Back to portfolio
ninote robot icon

ninote / PRIVACY

ninote Privacy Policy

ninote turns recordings, documents, images, text, and public YouTube videos into notes and study material. This policy explains how labzeetech, the operator of ninote, handles information when you use the app.

Last updated:

1. Information we handle

Account and preferences. You can use a guest account or connect with Apple or Google where available. We store an internal account identifier, authentication sessions, your profile name, language, and preferences. Connected sign-in can provide an email address, name, and provider identifier; Apple may provide a relay email address. A guest account does not require an email address, but its notes are still associated with an account identifier.

Your material. We receive text you paste or type, audio you record or import, images or scanned pages, PDFs, and public YouTube links you submit. We also store related titles, folders, file details, transcripts, summaries, mind maps, flashcards, quizzes, and other generated study material.

Conversations. We process your questions, messages, selected note context, and AI responses. When you use live voice, your microphone audio is sent to the voice provider, and conversation transcripts are saved in your chat. Speech dictation also sends the recorded audio for transcription.

Service and support data. Depending on the enabled features, we receive purchase and subscription information, usage events, device and app information, diagnostic reports, and support messages or attachments you choose to send. Network services also receive technical connection information, such as IP addresses, when your device connects.

2. How we use information

We use your information to maintain your library, authenticate your session, process source material, generate study content, answer questions, save conversations, and provide exports you request. We also use it to verify paid access, restore purchases, provide support, diagnose failures, understand app usage, and protect the service from misuse.

Where applicable data protection law requires a legal basis, we process information necessary to provide the service you request, use consent for processing that requires it, and rely on legitimate interests in operating, securing, and improving the service where those interests are not overridden by your rights. We may also retain or disclose information to meet legal obligations. You may withdraw consent for optional processing without affecting the lawfulness of earlier processing.

3. AI processing and your content

AI features require processing outside your device. Relevant source files, text, transcripts, questions, conversation history, and note context are sent to the services needed for the feature you use. This may include the complete source material, rather than only a short excerpt.

ninote uses Vercel AI Gateway to route processing to AI inference providers. The current model configuration includes OpenAI, Google Gemini, and xAI/Grok; generated visual notes may also use Black Forest Labs models. Some configurations use Google Gemini directly. The model and provider used can depend on the source format, feature, subscription tier, and service configuration; the company hosting a model may differ from its developer.

Live voice conversations use Vercel AI Gateway with Google Gemini or OpenAI, which receive microphone audio and relevant note or conversation context to generate spoken answers. YouTube processing sends the public video link for processing and retrieves video metadata from YouTube.

In app versions with AI permission controls, ninote asks before uploading material or starting AI processing. The prompt names the services and data shared. Choosing Not now keeps your draft and existing notes available. You can withdraw permission under Settings → Privacy & AI; this stops new AI requests and ends an active live voice session on that device. Requests already sent may finish, and withdrawal does not delete stored data. The choice is saved on your device and cleared when you log out or delete your account.

Provider retention and handling depend on the service, endpoint, and applicable agreement. This policy does not promise that every AI request has zero retention or that every provider uses identical training policies. Only submit material you are entitled to share and have processed, including permission from other people whose voices or information appear in it.

4. Services that receive information

Convex provides the backend database, file storage, authentication and account storage, and processing infrastructure for your account, notes, uploads, and chats. Vercel and the relevant AI providers process content as described above.

RevenueCat and Apple handle subscription-related services on iOS. RevenueCat receives an app user identifier, transaction and receipt information, and subscription status to verify access and restore purchases. Apple handles App Store payment details; ninote does not receive your full payment card number.

PostHog provides product analytics as described below. Sentry provides error and crash reporting, diagnostic logs, and sampled diagnostic session replays when configured. These can include device and app information, screen interactions, and context associated with an error. Diagnostic recordings may contain information visible on screen; avoid including unnecessary personal information in support or error reports. Crisp provides in-app support chat when enabled and processes the messages, attachments, contact details such as a name, email address or phone number you provide, and technical session information associated with that support interaction. Crisp may infer a coarse country or region from your IP address for support and usage reporting; ninote does not request precise device location.

The services used depend on your app version, platform, and enabled features. We may also share information where needed to comply with law, protect rights or security, or carry out a business transfer subject to applicable privacy obligations.

The current app does not include an advertising network integration or a feature that sells your note content. When you export or share material, the destination app, service, or recipient you choose receives it and handles it under its own practices.

