Privacy Policy
Notez Note Taker & Voice Summary
Superapp Labs Teknoloji A.Ş.
This Privacy Policy describes how Superapp Labs Teknoloji A.Ş. ("Superapp Labs", "we", "our", or "us") collects, uses, stores, and shares your information when you use Notez (the "Service" or "app") on iOS and Android.
Superapp Labs processes personal data in accordance with applicable data protection laws, including the Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") and, where applicable, the EU/UK General Data Protection Regulation ("GDPR"). Superapp Labs acts as the Data Controller for the personal data described in this policy.
1. Information We Collect
1.1 Content You Provide
When you use Notez, you may provide:
- Audio recordings (in-app voice recordings, meeting recordings).
- Uploaded files and documents (audio files, PDFs, documents, and images attached to notes).
- Text notes you type or paste into the app.
- Free-text questions you ask the features.
- Calendar event metadata for meetings, when you connect a calendar.
- Support messages and feedback (including feature suggestions and any images you attach to them).
When a note is created, its title, transcript, summary, and related content are processed to power features such as summaries and search.
If you use Notez to record audio, you are responsible for obtaining consent from any individuals being recorded, as required by applicable local laws.
Notez is a general-purpose consumer tool and is not intended for special-category or sensitive data. You should not upload health data or other special-category data (Article 9 GDPR / "sensitive personal data" under KVKK) unless you have a lawful basis and accept responsibility for that use. We are not a HIPAA-covered service.
1.2 Account Information
Notez uses anonymous authentication; we do not require you to create an account with a name or password to use core features. In connection with your use of the Service, we may process:
- An anonymous user identifier assigned by our authentication provider.
- Push notification tokens (via Firebase Cloud Messaging), used to deliver notifications you have opted into.
- OAuth tokens for calendar integrations you connect (Google Calendar, Microsoft Outlook), stored securely server-side.
- Subscription status and renewal state, mirrored from our payment/subscription processors.
- Your iOS App Tracking Transparency consent decision (the result, not the prompt content).
1.3 Device and Usage Information
We automatically collect:
- Device model, operating system version, app version, language, and time zone.
- Coarse country, derived from your IP address and/or your App Store / Google Play storefront. We do not collect precise location and do not request a location permission.
- Service usage events: screens viewed, features used, paywall views, conversions, and errors. These power our product analytics and lifecycle notifications.
- Advertising identifiers (IDFA on iOS only after you grant App Tracking Transparency consent; Android Advertising ID where not opted out at the system level) and anonymous identifiers generated by our SDKs at first launch, used for attribution and analytics.
- Crash diagnostics (stack traces, device state at crash time).
2. How We Use Your Information
We use your information to:
- Provide the core product: capture, transcribe, diarize, summarize, translate, and organize your notes and recordings.
- Run our features: summaries, key points, action items, templates, and translation.
- Personalize the experience: language preference, default template, and other settings.
- Communicate with you: important service updates and lifecycle notifications (e.g., reminders, paywall recovery, win-back). You can mute these at the device level.
- Process payments, validate subscription state, and enforce paywalls.
- Measure marketing performance and attribute installs.
- Diagnose crashes, debug issues, and improve product quality.
- Protect the Service against fraud, abuse, and unauthorized access, and comply with legal obligations.
We do not use your recordings, transcripts, summaries, or content to train models, and our providers are contractually required not to train their models on the content we send them through their commercial APIs.
The identifiers and event/install metadata described in this section relate to your use of the app and your device only. They do not include, and we never use for these purposes, any data received from Google APIs (such as your Google Calendar events).
2.1 Legal Bases (GDPR / KVKK)
Where the GDPR or KVKK applies, we rely on: performance of a contract (providing the core product, subscription management, payments); legitimate interests (product quality, debugging, security, fraud prevention, and processing information about other people contained in your recordings); consent (marketing measurement and advertising identifiers, where required); and legal obligation (compliance with lawful requests). Where we rely on consent, you may withdraw it at any time.
3. How We Share Information
3.1 We Do Not Sell Your Personal Information
We do not sell your personal information, recordings, transcripts, or notes, and we do not use your recordings or notes for advertising. We may share limited identifiers and event metadata with attribution and advertising partners to measure marketing performance; under some US state laws this may qualify as "sharing" for cross-context behavioral advertising (see Section 9).
