Noeta is operated by 深圳市宇渡智能科技有限公司 ("we", "us", or the "operator"). Noeta ("the app") is a private notebook that helps you keep notes about the people in your life and offers AI-assisted insights. We keep data collection to what is needed to run the app and give you control over your information.
1. Information we collect
- Account information. Noeta works without an account. If you choose Sign in with Apple, we receive a user identifier and may receive your name and an email address (which Apple may relay), used to secure and manage your account. Your account does not carry your notes.
- Content you create. Your notes, people, relationships, analyses, chats, usage footprint, images, and audio are primarily stored on your device and are not used for multi-device content sync. During the beta testing program, signed-in test accounts upload one overwrite-in-place diagnostic snapshot containing the latest structured notes, people, relationships, transcripts, and AI results. Image and audio file bytes are not included. The snapshot is linked to the test account and is used only by the development team to reproduce and fix beta issues. When you invoke an AI feature, only the context needed for that request is encrypted in transit and sent to the configured AI provider for processing. For an event analysis, that context may include a bounded one-hop relationship relevant to the event and the local notes supporting it; Noeta does not send the whole relationship graph by default. Which provider is configured depends on your language and region settings and on network signals (the service may return a coarse region hint — mainland China or international — derived from the request's network address; the app stores only that hint, not the address): mainland-China requests use mainland providers for applicable extraction, image, and speech tasks and may use Anthropic for analysis or chat as listed below, while international requests are routed only to international providers. Provider retention is governed by that provider's applicable terms; Noeta does not claim that every provider offers zero retention. On supported Apple devices, imported audio is transcribed on-device first. If on-device transcription is unavailable or fails, Noeta asks for permission before sending that audio over an encrypted connection to the configured AI transcription provider. Declining leaves the original recording on the device. For live voice input in the Chinese mainland region, the audio stream is sent over an encrypted connection to a speech-recognition provider operating in mainland China only while you are dictating, and is used solely to produce the transcript; Noeta's own servers never receive or store this audio. To improve recognition of names, the display names and aliases from your people list may accompany such requests. When the cloud service is unavailable (or in the international region), recognition runs on-device instead. Before any private content is sent for cloud AI processing, Noeta presents a versioned disclosure that identifies the data categories, recipients, and purpose, and asks you to choose Allow AI processing or Not now — keep notes local. No private content is sent until you allow it. Declining does not prevent local recording. You can later allow or revoke this permission under Me → Privacy & Data → Cloud AI Data Processing; revoking blocks new text, image, embedding, audio-file, and live cloud-speech requests. Depending on the requested feature, language, and region, relevant content may be processed by one or more of these named AI service providers: Volcengine/ByteDance (Doubao/Ark), Alibaba Cloud (Qwen/Bailian), Anthropic (Claude), Google (Gemini), and OpenAI. International content is not routed to mainland-China providers. Except for the live speech path expressly described above, requests may pass through Noeta's operator-run proxy or gateway before reaching the assigned provider. We select and configure these providers under applicable service and data-processing terms and require them to use the data only to provide the requested service and protect it under contractual and security obligations consistent with this policy.
- Anonymous product usage data. By default, Noeta assigns a random identifier to this installation and records screen visits, semantic actions, action order, active duration, success/failure, app version, and platform. This identifier is not linked to your account. We do not include note text, names, transcripts, AI results, images, audio, filenames, or local paths. You can disable this anytime under Me → Privacy & Data → Anonymous Usage Data; disabling it also removes events that are still waiting on your device to upload. This setting is separate from the signed-in beta diagnostic snapshot described above.
- AI service operation and quota data. For AI requests, Noeta uses a separate random installation identifier. The server converts it with a secret keyed hash and stores only the resulting opaque hash and a short support code. We record metadata such as the AI capability, provider/model, status, latency, payload byte count, weighted cost, retry/failure stage, and time. To enforce and explain beta quotas, we also keep quota balances, redeem-code redemption history, and anonymous referral relationships. A referral record uses the same opaque quota subjects for the inviter and invitee, the generated referral code, snapshotted benefit amounts, status, and qualifying event token; it does not contain account or content data. The device sends aggregate counts of locally stored events, people, and user chat messages. For event analysis, the device sends a SHA-256 token derived from the local event ID so the service can count successful analyses and regenerations without receiving that local ID. These operational records do not contain note or chat text, names, transcripts, AI output, images, audio, filenames, paths, credentials, or the raw installation identifier, and are not linked to an account. Because the opaque quota identifier remains stable for this installation, these records can be associated over time with the same installation, but not with an account unless a future account migration is separately introduced and disclosed. On a true first installation, you may optionally enter a separately issued source attribution code. We then store that code's campaign/channel label, the same opaque installation subject, and the attribution time to measure anonymous acquisition sources. It grants no benefit, does not consume or prevent a later friend-referral binding, and does not include your notes, people, chats, or AI results. Quota and referral records are required to provide quotas and support; a source-attribution record is created only if you enter a source code. Both are collected independently of the optional Anonymous Usage Data setting.
