Version: 2026-10-09
Last updated: 2026-10-09
Effective date: 2026-10-09 (the day it is published at type-note.app/privacy/)
1. Who is the controller
The controller of your personal data is:
USŁUGI IT Bartłomiej Józefiak
ul. Krótka 4, 55-081 Maniów Wielki
NIP 8961657099, REGON 542702231
Email: privacy@type-note.app
We have not appointed a Data Protection Officer. All privacy matters go to the address above. Our other contact addresses are on the Contact page.
2. Scope
This policy covers the Type application (web, Android, iOS, iPadOS, macOS, Windows), the "Domowe terminy" (household dates) tool and the website at type-note.app. It does not cover third-party sites we link to.
3. What data we process
3.1 Data you give us
| Data | Where it lives | Notes |
|---|---|---|
| Email address | users table (auth service) | Required. Used to sign in, verify the account, and send service messages. |
| Contact address (Apple accounts without an email address) | user_profiles table (user-service) | You enter it yourself when Sign in with Apple gave us no address. Before we use it, you confirm it with a link in an email (valid for 72 hours). Once confirmed it is used for service messages and billing, including as the customer address at Stripe. |
| Password | users table | Stored only as a salted hash. We never see your password. |
| Nickname, avatar image choice, avatar colour | user_profiles table | Set on first launch. Your nickname is visible to people you share notebooks with, and to people who type it in full in the contact search. |
| Your content: notes, notebooks, tags, lists, tables, polls in notes | note-service / notebook-service databases | The content of your notes is stored as structured text. We do not read it, mine it, or use it to train any model. |
| Files you attach and voice recordings | Cloudflare R2 object storage | A voice recording (up to 10 minutes) is an ordinary note attachment. We do not transcribe recordings. Files are reachable only through signed links valid for one hour. |
| Reminders | application database | The date and time of a reminder on a note; at that time our server sends a push notification. |
| Sharing relationships, contacts and blocks | notebook-service, user-service | Who a notebook is shared with, invitations sent and accepted, and people you blocked. |
| Referrals | user-service | Who invited whom with a referral link — so that PRO from a referral can be granted under the Terms. |
| Messages to us and reports | email inbox (the in-app form reaches it through Resend) | The message text and the reply address, and for the in-app form also your account identifier, platform, app version and language — never the content of your notes. The form is not stored in our database. "Report" on a contact opens an email to us with the reported person's nickname and identifier. |
| Answers in "Domowe terminy" | user-service | The list of items and dates you save with "Save to our shared notebook", without names or email addresses. We keep it for 7 days so that it can reach the notebook after you sign up, then it is deleted. The calendar file (.ics) is made entirely in your browser and never reaches us. |
| Addresses from sign-up forms | leads and lead_emails tables (user-service) | Only with consent confirmed by a click in an email (double opt-in). The type-note.app website has no such form today. |
| Survey answers and conversations with couples | application database, notes from the conversations | Only if you agree to take part (§4). |
3.2 Data created automatically
| Data | Where it lives | Notes |
|---|---|---|
| Account and content timestamps | application databases | Creation and modification times, the author of a change in a shared notebook. |
| Push tokens | device_tokens table | One row per device (token, platform, language, timestamps), only if you enable push notifications. |
| In-app notifications and activity | notifications table | Message text and read state. |
| Link previews | note-service | When you paste a web address, our server fetches the page title to show it in the note. The site you link to sees our server's IP address, not yours. The address and title stay in the note. |
| Server logs | DigitalOcean host | Include IP address, request path, user agent and timestamp. |
| Crash and error reports | Sentry | Stack trace, app version, platform and operating system. We attach no personal data from your device to them. |
| Website analytics events | PostHog (EU) | Only from the type-note.app website, without consent and without cookies, on the basis of legitimate interests — see §4 and §5. The app uses no analytics tools. |
| Billing identifiers | user_profiles, the App Store transaction ledger, and Stripe's or Apple's own records | We store the Stripe customer identifier or the App Store transaction identifiers (with amount and dates), and your plan state. Card numbers never reach our servers. |
3.3 Data from third parties
If you sign in with Google or Apple, we receive the identifiers those providers return — typically your email address and a stable user identifier. We do not receive your password, your contacts, or anything else from your account there. If you use Apple's "Hide My Email", we only ever see the relay address. If Apple gives us no address at all, you can enter a contact address (§3.1).