3.2 Categories of Recipients
- Sub-processors that help us operate the Service (Section 4).
- Providers we send your content to in order to deliver features (Section 4.2).
- People you share notes with, when you initiate that sharing (e.g., a shareable link or export).
- Legal authorities, when required by law or to protect rights and safety.
- A successor entity, in the event of a merger, acquisition, or restructuring.
Your recordings, transcripts, and summaries are private and are never shared publicly or used for marketing, except where you choose to export or create a shareable link for a specific note.
4. Sub-Processors
We engage third-party service providers (processors and sub-processors) to deliver the Service. Each processes personal information on our behalf under confidentiality and security obligations.
4.1 Infrastructure, Authentication, and Storage
- Firebase (Google LLC) anonymous authentication, database, push notifications (FCM), serverless runtime, crash diagnostics, and product analytics.
- Cloudflare (Cloudflare, Inc.) object storage (R2) for audio recordings, uploaded documents, and generated outputs, with content delivery through Cloudflare's CDN.
4.2 Third-Party Providers and Data Processing
Notez uses third-party service providers to provide core application functionality, including transcription, speaker diarization, summarization, question answering, translation, document processing, optical character recognition (OCR), embeddings and retrieval, analytics, attribution, and subscription management.
Depending on the feature you use, information shared with these providers may include audio recordings, transcripts, note or document text, chat questions and other prompts, photos or document images, app usage and technical information, device or advertising identifiers, and subscription or purchase information.
We currently use the following third-party providers:
- Microsoft Corporation / Microsoft Azure AI Foundry: provides AI-powered processing for features including summarization, question answering, translation, email summaries, executive summaries, meeting summaries, key-point extraction, study guides, to-do generation, and related AI functionality.
The data sent may include transcripts, note or document text, chat questions and prompts, and other text submitted or generated for AI processing.
- Google LLC / Google Vertex AI: provides AI-powered document processing, including the generation of suggested questions and related document-based AI functionality.
The data sent may include note and document text and other content required to provide the relevant feature.
- Google LLC / Google Generative AI: provides embedding and retrieval functionality used to process and retrieve relevant content.
The data sent may include document chunks, note or document text, search or retrieval queries, and, where applicable, images used for multimodal embedding or retrieval.
- Google LLC / Google Cloud Vision API: provides optical character recognition (OCR) and text extraction from images.
The data sent may include photos, document images, or other images submitted by the user for text extraction.
- Modulate, Inc.: provides speech-to-text transcription and speaker diarization through its Velma speech-to-text services.
The data sent may include audio recordings submitted or uploaded by the user for transcription and diarization.
- fal – Features & Labels, Inc. / Eleven Labs Inc.: may be used as a fallback speech-to-text provider when the primary transcription service is unavailable or when otherwise required to provide the transcription feature.
The data sent may include audio recordings submitted or uploaded by the user for transcription.
- Google LLC / Firebase: provides application analytics, crash reporting, and supporting application infrastructure services.
The data sent may include app usage information, technical and device information, crash and diagnostic information, and identifiers required to provide these services.
- Adjust GmbH: provides attribution and marketing analytics services.
The data sent may include device and advertising identifiers, installation and app-interaction information, and attribution and campaign-related information.
- Adapty Tech Inc.: provides subscription management, paywall functionality, entitlement management, and purchase analytics.
The data sent may include subscription and purchase information, user or account identifiers, and other information required to manage subscriptions and entitlements.
Depending on the provider and feature, Notez may send information directly through the provider's API or provide a secure storage URL from which the provider retrieves the relevant content. These providers process information on our behalf or otherwise in accordance with their applicable terms, contractual obligations, and data protection requirements.
Where applicable, providers used for AI processing are contractually restricted from using content submitted through their commercial or enterprise APIs to train their general-purpose AI models. Providers may retain limited request, response, security, or diagnostic information for purposes such as abuse prevention, security, debugging, and service operation in accordance with their applicable terms and retention practices.
For clarity, the principal categories of data shared with third-party providers are as follows:
- Audio Recordings: may be sent to Modulate, Inc. for transcription and speaker diarization and, where the fallback transcription service is used, to fal – Features & Labels, Inc. / Eleven Labs Inc.
