Effective 27 September 2026
Privacy Policy
This policy explains what SonaNote for Android and iPhone does with your information and what rights you have. It applies to both apps; differences are identified where a feature handles data differently. There is no account and no sign-in. It is also published at https://sonanote.app/privacy.
Who we are
MB Daivina (Mažoji bendrija Daivina), established in Lithuania, makes SonaNote and is the controller of the personal data described here.
MB Daivina (Mažoji bendrija Daivina)
Lauko g. 6, Kvetkai, LT-41212, Lithuania
Write to support@sonanote.app with any privacy question. We have not appointed a data protection officer, as we are not required to.
What stays on your device
Your notes, pictures, flashcards, schedules and settings live in SonaNote's private storage, which your operating system keeps apart from other apps and encrypts at rest. Reading text out of a photograph or a PDF and laying out a mindmap happen on your device. Speech recognition, cloud AI, reporting and backups have the separate data flows described below.
What leaves your device, and when
Some connections happen when the app opens or checks a subscription or the security of a request. Others happen when you use a feature or when your device runs a backup.
- Subscription and security checks. SonaNote contacts our subscription-management provider to check subscription status and your device's platform to prepare or verify the security proofs described below. These checks can run at launch, on refresh or when making a request. They carry identifiers and purchase or security information, but no note content.
- Distilling, or asking a question. Distill sends that note's title, text and up to four of its pictures to our service, which passes them to our AI provider in the European Union and streams the study kit back. Ask sends the title and text with your question, without pictures. Our relay processes the request in memory and does not save it as a notebook. Provider retention, reports you choose to send and operational error logs are described separately below.
- Reporting something the app wrote. On Android, Report sends the generated text, which is drawn from your note and may quote it; the question where applicable; anything you type; the category; the app version; and your installation identifier. It sends no other note. On iPhone, reporting uses email to support@sonanote.app: Settings → Feedback prepares an editable draft, and nothing is emailed unless you send it. A bug-report draft includes the app and operating-system versions and device model; a general comment or idea does not add those details. We use reports and support messages to investigate the issue and improve the feature and its safeguards.
- Backups, exports and mail. If your device's system backup is enabled for SonaNote, it can copy the app's database and pictures, note content included, to your own cloud account. This includes iCloud Backup on iPhone and Android's system backup. You control it in your device's backup settings. Anything you export, share, print or mail goes to the app, provider, printer or recipient you choose.
- Dictation and recordings you import. On Android, imported recordings are transcribed with an on-device speech model; if that service is unavailable, the import cannot proceed. Android dictation prefers on-device recognition but can use the device's speech provider, which may process audio on its servers. On iPhone, dictation uses on-device recognition where available. Imported recordings also prefer on-device recognition, but if it is unavailable or fails, Apple's speech recognition service can process the audio on Apple's servers. No audio is sent to SonaNote's servers. These platform speech services operate under their providers' own privacy policies.
- Text recognition. Reading text out of a photograph or a PDF happens on your device on both platforms. The image and recognised text are not uploaded as part of that step; they can be sent later if you choose Distill, share or another feature described here. On Android, the text-recognition component sends diagnostic and usage information about itself to its provider, without note content; we cannot read or disable those reports. We declare them as data collected through SonaNote. On iPhone, we use Apple's built-in text recognition and have not added that Android component or its diagnostic reporting.
Where the GDPR applies, distilling, asking and dictation perform our contract with you. The rest rests on our legitimate interests: metering the free plan, keeping the service available and free of abuse, keeping what the app writes accurate and safe, and shipping a text reader that keeps working.
You choose whether to use cloud AI, speech recognition, reporting, backups and sharing. Distill and Ask send the selected content when you request them; Android reports and iPhone feedback send the content described above. Choosing not to use these features does not prevent subscription and security checks or the Android text-recognition diagnostics. Device backups are controlled separately in your operating-system settings.
We seek out information about nobody, and we usually cannot identify a person named in a note, so please keep other people's details out of what you send. SonaNote is also not built for notes about health, beliefs, politics or sex life. A note is whatever you wrote, so if you distil one of those it goes with it, and we ask you to think before you do.
On iPhone, Distill and Ask require your Cloud AI permission before content is sent. You can turn it off in Settings → Cloud AI permission. Withdrawal stops future cloud AI requests; it does not undo earlier processing or automatically delete records already retained. Subscription and security checks still run without that permission.
What travels beside the note
- Your installation identifier goes with each distill, question and Android in-app report: a random value made at first run that meters the free plan and paces requests. It does not contain your name, but it can be associated with subscriber and security records, so it is not anonymous to our service.