If you buy PRO in the App Store, Apple sends us information about the transaction (identifier, product, dates, renewal state, any refund). We receive neither your payment details nor your address from Apple.
4. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Creating and running your account; storing, syncing and sharing your notes, files, recordings and reminders; link previews | (b) performance of the contract |
| Service messages: activation, password reset, sharing notifications and reminders | (b) performance of the contract |
| Processing payments, managing subscriptions, refunds, PRO from referrals | (b) performance of the contract |
| Keeping accounting and tax records | (c) legal obligation |
| Keeping the Service secure: abuse and fraud prevention, rate limiting, blocks and reports, revoking compromised sessions | (f) legitimate interest in protecting the Service and its users |
| Diagnosing crashes and errors | (f) legitimate interest in a working product |
| Aggregate figures from the database, e.g. how many couples actively use Type, how many notebooks have two authors, weekly retention — counted from metadata (dates, change authors, note counts), without reading the content | (f) legitimate interest in improving the Service |
| Cookieless analytics on the type-note.app website (§5) | (f) legitimate interest in knowing which pages lead to sign-ups (no cookies, no advertising identifiers, no profiling with legal effect) |
| "Domowe terminy": moving the list into a notebook after sign-up | (b) steps taken at your request before entering into a contract |
| An email inviting couples with paid Pro to a conversation about how they use Type | (f) legitimate interest in improving the Service; the conversation itself only happens with your consent, and you can object to such invitations at privacy@type-note.app |
| The in-app survey and conversations with couples about how they use Type | (a) your consent; the answers are kept in our database |
| Optional onboarding and product emails, and emails to addresses from sign-up forms | (a) your consent, withdrawable at any time via the unsubscribe link in every such message |
| Push notifications | (a) your consent, given through the operating system permission prompt and withdrawable in system settings |
| Replying to messages you send us | (b) or (f) — handling the contract, or our legitimate interest in answering |
We do not sell personal data, do not share it with advertising networks, do not build advertising profiles, and do not use your content to train machine-learning models.
5. Analytics and cookies
- No advertising cookies. No third-party tracking cookies. No cross-site tracking.
- The app uses no analytics tools. It sends no events about how you use it, to PostHog or anyone else, and stores no analytics identifier on your device. We count how many couples use Type from metadata in our database (§4), and learn about errors from crash reports (§3.2).
- Our server may send PostHog events about an account (for example a trial started, a plan bought, renewed or refunded, a referral) only if consent to analytics is recorded on that account. The app currently offers no way to give that consent, so these events are not sent. If we ever turn on analytics in the app, we will first change this policy and ask for your consent (§13).
- On the type-note.app website analytics run without cookies: the library keeps its state in memory only, for the duration of one page view. This is why the site has no cookie banner. The site sends two kinds of event: a page view and a click on a link into the app — no automatic click capture and no session recording. Each event contains: the address of the page viewed without the part after the “?” (domain and path), any
utm_parameters in the address, the domain of the site that sent you to us (without the rest of its address), your browser type and version, operating system, device type (desktop, phone, tablet), screen and browser window size, browser language, time zone, random identifiers of the browser, the visit and the tab, and the version of PostHog's library. Any other address parameters (such asfbclidorgclid) and the full browser description (user agent) are removed from the event before it is sent. The site loads PostHog's script fromeu.i.posthog.comon every visit, so PostHog sees your browser's IP address before it discards it. Links from the site into the app carry a random page-view identifier in the address (thephparameter); the app does not use it and we do not link a website visit to an account. You can object to this analytics (§9). - The app stores strictly necessary data on your device: your session token, your language, theme and interface preferences, and an offline cache of your notes. These are not used for tracking.
If you do not want your account counted in the aggregate figures from the database (§4), write to privacy@type-note.app and we will add it to the exclusion list.
Website events are not linked to an account and stay in PostHog until the end of the period in §7.