- Transcripts: may be processed through Microsoft Azure AI Foundry for summarization, question answering, translation, meeting summaries, key points, study guides, to-do generation, and related AI functionality.
- Note and Document Text: may be processed through Microsoft Azure AI Foundry, Google Vertex AI, and Google Generative AI for summarization, question answering, suggested questions, embeddings, retrieval, and related AI functionality.
- Chat Questions and Prompts: may be processed through Microsoft Azure AI Foundry to generate AI-powered responses and related outputs.
- Photos and Document Images: may be sent to Google Cloud Vision API for OCR and text extraction and to Google Generative AI where image or multimodal embeddings are required.
- Subscription and Purchase Information: may be processed by Adapty Tech Inc. for subscription, entitlement, paywall, and purchase-related functionality.
- Analytics and Attribution Information: may be processed by Google LLC / Firebase and Adjust GmbH for analytics, diagnostics, attribution, and marketing measurement.
Privacy / Consent Screen
Before user content is shared with third-party AI providers, Notez presents a consent screen describing the relevant third-party providers and the categories of data that may be shared with them.
How to access the screen: Open Settings → Privacy / Data & AI → Third-Party AI Data Sharing.
The screen identifies the relevant third-party AI service providers, including Microsoft Azure AI Foundry, Google Vertex AI / Google Cloud Vision, Modulate, Inc., and fal / ElevenLabs, and explains the categories of user data that may be shared for the applicable functionality.
4.3 Subscription Management and Payments
- Adapty subscription management, receipt validation, and in-app purchase analytics.
- Apple App Store / Google Play payment processing for in-app purchases.
4.4 Attribution and Marketing Analytics
- Firebase Analytics (Google LLC) product and usage analytics.
- Adjust mobile install attribution and event measurement.
- Facebook SDK (Meta Platforms, Inc.) install attribution and conversion measurement.
These partners may receive device identifiers (such as IDFA, IDFV, and Android Advertising ID, subject to your platform settings and consent), event names, and install metadata to measure marketing performance.
The identifiers and event/install metadata described in this section relate to your use of the app and your device only. They do not include, and we never use for these purposes, any data received from Google APIs (such as your Google Calendar events).
4.5 Calendar Integrations
- Google Calendar API when you connect a Google Calendar, we use the Calendar API to read your events on your behalf. We store an OAuth token server-side.
- Microsoft Graph (Microsoft Corporation) when you connect an Outlook or Microsoft 365 calendar, we use Microsoft Graph to read your events and meeting metadata on your behalf. We store an OAuth token server-side.
We will update this list as we add, remove, or change processors.
5. Google API Services — Limited Use
Notez's use and transfer of information received from Google APIs (including the Google Calendar API) adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data obtained from Google APIs is used only to provide and improve user-facing features that are prominent in Notez — specifically, to display your upcoming meetings in the app and to schedule local reminder notifications on your device. It is not used for any other purpose.
In particular, information received from Google APIs is never:
- used to develop, train, test, or improve any artificial-intelligence or machine-learning models;
- used for advertising of any kind, including targeted, personalized, retargeted, interest-based, or user advertisements;
- used for marketing, attribution, or marketing-performance measurement;
- sold, rented, or transferred to data brokers, information resellers, or any third party for their own use;
- used to create or build databases, or for determining credit-worthiness or for lending.
We do not transfer Google API data to any third-party AI/ML service. Google API data is processed only on your device and through Google's own APIs; it is never sent to our servers or to the AI providers that power other features of the app. Human access occurs only in the limited cases permitted by the policy (with your consent, for security, or to comply with law).
6. Data Storage, Encryption, and Retention
6.1 Where Your Data Lives
- Notes, transcripts, summaries, AI outputs, and metadata are stored in our cloud database (Firebase), scoped to your anonymous user identifier.
- Audio recordings, uploaded documents, and generated outputs are stored in Cloudflare R2 with delivery through a content delivery network.
- OAuth tokens for calendar integrations are stored securely, scoped to your account.
- Subscription state is mirrored from Adapty so paywalls can be enforced.
- On-device, we keep light client state (onboarding flags, last-selected language, UI state).