- Your subscriber identifier goes with every distill and question, whether or not you subscribe, because it is how our service asks whether a subscription is active and it needs the answer no as much as yes. It names no person, but it is not anonymous to us: our service records the first installation to present it, so that one subscription cannot be spread across many phones. If you are paying and SonaNote stops recognising you, write to us.
- Security proofs. On Android, Google Play Integrity provides a signed token about the app, device and request. Our service sends it to Google for verification; we do not keep the token itself, but keep verification outcomes and short-lived replay-prevention records. On iPhone, Apple App Attest supplies an attestation and signed request proofs. Our service verifies them and stores the key identifier, public key, Apple receipt, installation association and verification metadata, including a counter that prevents reuse of an old request. These records contain no note text or audio. Apple and Google process their platform information under their own privacy policies.
Our service also sees the network address a request comes from and keeps usage counts and operational logs to run the service and investigate failures. Routine logs contain security or allowance results and a shortened installation identifier, rather than note text, questions or report bodies. Both services log fixed error codes and numeric status codes for provider failures, without logging provider response bodies or exception text. Installation, subscriber and security identifiers support quota, subscription and integrity checks.
We build no profile of you and make no decision about you as a person. Our service does judge automatically how fast and how many requests arrive from one installation, and may delay or refuse them for a time; it never reads your notes to decide. Write to us if it stops you wrongly and a person will look.
Who else is involved
A few companies handle information for us. This policy describes our service providers by what they do. If you would rather know exactly who they are, write to support@sonanote.app and we will tell you: when you ask, you are entitled to their identities and not merely to these descriptions. Platform services identified below have their own privacy policies.
- Our AI provider writes your study kits and the answers to your questions, on servers in the European Union. It does not use your content to train its models. It may retain submitted content for abuse monitoring, including review by authorised people. Separately, its performance cache can hold inputs, outputs and related data in memory for up to 24 hours, isolated to our project. These are separate from the temporary processing in our relay; we do not promise zero retention by the AI provider.
- The provider that runs our relay carries content to the AI provider and the result back. It also stores the usage counts, operational logs, Android reports, subscriber associations and iPhone security records described in this policy on our behalf.
- Our subscription-management provider records your purchase so that a subscription survives a new device, and answers whether one is active. It receives no notes.
- Our email provider carries messages you send to support@sonanote.app.
Each of those acts as our processor under a written data processing agreement: to act only on our documented instructions, to keep your data confidential and secure, to use it for nothing of its own and never for advertising, to add no one else without our authority, and to delete or return what it holds when the work ends.
Your device's platform operates its own app store, backup, speech-recognition and security services under its own privacy policies. On Android, the text-recognition component's provider also receives the diagnostic reports described above under its own policy. We chose to include that component and are responsible for explaining that collection. The iPhone app does not include that component.
Distilling and asking are processed in the European Union. Our relay runs worldwide, so the counts, operational logs, reports and security records may be stored outside the European Economic Area, and some of our providers belong to United States groups. Transfers out rest on a European Commission adequacy decision where one applies, and otherwise on standard contractual clauses — for a transfer out of the United Kingdom, on the UK Addendum to those clauses. Write to us and we will send you a copy of the safeguards that apply.
How long we keep things
- Your notebook and study material stay on your device for as long as you keep them. We do not maintain a server-side notebook. Content you submit for cloud AI is processed temporarily by our relay, with the separate AI-provider retention described above. Content you include in a report or email follows the reporting and support periods below.
- Android reports about generated content are scheduled for deletion within 24 months of submission, or sooner when newer reports replace older ones. Cleanup runs automatically without requiring another report; deletion can be delayed by service failures. Ask us to delete yours and say roughly when you sent it and what it was about. Messages you email us, including iPhone feedback, are kept up to 24 months after the matter is closed.
- Usage and security counters measure requests over minute, hour, day, month or subscription-allowance windows. Free-plan records include note numbers, never note text. On both services, monthly counters and free-note lists are scheduled for deletion at the start of the second following UTC month; for example, September records expire on 1 November. Shorter counters are scheduled for deletion when their windows end, and temporary verification and subscription-cache records at their expiry. Cleanup continues without further requests. Deletion can be delayed by service failures; contact us to request erasure of records associated with your installation.
- Subscriber associations and iPhone security records. The association between a subscriber identifier and its first installation has no automatic expiry, to prevent one subscription from being spread across devices. Registered App Attest keys, receipts and replay counters also have no automatic expiry; pending challenges stop being valid after five minutes but can remain stored until a later update. These records are not deleted by uninstalling the app. Contact us to request erasure, subject to any lawful need to retain data for security or legal obligations.
- Purchase records: for the life of the subscription, and then for as long as tax law requires, which in Lithuania is generally ten years. We hold no invoice and no payment card details.
