dumpnotes
privacy policy

Privacy Policy

Your notes are the most personal thing you can put in an app. This document explains exactly what we collect, why we need it, everyone it touches, and how to get it back or delete it. No hidden clauses.

Last updated · 10 August 2026Effective · 10 August 2026Applies to · dumpnotes.app and the DumpNotes apps
Jump to a section
  1. Scope and who we are
  2. Our principles
  3. What we collect
  4. Where it comes from
  5. How we use it
  6. Legal bases
  7. AI processing
  8. Who we share it with
  9. International transfers
  10. How long we keep it
  11. How we protect it
  12. Your rights
  13. Making a request
  14. Regional rights
  15. Children
  16. Cookies and tracking
  17. Breach notification
  18. Changes
  19. Contact and complaints

Scope and who we are

This policy covers personal data processed by [Legal entity name] (DumpNotes, “we”, “us”) through dumpnotes.app, the DumpNotes web app, any DumpNotes desktop or mobile app, and our support email.

We are the data controller for that data (the equivalent term is data fiduciary in some jurisdictions). Our address is [Registered address]. You can reach us at admin@dumpnotes.app.

This policy does not cover third-party sites you reach from DumpNotes, which have their own policies.

Our principles

  • We do not sell your personal data. Not to advertisers, not to data brokers, not to anyone.
  • We do not run advertising and we do not build advertising profiles.
  • We do not train models on your notes. Neither our own models nor, per our provider’s terms, our AI provider’s.
  • We collect the minimum needed to make the product work and keep it secure — not everything we could technically collect.
  • Staff do not read your notes. Access to production data is restricted, and is used only to fix a specific problem, usually one you have reported.

What we collect

Account and identity data

Handled by Clerk, our authentication provider: your email address, a hashed password (we never see the plaintext), your display name, optional profile image, and — if you sign in with a provider like Google — the basic profile information that provider returns. Clerk also records sign-in events, devices and verification codes for security.

Profile data

Your chosen username, display name and avatar, stored in our database so other users can find and identify you.

Content you create

This is the bulk of it, and it is stored in our Supabase database and storage:

  • notes, including their full text, titles, tags and AI-generated summaries;
  • notebooks and the notes assigned to them;
  • calendar events and reminders, including titles, dates and times;
  • messages you send to other users, and images you attach to them;
  • friend connections and requests;
  • your AI assistant conversation history.

Usage and metering data

Counts of AI tokens and AI requests per day and per month, and the timestamps at which each window resets. This is how allowances are enforced and how the usage meter in the app is drawn. It records how much you used, not what you wrote.

Subscription and billing data

Your plan tier, subscription status, subscription identifier and renewal dates, written to our database by Paddle’s webhook. We do not receive, process or store your card number, CVV or bank details — those go directly to Paddle. Paddle also holds your billing name, address, country and tax identifiers for invoicing and tax compliance.

Technical data

  • IP address, used to rate-limit requests from signed-out visitors and to investigate abuse. For signed-in requests the rate limiter keys on your account identifier instead of your IP.
  • Request metadata — timestamps, endpoint, status code, user agent — recorded in server logs by our hosting provider.
  • Error diagnostics when something breaks, which may incidentally include a fragment of the request that failed.

Local preferences

Theme (light or dark), navigation layout and similar interface choices are stored in your browser’s local storage, on your device. They are not sent to us. See the Cookie Policy.

Support correspondence

If you email us, we keep the message, your address and our reply, so we have the history if you write again.

What we do not collect

No advertising or analytics trackers. No third-party marketing pixels. No location beyond what an IP address broadly implies. No contact list, microphone or camera access. No biometric data. No behavioural profiling.

Where it comes from

  • From you — everything you type, upload, or configure.
  • From your device automatically — IP address, browser and device type, request metadata.
  • From other users — a friend request, a message, or a note someone shares with you.
  • From our providers — Clerk (sign-in and verification events), Paddle (subscription status and payment outcomes, not card data), and any single sign-on provider you choose to use.

How we use it

PurposeData used
Provide the appAccount data, profile, content, preferences
Authenticate you and keep the account secureAccount data, sign-in events, device and IP
Run AI features you invokeThe note text or prompt involved, plus minimal context
Enforce allowances and rate limitsUsage counters, account identifier, IP for signed-out traffic
Take payment and manage subscriptionsEmail, subscription status and identifiers (via Paddle)
Deliver messages and shared notesMessage content, attachments, friend connections
Provide supportYour email, your message, account metadata
Detect abuse, fraud and attacksIP, request metadata, usage patterns
Fix bugs and improve reliabilityAggregated usage, error diagnostics
Send service messagesEmail address
Comply with legal obligationsBilling records, whatever a valid legal request requires

We do not use the content of your notes to make automated decisions that produce legal or similarly significant effects about you.

Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on the following bases. Where the DPDP Act applies, we rely on your consent or on legitimate uses recognised by that Act.