6.2 Encryption
Data is encrypted at rest using vendor-managed AES-256, and all traffic uses TLS 1.2 or higher.
6.3 Retention
- Notes, transcripts, summaries, and associated audio/document files remain until you delete the individual note or your data is deleted (Section 6.4). Deleting a note removes its record and associated file; CDN edge caches expire within 24 hours.
- Cached calendar events are purged after they are no longer needed.
- Provider request/response logs are retained by each provider under its own policy, typically up to 30 days.
- Analytics events are retained under each vendor's plan-level retention policy.
6.4 Deletion
You can delete individual notes at any time from within the app, which removes the note record and its associated audio or document file. To request deletion of your data associated with your device/anonymous identifier, contact support@superapplabs.co. We complete erasure across active systems on a 30-day target and from backups on a 90-day target, except where retention is required by applicable law. Canceling a paid subscription is separate from deleting your data and is done through the store where you purchased it.
7. Information About Other People
Some features cause us to process information about people other than you (for example, attendees in a recorded meeting, or speaker names you assign during diarization). We process that information only to deliver the feature you requested, do not market to those individuals, and do not enrich it from other sources. If you appear in a Notez recording or share and want your information removed, contact support@superapplabs.co.
8. Your Rights
Depending on where you live, you may have rights under the GDPR, KVKK, and similar frameworks, including the right to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent. If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority; in Türkiye, with the Turkish Personal Data Protection Authority (KVKK Kurumu).
In-app controls: delete individual notes; edit note text to correct inaccuracies; disconnect a calendar (Settings); manage microphone, camera, and photo permissions from your device settings; change iOS App Tracking Transparency consent; and manage push notifications.
Requests via support: for rights without a self-serve path, email support@superapplabs.co from the relevant device/account context. We acknowledge requests within a reasonable period and respond within 30 days. If a request is rejected, we provide a justified explanation.
9. Cookies, Push Notifications, and Third-Party Links
- Push notifications. We may send notifications related to service updates, reminders, and offers. You can manage or disable them via your device settings.
- Third-party links. The Service may include links to external services not controlled by Superapp Labs. We are not responsible for their content or practices.
- US state privacy rights. We do not "sell" personal information as defined under applicable US state laws. We may "share" limited identifiers and event metadata for cross-context behavioral advertising; to opt out, email support@superapplabs.co with the subject "Do Not Sell or Share My Personal Information."
The identifiers and event/install metadata described in this section relate to your use of the app and your device only. They do not include, and we never use for these purposes, any data received from Google APIs (such as your Google Calendar events).
10. International Data Transfers
We are based in Türkiye and operate the Service using cloud regions and sub-processors located in Türkiye, the United States, the European Union, and potentially other countries where our providers operate. When you use Notez from outside these regions, your information will be transferred to and processed in them. Where required, transfers rely on the European Commission's Standard Contractual Clauses or equivalent safeguards built into our sub-processors' data-processing agreements.
11. Children's Privacy
Notez is not directed to children under 13 (or under 16 in jurisdictions where that is the relevant age of consent for data processing). We do not knowingly collect personal information from children under those ages. If you believe a child has provided personal information to us, contact support@superapplabs.co and we will delete it.
12. Security
Superapp Labs applies technical and administrative measures to protect personal data, including encryption in transit and at rest, role-based access control, secure authentication to internal systems, logging, and regular security reviews. In the event of a breach, affected users and the relevant authority will be notified as required by law, and corrective actions will be taken.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the new policy on this page and update the "Last Updated" date. For material changes that affect how your data is processed, we will provide additional notice where required by law. Continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Information
- Company Name: Superapp Labs Teknoloji A.Ş.
- Address: EGS Business Park, D Blok, No: 12, Daire: 251, Yeşilköy Mah., Atatürk Cad., Bakırköy, Istanbul, Türkiye
- Email: support@superapplabs.co
- Phone: +90 212 909 17 35
As the company is established in Türkiye, the Turkish data protection law (KVKK) and the Turkish Personal Data Protection Authority apply to our processing, alongside the GDPR and UK GDPR where they apply to EEA and UK users.
© 2026 Superapp Labs Teknoloji A.Ş. All rights reserved.