- Operational logs in our hosting provider's built-in logging service are retained for up to seven days. Older Android logs from before the 27 September 2026 logging fix may contain short provider-error excerpts, including submitted content if a provider echoed it in an error; those logs expire under the same seven-day limit. Provider recovery backups of service records can remain for up to 30 days after deletion from active storage; your own device or cloud backups remain under your control.
Your rights
Over your notes you exercise most rights yourself: you can read, edit, export and delete any of them without asking us. Over the personal data we hold you have the right of access and to a copy, including the identities of the companies it has been disclosed to; to correction; to erasure where the law allows; to restriction; to portability; and to withdraw consent where consent is the basis.
You also have the right to object. Where we rely on our legitimate interests — that is the identifiers, the counts and the log, the signed statement, your reports, and the text component's own reports — you may object at any time, and we will stop unless we can show compelling grounds that override your objection.
Write to support@sonanote.app to exercise any of them. We answer within one month, and we will say so if we need longer or cannot comply. Because there is no account, what we hold is tied to a random identifier rather than to you; where we genuinely cannot work out which data is yours these rights do not apply until we can, so tell us anything that would help us find it.
There is no SonaNote account to delete. Removing the app deletes its local notebook from that device but does not cancel a subscription, remove backups and exports, or erase records held by our service or providers. Remove your own backups and exported copies separately. Write to support@sonanote.app to request deletion of reports, support messages, subscriber associations, security records or other data we can identify as yours; we will also handle applicable requests with our processors. We may retain data where the law permits or requires it, and will explain any such reason. If you believe we have handled your data wrongly you may complain to your data protection authority. Ours is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt. We would appreciate the chance to put it right first.
Security
Everything that leaves your device for us travels over an encrypted connection, and access to the little we hold is limited to those who need it. No system is perfectly secure, and a device you have rooted, lost or shared is outside what any app can protect. Nothing in this section limits our liability or takes away a right the law gives you.
If you are in the United States
This is our notice at collection. We collect identifiers (your installation and subscriber identifiers, and your network address); your own content (a note you distil or ask about, its pictures, your question, and what a report carries); commercial information (a subscription's plan, status and dates); device and internet activity (the counts and the log); and whatever you write to us. All of it comes from you or from your device, and each is kept for the period set out above, for the purposes set out above.
We never ask for sensitive information and nothing here is built specifically to collect it, but a note is whatever you wrote: distil one about your health, beliefs or private life and that content is submitted too. We use it to provide the feature you requested, subject to the processing, security and retention described above. Please keep other people's sensitive details out of what you send.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we have done neither in the preceding twelve months. We do not sell or share the personal information of anyone under 16, we offer no financial incentive for your data, and we will not treat you differently for exercising a right. Android's text-recognition diagnostics are disclosed above as information sent to the component's provider; this component is not included in the iPhone app.
Because there is nothing here to opt out of, there is no Do Not Sell or Share link and no link to limit the use of sensitive personal information. SonaNote has no browser, so a Do Not Track or Global Privacy Control signal has nothing to act on, and no other party collects information about your activity across other websites or apps through SonaNote. To exercise a right, write to support@sonanote.app, or have an authorised agent write on your behalf with your authority.
Children
SonaNote is for people aged 16 and over. It is a general-audience study app, it is not directed at children, and we do not ask anyone's age. We do not knowingly collect personal data from a child under 13. If you are a parent or guardian and believe a child has sent us something, write to us and we will delete it.
Written by AI
Study kits, mindmaps and the answers you get when you ask a note a question are written by an AI model, in most cases from your own note at the moment you ask. The kits on the sample notes SonaNote starts you with were written the same way before the app shipped. Nothing in any of them was checked by a person first.
A model can be wrong while sounding certain. Treat what it writes as a study aid, check anything that matters against a source you trust, and do not lean on it for a medical, legal, financial or safety decision. That is advice about using SonaNote, not a limit on what we owe you.
If a kit, a mindmap or an answer is wrong, offensive or otherwise bad, use Report on Android or email support@sonanote.app on iPhone. Settings → Feedback on iPhone helps prepare that email. We review reports and use them to improve how the feature behaves.
Changes to this policy
If SonaNote begins doing something this policy does not describe, the policy changes with it and so does the date at the top. We change it only for a reason we can state: a new or altered feature, a change at a provider we rely on, or a legal or security requirement.
Where a change would mean more of your information leaving your device, or a paid feature working differently, we will tell you at least 30 days beforehand, in the app and at https://sonanote.app/privacy, in a dated version you can keep. If the change is more than minor and you have a subscription, you may end it free of charge within 30 days.