BasisWhen we rely on it
ContractProviding the app, storing your notes, running features you invoke, taking payment
Legitimate interestsSecurity, abuse and fraud prevention, rate limiting, debugging, and improving reliability — balanced against your rights, and not used where your interests override ours
Legal obligationTax and accounting records, responding to lawful requests
ConsentOptional features you switch on, and any non-essential communication. You can withdraw consent at any time without affecting prior processing

AI processing — the important part

This is the one place your notes leave our infrastructure, so it deserves to be spelled out.

What is sent, and when

Nothing is sent to an AI provider until you invoke an AI feature. When you do — asking the assistant a question, auto-organising, generating a summary, running smart search, asking for a definition, or accepting a suggested event or reminder — we send only the text relevant to that request, together with your prompt and minimal context such as the current date and time. We do not send your entire workspace, your email address, your name, or your billing details.

Who processes it

Google, via the Gemini 2.5 Flash API. We use Google’s paid Gemini API tier. Google states that it does not use paid-tier API content to improve or train its models. Google processes the request and returns a result; the result is stored in your workspace where the feature works that way (for example, a saved summary). Google’s handling is governed by its API terms and privacy policy.

Your control

  • AI features are invoked by you. If you never use them, your note content is never sent to an AI provider.
  • You can clear your AI conversation history in the app, and delete AI-generated summaries along with the notes they belong to.
  • If we change AI provider or model, we will update the Subprocessors page and give notice as described there.
A practical caution

Do not put someone else’s sensitive personal information into an AI prompt without a proper basis for doing so, and do not paste in material you are contractually forbidden to disclose. Once a request is sent to the provider, we cannot unsend it.

Who we share it with

We share personal data only in the situations below. The full list of providers, what each receives and where each is located is on the Subprocessors page.

  • Service providers (subprocessors) — authentication, database and storage, AI processing, payments, rate limiting and hosting. Each is bound by contract to process data only on our instructions and to protect it.
  • Other users — but only what you choose to share: your username, display name and avatar are visible to users who can find you; messages and shared notes go to the recipients you pick.
  • Legal and safety — where we are required by valid law or legal process, or where disclosure is necessary to protect our rights, our users’ safety, or to investigate fraud or a security incident. We assess each request, decline overbroad ones, and notify you unless legally prohibited.
  • Corporate transactions — if the business is merged, acquired or has its assets sold, data may transfer as part of that. We will give notice, and the acquirer remains bound by commitments at least as protective as these.

We do not share your data with advertisers or data brokers, and we do not sell it.

International transfers

We are based in [Country of registration], and several of our providers are based in or operate from the United States and the European Union. Using DumpNotes therefore involves transferring your data across borders.

Where data is transferred out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), on adequacy decisions where one applies, or on your explicit consent. Our providers each maintain their own transfer safeguards, which are linked on the Subprocessors page. You can request details of the safeguards that apply to you at admin@dumpnotes.app.

How long we keep it

DataKept for
Notes, notebooks, events, remindersUntil you delete them, or until 30 days after you delete your account
Messages and attachmentsUntil deleted by you or the other participant; a recipient’s copy persists in their account
Account and profile dataLife of the account, then deleted within 30 days
Usage countersRolling windows; historical counters cleared with the account
Subscription recordsRetained by us and by Paddle for as long as tax and accounting law requires (typically 7 years), even after account deletion
Server and security logsTypically up to 30 days, longer where an incident is under investigation
Rate-limit countersMinutes — they expire with the sliding window
Support emailsUp to 24 months after the issue is closed
Encrypted backupsUp to 30 days on a rolling cycle; deleted content disappears from backups as the cycle rotates

Account deletion is permanent. Once the 30-day window closes, we cannot restore your notes — not from backups, not on request. Export before you delete.

How we protect it

Summarised here; described in full on the Security page.

  • All traffic is encrypted in transit with TLS; data is encrypted at rest by our providers.
  • Row Level Security is enabled on every database table, so a query can only ever return rows belonging to the authenticated account — enforced by the database, not just the application.
  • Uploaded images live in a private storage bucket with per-user access policies and are served only through short-lived signed URLs.
  • Passwords are never handled by us — Clerk manages credentials, hashing, verification and optional second factors.
  • Rate limiting and usage metering protect against abuse and runaway cost.
  • Secrets are held in environment configuration, never committed to source control.

No system is perfectly secure. We cannot guarantee absolute security, and you should use a strong unique password and enable a second factor.

Your rights

Depending on where you live, you have some or all of the following rights. We honour them for all users regardless of location, as a matter of policy, except where doing so would conflict with a legal obligation.

  • Access — a copy of the personal data we hold about you.
  • Portability — your content in a structured, machine-readable format. Available directly from the app’s export function.
  • Correction — fix anything inaccurate. Most of it is editable in Settings.
  • Deletion — delete your content or your whole account.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — at any time, where processing was consent-based.
  • Complain — to your data protection authority.
  • Non-discrimination — exercising a right will never degrade your service or change your price.

