Skip to main content

Privacy Policy

Effective Date: 14 August 2026
Controller: Noteastic OG, Anton-Baumgartner-Straße 44, C8/1504, 1230 Wien, Österreich (FN 644438 d; UID ATU81638239)
Language: English (British)


1. Definitions and Interpretation

1.1 Definitions

In this Policy, capitalised expressions have the meanings set out below. Terms defined in the Terms of Service have the same meaning here unless a different meaning is given.

  • “Account” means the user account required to access the Application.
  • “Account Data” has the meaning set out in Section 5.1(a).
  • “Advertising Measurement Data” has the meaning set out in Section 5.1(k).
  • “Advertising Networks” means, collectively, the providers identified in Section 7.3(d) through which We place Our advertising and measure its effectiveness.
  • “Application” or “Noteastic Application” means the Noteastic software application for Microsoft Windows, distributed through the Microsoft Store.
  • “Attribution Data” has the meaning set out in Section 5.1(c).
  • “Billing Data” has the meaning set out in Section 5.1(g).
  • “Campaign Identifier” has the meaning set out in Section 5.1(l).
  • “Consent Mode” means the mechanism described in Section 11.4.3 by which We signal a Website visitor’s consent decision to the Advertising Networks.
  • “Controller” has the meaning given in Article 4(7) GDPR.
  • “Correspondence Data” has the meaning set out in Section 5.1(d).
  • “Currency-Geolocation Data” has the meaning set out in Section 5.1(i).
  • “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
  • “EEA” means the European Economic Area.
  • “Feedback Data” has the meaning set out in Section 5.1(e).
  • “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
  • “Microsoft Store” means the digital distribution platform operated by Microsoft Corporation.
  • “Newsletter” means Our optional email newsletter, comprising the thematic content categories described in Section 5.1(j), sent only to Users who have subscribed to it.
  • “Newsletter Data” has the meaning set out in Section 5.1(j).
  • “Noteastic”, “We”, “Us”, or “Our” means Noteastic OG, the legal entity identified in Section 2.
  • “Personal Data” has the meaning given in Article 4(1) GDPR.
  • “Policy” or “Privacy Policy” means this document.
  • “Processing” (and its cognate expressions) has the meaning given in Article 4(2) GDPR.
  • “Services” means the Application, the Website, and any related services We provide, including Subscription handling.
  • “Stripe” means Stripe Payments Europe Limited, an Irish entity within the Stripe group of companies, acting as Our payment processor.
  • “Sub-Processor” means any Processor engaged by Us to Process Personal Data on Our behalf.
  • “Subscription” means a recurring agreement to access the Pro Plan in exchange for a periodic Subscription Fee, as defined in the Terms of Service.
  • “Telemetry” has the meaning set out in Section 5.1(b).
  • “Terms of Service” means Our separately published Terms of Service, available at https://www.noteastic.app/en/legal/terms-of-service.
  • “User”, “You”, or “Your” means an individual who uses the Services.
  • “Website” means the website located at noteastic.app and its subdomains.
  • “Website Analytics Data” has the meaning set out in Section 5.1(f).

1.2 Interpretation

(a) Headings are for convenience only and do not affect interpretation.
(b) References to a Section are to a section of this Policy unless stated otherwise.
(c) The singular includes the plural and the plural includes the singular.


2. Controller Identity and Contact

The Controller of Personal Data Processed under this Policy is:

Noteastic OG
Anton-Baumgartner-Straße 44, C8/1504
1230 Wien, Österreich

We have not appointed a Data Protection Officer. We are not required to do so under Article 37 GDPR given Our size, structure, and Processing activities. The privacy contact above is the designated point of contact for all data-protection matters.


3. Scope of this Policy

This Policy applies to all Processing of Personal Data by Us in connection with:

(a) the Application, including telemetry collected before and after Account creation;
(b) Your Account;
(c) the Subscription and One-Time Purchase mechanics relating to the Pro Plan, including payment processing through Stripe;
(d) the Website;
(e) Our correspondence with You; and
(f) inbound feedback through public channels (see Section 14).

