were used; a pseudonymous analytics identifier; and app and device metadata attached to those events.
What is never collected by analytics: your audio recordings, transcript text, summaries, note titles, chat messages, or the contents of any file you import. Analytics tells us that a note was created — not what was in it.
Turning it off. You can disable analytics in the app's settings at any time. When you do, the app opts out of collection and stops sending events. Deleting your account also resets the analytics identifier, so events can no longer be tied to a returning user.
We rely on our legitimate interest in maintaining and improving the app for this processing (Art. 6(1)(f) GDPR), which is why an opt-out is available to everyone rather than an opt-in. Analytics is used for that purpose only. If we ever wanted to use it for anything else — profiling, advertising, or anything that is not maintaining and improving the app — we would ask for your consent first, as described in section 17, rather than rely on this basis.
17. Changes to this policy
We may update this policy when the app changes, when we add or replace a service provider, or when the law requires it. The "Last updated" date at the top always reflects the current version.
If we make a material change — for example collecting a new category of data, using your content for a genuinely new purpose, or adding a recipient that meaningfully changes where your data goes — we will give you notice inside the app before the change takes effect, and where the law requires it, we will ask for your consent. Continuing to use the app after a non-material update means the updated policy applies to you.
We will not retroactively reduce the protections that applied to data we already hold without telling you first.
18. Contact us
Questions, privacy requests, complaints and corrections all go to the same person — the developer.
- Privacy and data protection: hamidmanafov7@gmail.com
- General app support: support@micnoteai.com
- Data controller: Hamid Manafov, individual developer, Azerbaijan
- Postal address: available on request — email the privacy address above and we will provide it
Please write in English or Azerbaijani. We aim to reply within a few business days, and within the statutory deadlines set out in sections 10 and 11 for formal rights requests.
Micnoteai is made by one developer. If something in this policy is unclear, or does not match what you see the app doing, please write — it will be read by the person who wrote the code.