Making a request

Email admin@dumpnotes.app from the address on your account, and say what you want. We will:

  1. acknowledge within 5 business days;
  2. verify it is really you — usually by confirming control of the account email, and never by asking for identity documents unless the request is high-risk;
  3. respond substantively within 30 days, or tell you why we need longer (up to a further 60 days for complex requests).

Requests are free. We may charge a reasonable fee or decline only where a request is manifestly unfounded or repetitive, and we will explain why. You may use an authorised agent, who must provide proof of authority.

Regional rights

DumpNotes is used in many countries, and data protection law differs between them. The rights in section 12 are offered to everyone. This section adds what specific regimes require on top, and names the regulator you can escalate to. Regions are listed alphabetically.

Australia

We handle personal information consistently with the Australian Privacy Principles under the Privacy Act 1988. Complaints may be made to the Office of the Australian Information Commissioner after raising them with us first.

Brazil

Under the LGPD you additionally have the right to confirmation of processing, to information about the entities with which we share data (see Subprocessors), and to know the consequences of refusing consent. The supervisory authority is the ANPD.

Canada

Under PIPEDA and provincial equivalents you may access your personal information and challenge its accuracy. Complaints may be made to the Office of the Privacy Commissioner of Canada.

European Economic Area, United Kingdom and Switzerland

Our legal bases are set out in section 6 and our transfer safeguards in section 9. You may lodge a complaint with your national supervisory authority — for example the Information Commissioner’s Office in the UK, your national Data Protection Authority in the EEA, or the FDPIC in Switzerland. We would appreciate the chance to resolve it first at admin@dumpnotes.app.

We have not appointed an Article 27 representative, because our processing of EEA and UK residents’ data is occasional and does not involve large-scale processing of special category data. If that changes we will appoint one and update this policy.

India

Under the Digital Personal Data Protection Act, 2023 we act as a Data Fiduciary and you are a Data Principal. In addition to the rights in section 12 you may nominate another person to exercise your rights in the event of your death or incapacity, and you may raise a grievance with our data protection contact at admin@dumpnotes.app. We acknowledge grievances within 5 business days and resolve them within 30 days; unresolved matters may be escalated to the Data Protection Board of India.

Japan and South Korea

Under the APPI and PIPA respectively you may request disclosure, correction, suspension of use, and deletion of your personal information, and be informed of cross-border transfers — which are described in section 9.

United States

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable state laws. We have not done so in the preceding 12 months, including for anyone we know to be under 16.

The categories we collect, our purposes, the categories of recipients and our retention periods are in sections 3, 5, 8 and 10. Residents of California, Colorado, Connecticut, Virginia and other states with comparable laws may exercise access, correction, deletion, portability and appeal rights by emailing admin@dumpnotes.app. If we deny a request you may appeal by replying to our response, and we will answer within 45 days. We treat the content of your notes as sensitive and use it only to provide the Service, never to infer characteristics about you.

Everywhere else

If your country grants you a right not listed here, tell us and we will honour it. We would rather apply the most protective standard uniformly than maintain a different privacy posture per market.

Children

DumpNotes is not directed at children under 13, and we do not knowingly collect their data. Users aged 13 to 17 require parental or guardian consent (see the Terms). Some jurisdictions set a higher age of digital consent or require that consent to be verifiable; where they do, that standard applies.

If you believe a child has given us personal data without the necessary consent, email admin@dumpnotes.app and we will delete the account and its content promptly.

Cookies and similar technologies

We use only what is necessary to keep you signed in, to process payment, and to remember your interface preferences. There are no advertising or analytics cookies. Every cookie and local store is itemised in the Cookie Policy.

We do not currently respond to Do Not Track browser signals, because there is no common standard for them. We honour Global Privacy Control signals where applicable law requires it — though since we do not sell or share data for advertising, the signal has nothing to switch off.

Breach notification

If a personal data breach is likely to result in a risk to your rights, we will notify you without undue delay, describing what happened, what data was involved, what we are doing, and what you should do. We will notify the relevant supervisory authorities within whichever deadline applies to us and is shortest — 72 hours under the GDPR, and the equivalent periods set by other regulators.

Changes to this policy

We will post any updated version here with a revised date. For material changes — a new category of data, a new purpose, a new category of recipient — we will give at least 30 days’ notice by email and in-app before the change takes effect, and where the law requires consent, we will ask for it rather than assume it.

Contact and complaints

[Legal entity name]
[Registered address]
Privacy: admin@dumpnotes.app
Data protection contact: admin@dumpnotes.app

Billing data held by Paddle.com Market Ltd as Merchant of Record is governed additionally by Paddle’s privacy notice.

This document was last revised on 10 August 2026. Earlier versions are available on request from the legal index.