6. Who we share data with
We use the following processors. Each acts on our instructions under a data processing agreement.
| Processor | What it processes | Where |
|---|---|---|
| DigitalOcean | Application servers and the database — all account data and note content; daily backups of the whole server | EU (Frankfurt) |
| Cloudflare | Hosting and CDN for the type-note.app website and the web app (IP address, requests); R2 storage for the files and recordings you upload and for database backups; forwarding of incoming mail to @type-note.app addresses | EU / US |
| Google (Gmail) | The inbox that receives messages sent to @type-note.app addresses | EU / US |
| Stripe | Payment data, billing address, tax country, subscription state | EU / US — Stripe is the controller for its own payment and anti-fraud purposes |
| Resend | Email address and message content of transactional and product emails, and messages from the in-app contact form, which reach our inbox through Resend | EU / US |
| Google (Firebase Cloud Messaging) | Push tokens and notification payloads on Android and the web | EU / US |
| Google (gstatic.com) | The web app loads fallback fonts and the Firebase library (browser notifications) from there; Google sees the browser's IP address while doing so | EU / US |
| Apple (APNs) | Push tokens and notification payloads on iOS | EU / US |
| Google Sign-In / Sign in with Apple | Authentication, only if you use them | EU / US |
| PostHog | The analytics events and identifiers from the type-note.app website (§5), without consent, on the basis of legitimate interests (§4). The site loads PostHog's script from eu.i.posthog.com, so PostHog sees the browser's IP address before it discards it. The app sends nothing to PostHog | EU |
| Sentry | Crash and error reports | EU / US |
Apple for App Store purchases. If you buy PRO in the app on an iPhone or iPad, Apple is the seller and a separate controller of the payment data, under its own privacy policy. We only receive the information in §3.3.
We also disclose data where we are legally obliged to (for example a lawful order from a competent authority), and to professional advisers where necessary to establish or defend legal claims.
Transfers outside the EEA. Where a processor operates outside the EEA or may store data in the US ("EU / US" in the table), the transfer relies on the EU–US Data Privacy Framework where the processor is certified under it, and in addition on the European Commission's Standard Contractual Clauses. A copy of the safeguards is available on request from privacy@type-note.app.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and content | For as long as your account exists |
| Notes moved to the trash | 90 days from being moved to the trash, then permanently deleted together with their attachments (sooner, if they are deleted from the trash permanently). FREE accounts see trashed notes from the last 7 days; PRO accounts (including the trial) see all 90 days. Your plan does not change how long we keep them |
| Earlier versions of notes (version history) | 90 days from the moment a newer version replaces them, then deleted automatically. FREE accounts see versions from the last 7 days; PRO accounts (including the trial) see all 90 days. Your plan does not change how long we keep them |
| Answers from "Domowe terminy" | 7 days from saving |
| Addresses from sign-up forms | Until consent is withdrawn — we then stop sending, and the address stays only as a record of the unsubscribe so that it is not signed up again; we delete it on request or together with an account created with that address |
| Survey answers and notes from conversations | Until consent is withdrawn |
| Everything, after you delete your account | Removed from production systems immediately on confirmation, with the exceptions listed in this table; see §8 |
| Account export archive prepared on the server | 7 days from preparation, also if you delete your account in the meantime; then deleted automatically |
| Stripe customer identifier for a Founding Pair place, after account deletion | Up to 31 days from deletion (the clean-up job runs once a day, so about 32 days at most), only so that a full refund within the guarantee period frees the place |
| App Store transaction ledger (the account identifier given to Apple, transaction identifiers, product, amount, dates), after account deletion | Kept under an identifier that can no longer be linked to an account in Type, for as long as tax law requires, like the payment and accounting records (usually 5 years from the end of the tax year); later Apple notifications about that subscription are still recorded in it |
| Pseudonymous pair records for retention statistics (identifiers hashed with a secret key, pair start, whether both wrote between days 7 and 14 and between days 30 and 37; no content) | Up to 37 days from the start of the pair; after the pair splits up or an account is deleted, until the next weekly measurement. After that only aggregate counts without identifiers remain |
| Database backups sent off the server (non-public Cloudflare R2 storage, encrypted by the provider) | Up to 30 days from the backup, then deleted automatically. Used only for disaster recovery |
| Nightly database backups on the server | 14 days. Used only for disaster recovery |
| Daily backups of the whole server at the provider (DigitalOcean) | 7 days. Used only for disaster recovery |
| Database dumps taken before a deployment (on the server) | The last three for each database, about 37 days at most (we delete them after 30 days in a weekly clean-up). Used only to recover from a failed deployment |
| Payment and accounting records | For the period required by tax law (typically 5 years from the end of the tax year) |
| Server logs | Rotated by size (at most three files of 10 MB per service) and also removed whenever a service is redeployed; usually a few days to a few weeks, with no fixed time limit |
| Crash reports | Up to 90 days |
| Analytics events from the type-note.app website | Up to 12 months (§5) |
| Messages to us | For as long as needed to deal with the matter, longer only where needed to establish or defend legal claims |
8. Deleting your account
You can delete your account at any time from the app's settings. Deletion is immediate and irreversible — there is no restore period. Export your notes first if you want to keep them (§9).
