Back to SmartNoter
S
SmartNoter

Privacy Policy

Last updated: August 1, 2026

At SmartNoter, we take your privacy seriously. This policy explains what data we collect, how we use it, and the measures we take to protect it.

1. Information We Collect

SmartNoter collects the following types of information to provide and improve our services:

Account Information: When you create an account, we collect your name, email address, and hashed password. Admin accounts are configured via secure environment variables.

Note Content: Notes you create, edit, or polish are stored in our MongoDB Atlas database. This includes text content, tags, timestamps, and media attachments.

Voice Transcriptions: Audio recordings submitted for transcription are processed via the Mistral AI API. Audio files are not permanently stored on our servers after processing is complete.

Usage Data: We collect anonymized usage analytics including feature usage frequency, session duration, and error logs to improve app stability.

Device Information: For error reporting, we may collect device model, OS version, and screen context to help diagnose issues.

2. How We Use Your Information

We use collected information for the following purposes:

Service Delivery: To provide note storage, AI-powered polishing, voice transcription, and chat features.

Authentication: To verify your identity and manage access levels (admin, user, guest).

AI Processing: Note content is sent to the Mistral AI API for polishing and transcription. This data is processed in accordance with Mistral's privacy policy.

Analytics: To monitor service health, track feature adoption, and diagnose technical issues.

Communication: To send important service updates, security alerts, and respond to support requests.

3. Data Storage & Security

Your data security is our top priority:

Encryption in Transit: All data transmitted between the app and our servers is encrypted using TLS/SSL.

Password Security: Passwords are hashed using bcrypt with 12 rounds of salting. We never store plaintext passwords.

JWT Authentication: Session tokens are signed using HS256 JWT with a secure secret key. Tokens expire after 30 days.

Database: User data and notes are stored in MongoDB Atlas with encrypted connections and access controls.

Infrastructure: Our backend runs on secure cloud infrastructure with firewall protection and regular security audits.

Guest Sandboxing: Guest accounts are automatically cleaned up after 48 hours of inactivity.

4. Data Sharing & Third Parties

We do not sell your personal data. We share data only with the following service providers for specific purposes:

Mistral AI: Note content is sent to Mistral's API for AI-powered polishing and voice transcription. This is processed in accordance with Mistral's privacy policy.

MongoDB Atlas: Our database is hosted on MongoDB Atlas's cloud infrastructure. Data is stored in encrypted databases with strict access controls.

Google Play Billing: Subscription purchases are processed through Google Play's billing system. We do not have access to your payment card details.

5. Data Retention

Account Data: We retain your account information for as long as your account is active. You may request account deletion at any time.

Note Content: Notes are stored until you delete them or request data removal.

Guest Data: Guest session data is automatically purged after 48 hours of inactivity.

Error Logs: Error and crash logs are automatically deleted after 90 days via TTL index.

Voice Audio: Transient audio files submitted for transcription are not permanently stored and are discarded after processing.

6. Your Rights

You have the following rights regarding your data:

Access: You can view all your notes and account data within the app.

Export: You can export your notes in standard formats from the app.

Deletion: You can delete individual notes or request complete account and data deletion.

Correction: You can edit your profile information and notes at any time.

Portability: You may request a copy of all your data in a machine-readable format.

To exercise any of these rights, please contact us at the email address below.

7. Children's Privacy

SmartNoter is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete that information promptly.

8. Subscriptions & Payments

SmartNoter offers optional subscription plans (Pro and Elite tiers) with monthly and yearly billing options.

All subscription payments are processed securely through Google Play Billing. We do not store or have access to your credit card or payment information.

Subscriptions automatically renew unless cancelled at least 24 hours before the current period ends.

You can manage, pause, or cancel your subscription through your Google Play account settings.

A 7-day free trial is offered for new subscribers. The trial can be cancelled at any time through Google Play.

9. Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will notify you through the app and/or via email before the changes take effect.

Your continued use of SmartNoter after the changes become effective constitutes your acceptance of the updated policy.

The "Last Updated" date at the top of this page indicates when this policy was last revised.

10. Contact Us

If you have any questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

Email: talha@brevios.com

GitHub: github.com/Talha-SE/Smart-AI-Notes

We aim to respond to all privacy-related inquiries within 30 days.

© 2026 SmartNoter. All rights reserved.