5. Analytics and diagnostics

When usage analytics is enabled, PostHog receives an installation identifier, app opens and active days, fixed screen names, time spent on screens, navigation or background exits, onboarding progress, note-processing success or failure, language, subscription status, and app/device metadata. These events help us measure return visits during the first seven days and find where people leave a flow. They do not include note titles or bodies, source files, prompts, transcripts, or free-text onboarding answers.

A random installation identifier is pseudonymous: it links activity across sessions even without your name or email. Current product events do not create named person profiles or use your account identity for analytics. IP-based geolocation is disabled in the app’s PostHog configuration. Analytics are enabled by default when configured; turn Usage analytics off under Settings → Privacy & AI to stop future product analytics events. Turning it off does not erase events already received.

The current app does not request App Tracking Transparency permission, collect an advertising identifier for advertising, or use these analytics to track activity across other companies’ apps and websites for targeted advertising or advertising measurement. PostHog session replay is disabled in the current app. Older versions may have different controls; this policy describes the current version.

The usage analytics setting is separate from Sentry diagnostics, including diagnostic session replays, and does not turn them off. It also does not disable cloud processing needed for requested features, subscription verification, or support interactions. Contact us about diagnostic data or deletion requests. A seven-day retention report describes return visits; it is not a promise to delete analytics data after seven days.

6. Device permissions and local storage

Microphone access supports recording, dictation, and live voice. Camera and photo access support scanning or selecting images. The document picker lets you select files to import. Notification permission supports local reminders, including trial reminders when available. You can change permissions in your device settings; denying a permission can prevent the associated feature from working.

ninote stores settings, installation identifiers, permission choices, recording drafts, and pending conversation transcripts locally. Native authentication credentials use secure device storage. The app also stores whether it has offered a store review and when, to avoid repeated requests. If you choose to rate the app, the App Store or Google Play handles the review; ninote does not receive your rating through the in-app review API. Recordings, temporary files, and exported documents may remain on your device or in a location you choose. Local reminders are scheduled on the device.

7. Retention and deletion

Your cloud library is retained so you can return to it. Deleting a note removes its stored source and transcript and schedules removal of related study content and discussions. Profile → Account Status → Delete Account starts background deletion of your account, notes, uploads, folders, preferences, authentication records, and associated app data. Deletion is processed in batches and may not finish immediately.

Public YouTube transcripts and generated study material may be cached and reused across users. Those shared caches exclude your personal titles, edits, uploads, and account data and can remain after you delete your copy of a note or your account.

Temporary uploaded speech files used for dictation are scheduled for removal after the transcription attempt. Deleting cloud data does not automatically erase exports, copies you shared, local files, or records held separately by service providers. Provider logs, backups, support conversations, diagnostics, and purchase records may remain according to the relevant service’s retention settings and legal requirements. Contact us to request deletion of information outside the in-app deletion flow.

Logging out or uninstalling the app is not a request to delete your cloud library, and a guest session may be difficult to recover. Export anything you need and use account deletion before leaving if you want the cloud account removed. Deleting an account does not cancel an App Store subscription; manage that subscription through Apple.

8. Security and international processing

The app uses authenticated access checks for private account content and encrypted network connections to its cloud services. No storage or transmission system can be guaranteed completely secure, and cloud AI processing means this is not an end-to-end encrypted service in which only you can read the content.

Our service providers may process information outside your country, including in the United States and other countries where the selected providers operate. PostHog’s default ingestion service is in the United States. Protections and available rights can vary by jurisdiction. Contact us for information about the providers and transfer arrangements relevant to your request.

9. Your choices and privacy requests

You can edit your profile preferences, delete notes or your account, choose what to upload, manage device permissions, and use the available sharing and export features. You can also contact us to request access to, correction of, a copy of, or deletion of personal information. Depending on your location, you may have rights to object to or restrict processing, withdraw consent, request portability, or complain to your local data protection authority.

Email contact@labzeetech.com and identify ninote and the nature of your request. We may need enough information to verify your connection to a guest account or support conversation before acting. Do not send passwords, payment card details, or unnecessary private note content.

10. Children’s information

If you are a parent or guardian and believe a child has provided personal information to ninote without the authorization required by applicable law, contact us so we can investigate and address the information, including deletion where appropriate.

11. Changes to this policy

We may update this policy as ninote’s features and data practices change. We will revise the date on this page and provide additional notice or request consent where required. This app-specific policy governs ninote if a general labzeetech mobile-app privacy page describes different practices.