Shared notebooks pass to the other person. A shared notebook you own, with all its notes (including the ones you wrote), files and version history, passes to the person you share it with; they receive a notification. We do it this way because a shared notebook is theirs too — otherwise one tap by the other person would wipe the shared contracts, policies and lists. In other people's shared notebooks your earlier entries stay as part of the shared content.
Everything else is deleted from our production systems: your profile and the rest of your account data, your private notebooks and notes (including notes outside any notebook), the files and recordings uploaded to them, the change log of those notes in the co-editing service, and addresses from sign-up forms linked to your account. If the co-editing service is not responding at the moment of deletion, we delete that change log by hand once the outage is fixed. The exceptions, each with its period in §7:
- an account export archive prepared on the server stays for up to 7 days from preparation;
- if you have a Founding Pair place, we keep your Stripe customer identifier for up to 31 days after deletion, only so that a full refund within the guarantee period frees the place; then we delete it;
- the App Store transaction ledger stays under an identifier that can no longer be linked to an account in Type;
- data we are legally required to keep — principally payment and accounting records — is retained for the period stated in §7 and is not used for any other purpose.
A subscription bought through Stripe ends immediately. You have to cancel an App Store subscription with Apple (Settings → Apple ID → Subscriptions); deleting your account does not stop it. The person you gave PRO to under the plan for two goes back to FREE. Residual copies in backups are gone within about 37 days (§7). The pseudonymous record of your pair in our retention statistics is removed at the next weekly measurement (§7).
9. Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- rectify inaccurate data;
- erase your data ("right to be forgotten") — in most cases this is the account deletion in §8;
- restrict processing;
- object to processing based on our legitimate interest, including the website analytics and the aggregate figures in §4;
- portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. You can download a copy of your notes, notebooks and files yourself at any time from the app settings: a single ZIP holding your notes (
notes.mdin Markdown andnotes.json), your notebooks (notebooks.json), your uploaded files (attachments/) and amanifest.jsonthat lists the contents — including any file that could not be included, and why. Our server can also prepare the archive; it then waits 7 days for download (§7). It does not include the trash, version history, your profile (email, nickname, contact address), contacts and blocks, or plan and payment data — we provide those on request. If you would rather we prepared the whole copy, write to privacy@type-note.app; - withdraw consent at any time, where processing is based on consent (product emails — with the unsubscribe link or in Settings; push notifications — in system settings; the survey and conversations — by writing to privacy@type-note.app), without affecting the lawfulness of processing before the withdrawal;
- lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa), or the authority in your country of residence.
Write to privacy@type-note.app to exercise any of these. We acknowledge your request within 2 business days and fulfil it within one month; if a request is complex we may extend that by two further months and will tell you why.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you for such purposes.
11. Age
You may use the Service if you are at least 16 years old. See §5 of the Terms of Use. If we learn that an account was created by someone younger, we delete it together with its data.
12. Security
We use encryption in transit (HTTPS/TLS) everywhere, store passwords only as salted hashes, isolate the services from each other, keep database backups in a separate, non-public storage with the provider's encryption, and restrict administrative access to the production host. Uploaded files are served through time-limited signed links rather than public URLs. No system is perfectly secure; if a breach occurs that is likely to result in a high risk to your rights, we will notify you and the supervisory authority as required by Articles 33–34 GDPR. Report vulnerabilities to security@type-note.app.
13. Changes to this policy
We may update this policy. The version string and the "Last updated" date above change with every revision. Material changes are announced in the application and, where the change concerns processing based on your consent, we ask for that consent again.
14. Contact
USŁUGI IT Bartłomiej Józefiak, ul. Krótka 4, 55-081 Maniów Wielki
Privacy and data protection: privacy@type-note.app
Everything else: type-note.app/en/contact/