Noeta
Home中文
Legal

Privacy Policy

Effective: August 4, 2026

Operator深圳市宇渡智能科技有限公司support@noetaapp.com

Noeta is operated by 深圳市宇渡智能科技有限公司 ("we", "us", or the "operator"). Noeta ("the app") is a private notebook that helps you keep notes about the people in your life and offers AI-assisted insights. We keep data collection to what is needed to run the app and give you control over your information.

1. Information we collect

  • Account information. Noeta works without an account. If you choose Sign in with Apple, we receive a user identifier and may receive your name and an email address (which Apple may relay), used to secure and manage your account. Your account does not carry your notes.
  • Content you create. Your notes, people, relationships, analyses, chats, usage footprint, images, and audio are primarily stored on your device and are not used for multi-device content sync. During the beta testing program, signed-in test accounts upload one overwrite-in-place diagnostic snapshot containing the latest structured notes, people, relationships, transcripts, and AI results. Image and audio file bytes are not included. The snapshot is linked to the test account and is used only by the development team to reproduce and fix beta issues. When you invoke an AI feature, only the context needed for that request is encrypted in transit and sent to the configured AI provider for processing. For an event analysis, that context may include a bounded one-hop relationship relevant to the event and the local notes supporting it; Noeta does not send the whole relationship graph by default. Which provider is configured depends on your language and region settings and on network signals (the service may return a coarse region hint — mainland China or international — derived from the request's network address; the app stores only that hint, not the address): requests from mainland China are processed by providers operating there, while international requests are routed to international providers. Provider retention is governed by that provider's applicable terms; Noeta does not claim that every provider offers zero retention. On supported Apple devices, imported audio is transcribed on-device first. If on-device transcription is unavailable or fails, Noeta asks for permission before sending that audio over an encrypted connection to the configured AI transcription provider. Declining leaves the original recording on the device.
  • Anonymous product usage data. By default, Noeta assigns a random identifier to this installation and records screen visits, semantic actions, action order, active duration, success/failure, app version, and platform. This identifier is not linked to your account. We do not include note text, names, transcripts, AI results, images, audio, filenames, or local paths. You can disable this anytime under Me → Privacy & Data → Anonymous Usage Data; disabling it also removes events that are still waiting on your device to upload. This setting is separate from the signed-in beta diagnostic snapshot described above.
  • AI service operation and quota data. For AI requests, Noeta uses a separate random installation identifier. The server converts it with a secret keyed hash and stores only the resulting opaque hash and a short support code. We record metadata such as the AI capability, provider/model, status, latency, payload byte count, weighted cost, retry/failure stage, and time. To enforce and explain beta quotas, we also keep quota balances, redeem-code redemption history, and anonymous referral relationships. A referral record uses the same opaque quota subjects for the inviter and invitee, the generated referral code, snapshotted benefit amounts, status, and qualifying event token; it does not contain account or content data. The device sends aggregate counts of locally stored events, people, and user chat messages. For event analysis, the device sends a SHA-256 token derived from the local event ID so the service can count successful analyses and regenerations without receiving that local ID. These operational records do not contain note or chat text, names, transcripts, AI output, images, audio, filenames, paths, credentials, or the raw installation identifier, and are not linked to an account. Because the opaque quota identifier remains stable for this installation, these records can be associated over time with the same installation, but not with an account unless a future account migration is separately introduced and disclosed. They are required to provide quotas and support and are therefore collected independently of the optional Anonymous Usage Data setting.
  • Optional notification data. On first open, Noeta separately asks for system notification permission. Only if you allow it, Noeta creates another random installation identifier and sends the APNs device token, notification preference, locale, app version, and delivery/click status to our server. The identifier is separate from analytics and quota identifiers and is not linked to an account. Apple Push Notification service receives the token and generic notification payload to deliver the notification. A rich notification may include a URL to campaign image, audio, or video hosted by Noeta, which the device downloads from our controlled domain. Notifications never include your names, notes, relationship details, profiles, chats, or user-created image/audio content. You can disable this under Me → Preferences or in iOS Settings.
  • Subscription and payment data. If subscription payments are made available and you choose to purchase, we process your Noeta account identifier, selected plan, order number, price and currency, payment channel, payment/renewal/refund status, platform transaction identifier, entitlement period, and security or reconciliation metadata. Apple processes iOS in-app purchases and WeChat Pay processes supported Android payments under their own policies. We do not receive your full bank-card number, payment password, or Apple/WeChat account password. The payment entry is remotely controlled and may remain unavailable while the feature is being tested.

2. How we use information

To provide and maintain the app, including account sign-in, subscription entitlement delivery, payment reconciliation, refunds, and beta issue diagnosis; to provide AI-assisted features (for which relevant content is processed by us and/or trusted third-party providers solely to produce the result); to keep the service reliable and secure; and to respond to support requests. We do not use your content for advertising, and we do not sell your data.

3. Storage, system backup, and encrypted migration

Your content is primarily stored on your device and Noeta does not provide active multi-device content sync. During beta testing, the latest structured diagnostic snapshot for a signed-in test account is stored on Noeta's server as described above. If you enable Apple system device backup, local content may be included under Apple's and your control. You may request “Manual backups only” in Noeta; losing the device without a valid exported backup may then permanently lose the content. You can export a password-encrypted .noeta backup and restore it on another device. Noeta does not receive the file or password and cannot recover a forgotten password.

4. Sharing

We share information only with service providers that help us operate the app (such as cloud hosting, AI processing, Apple in-app purchase, and WeChat Pay), under agreements limiting their use to providing services to us, or where required by law. We never sell your data.

5. Retention & deletion

The beta diagnostic table keeps only the latest overwrite-in-place snapshot for an account. It is deleted when the account is deleted and will be removed when the beta diagnostic program ends. Anonymous product events, AI call logs, client error diagnostics, and settled weighted-cost ledger entries are retained for up to 90 days. Notification delivery/click records are also retained for up to 90 days. An operator-uploaded campaign media asset may remain available for up to 90 days. An APNs token and its separate installation identifier are retained while notifications are enabled, and disabled when you turn them off or APNs reports that the token is no longer valid. The opaque quota subject and support code, current quota balances, redeem-code redemption and anonymous referral records, latest aggregate inventory counts, and opaque event-analysis counters may be kept while the beta quota/support program operates so quotas, regeneration counts, and support restoration remain accurate. Content on your device is removed when you delete the app or clear it in-app. If you signed in, you can permanently delete your account and its associated account data directly in the app: Me → account card → "Delete account". Deletion takes effect immediately and cannot be undone; we retain only limited records required for security or legal compliance. You may also request deletion at the contact below. Payment and transaction records may be retained for the period required for account reconciliation, refunds, tax, anti-fraud, and other legal obligations, even after an account is deleted; retained records are limited to what those purposes require.

6. Security

Encrypted transport (HTTPS/TLS); server-side data protected with access controls.

7. Your choices

Use the app without an account (no account-linked diagnostic snapshot); enable or disable anonymous usage data independently; choose the system-backup mode; export or restore an encrypted backup; independently enable or disable product-announcement notifications; sign out; or request account deletion and clear local content separately.

8. Children

Not directed to children under 13 (or the minimum age in your region).

9. Changes

We may update this policy and will revise the effective date above.

10. Contact

Operator: 深圳市宇渡智能科技有限公司 Email: support@noetaapp.com

NoetaRelationship intelligence, kept private
PrivacyTerms
© 2026 深圳市宇渡智能科技有限公司