- Optional notification data. On first open, Noeta separately asks for system notification permission. Only if you allow it, Noeta creates another random installation identifier and sends the APNs device token, notification preference, locale, app version, and delivery/click status to our server. The identifier is separate from analytics and quota identifiers and is not linked to an account. Apple Push Notification service receives the token and generic notification payload to deliver the notification. A rich notification may include a URL to campaign image, audio, or video hosted by Noeta, which the device downloads from our controlled domain. Notifications never include your names, notes, relationship details, profiles, chats, or user-created image/audio content. You can disable this under Me → Preferences or in iOS Settings.
- Subscription and payment data. If subscription payments are made available and you choose to purchase, we process the same opaque quota subject hash and support code described above, selected plan, order number, price and currency, payment channel, payment/renewal/refund/revocation status, platform transaction identifier (including Apple's original transaction identifier where applicable), entitlement period, and security or reconciliation metadata. For App Store privacy disclosure purposes, this purchase history is treated as linked to the installation because it remains associated with the same opaque quota subject for entitlement delivery, support, and reconciliation. It is used for app functionality, purchase restoration, refunds, security, fraud prevention, and legal or tax reconciliation; it is not used for advertising or cross-app tracking. When you restore an active Apple subscription on another device using the same Apple ID, the verified original transaction may be used to transfer the current membership entitlement to the new installation's opaque subject. This does not transfer or restore your local notes. Payment records do not store the raw installation UUID, hardware identifier, Apple account, WeChat identity, or your notes and chats. Apple processes iOS in-app purchases and WeChat Pay processes supported Android payments under their own policies. We do not receive your full bank-card number, payment password, or Apple/WeChat account password. The payment entry is remotely controlled and may remain unavailable while the feature is being tested.
2. How we use information
To provide and maintain the app, including account sign-in, subscription entitlement delivery, payment reconciliation, refunds, and beta issue diagnosis; to provide AI-assisted features (for which relevant content is processed by us and/or trusted third-party providers solely to produce the result); to keep the service reliable and secure; and to respond to support requests. We do not use your content for advertising, and we do not sell your data.
3. Storage, system backup, and encrypted migration
Your content is primarily stored on your device and Noeta does not provide active multi-device content sync. During beta testing, the latest structured diagnostic snapshot for a signed-in test account is stored on Noeta's server as described above. If you enable Apple system device backup, local content may be included under Apple's and your control. You may request “Manual backups only” in Noeta; losing the device without a valid backup may then permanently lose the content. You can export a password-encrypted .noeta backup, or explicitly save the latest encrypted snapshot to your own iCloud Drive on iOS or a system-selected cloud folder on Android. Manual cloud backup is always available after setup; automatic backup is a separate opt-in setting and runs while the app is active. Noeta keeps only the latest successfully verified cloud snapshot. The selected storage provider receives the encrypted file and ordinary file metadata such as its name, size, and modification time. Noeta's servers receive neither the backup file nor its recovery password, and Noeta cannot recover a forgotten password. After reinstalling or changing devices, use the same iCloud account on iOS, or select the same cloud folder again on Android, then enter the recovery password to restore.
4. Sharing
We share information only with service providers that help us operate the app, including the named AI providers Volcengine/ByteDance, Alibaba Cloud, Anthropic, Google, and OpenAI, cloud hosting, Apple in-app purchase, and WeChat Pay. We use contractual and technical controls that limit their use to providing the requested services and require protections consistent with this policy, or share where required by law. We never sell your data.
5. Retention & deletion
The beta diagnostic table keeps only the latest overwrite-in-place snapshot for an account. It is deleted when the account is deleted and will be removed when the beta diagnostic program ends. Anonymous product events, AI call logs, client error diagnostics, and settled weighted-cost ledger entries are retained for up to 90 days. Notification delivery/click records are also retained for up to 90 days. An operator-uploaded campaign media asset may remain available for up to 90 days. An APNs token and its separate installation identifier are retained while notifications are enabled, and disabled when you turn them off or APNs reports that the token is no longer valid. The opaque quota subject and support code, current quota balances, redeem-code redemption, anonymous referral and optional source-attribution records, latest aggregate inventory counts, and opaque event-analysis counters may be kept while the beta quota/support program operates so quotas, regeneration counts, and support restoration remain accurate. Content on your device is removed when you delete the app or clear it in-app. If you signed in, you can permanently delete your account and its associated account data directly in the app: Me → account card → "Delete account". Deletion takes effect immediately and cannot be undone; we retain only limited records required for security or legal compliance. You may also request deletion at the contact below. Payment and transaction records may be retained for the period required for reconciliation, refunds, tax, anti-fraud, and other legal obligations, even after an account is deleted; retained records are limited to what those purposes require.
6. Security
Encrypted transport (HTTPS/TLS); server-side data protected with access controls.
7. Your choices
Use the app without an account (no account-linked diagnostic snapshot); explicitly allow or revoke cloud AI data processing while keeping local recording available; enable or disable anonymous usage data independently; choose the system-backup mode; export or restore an encrypted backup; manually save the latest encrypted snapshot to your own cloud storage; separately opt in to or turn off automatic cloud backup; independently enable or disable product-announcement notifications; sign out; or request account deletion and clear local content separately.
8. Children
Not directed to children under 13 (or the minimum age in your region).
9. Changes
We may update this policy and will revise the effective date above.
10. Contact
Operator: 深圳市宇渡智能科技有限公司
Email: support@noetaapp.com
APP filing number: 粤ICP备2026115840号-1A (MIIT filing lookup)