This Policy does not apply to:

(g) information You choose to publish through third-party platforms (for example, on subreddits or the Microsoft Store review surface) where We do not control the platform; or
(h) Processing performed by Stripe, Microsoft, Google, Reddit, or other third parties acting as Independent Controllers in respect of their own services. Such Processing is governed by those third parties’ privacy notices.


4. Minimum Age

4.1 Sixteen-year minimum

The Application is not directed at, and not intended for, persons under sixteen (16) years of age. You must be at least 16 to use the Services.

4.2 No knowing collection from minors

We do not knowingly collect Personal Data from persons under 16. If We become aware that We have collected Personal Data from a person below that age, We will delete it without undue delay and close any associated Account.

4.3 Higher local thresholds

Where the law in Your country of residence imposes a higher minimum age for the use of online services or for the provision of Personal Data, that higher age applies to You.


5. Personal Data We Process

5.1 Categories

We Process the following categories of Personal Data:

(a) Account Data — information You provide or generate in the course of creating and maintaining an Account: email address, given name, family name, hashed password (where applicable), unique anonymous user identifier, the identity-provider source (email/password, Google OAuth, Microsoft OAuth), email-verification status, Account creation timestamp, last-sign-in timestamp, and a signup country code derived from the IP address at Account creation (Section 6.1, row 20).

(b) Telemetry — data concerning the performance, stability, and use of the Application:

  • crash reports and diagnostic logs;
  • application-start and application-stop events;
  • anonymised feature-usage events (including, with effect from the Effective Date, usage events relating to Pro Plan features);
  • device metadata: device family, device form factor, operating-system version;
  • network metadata: IP address (truncated where reasonably practicable for analytic Processing, retained in full where required for diagnostic purposes), language, approximate geolocation derived from IP;
  • a unique anonymous user identifier (which You may, but are not required to, share with Us in connection with a support request).

(c) Attribution Data — Your responses, where You provide them, to the in-Application attribution question (“Where did You hear about Us?”) and the in-Application student question (whether You are a student and Your field of study).

(d) Correspondence Data — the content of any communication You send to Us at office@noteastic.app or privacy@noteastic.app or another published address, together with the sender’s email address and the timestamp.

(e) Feedback Data — feedback that You voluntarily submit through the in-Application feedback mechanism, including the verbatim message and, where You provide it, an email address for Us to follow up.

(f) Website Analytics Data — data collected through PostHog for analytics purposes when You visit the Website: page visits, click events, session duration, browser metadata, IP address, language, referrer, and the UTM parameters of the address called (source, medium, campaign, owner). Collection begins with the first page view and therefore before You have made Your decision through the Website banner; Section 11.2(b) describes how Your decision affects it.

(g) Billing Data — data generated by and necessary for the Subscription or One-Time Purchase lifecycle:

  • a Stripe customer identifier stored on Your Account record;
  • per-entitlement records containing: the Plan code, the entitlement kind (subscription, one-time purchase, or grant), the entitlement status (such as active, trial, or grace), the current Billing-Period end date where applicable (a One-Time Purchase is perpetual and has no Billing-Period end date), and a Stripe reference identifier (a subscription identifier for a Subscription, or a payment-intent identifier for a One-Time Purchase);
  • a webhook event ledger containing the raw Stripe event payloads received by Us for idempotent Processing and audit.

(h) Statutory Records — Invoices and related billing records as retained under § 132 of the Austrian Federal Tax Code (Section 9.4).

(i) Currency-Geolocation Data — the IP address of the device from which You access the pricing or checkout interface, whether in the Application or on the Website. This IP address is Processed transiently and solely to resolve the country associated with it, so that prices may be displayed to You in the currency likely relevant to You. The IP address is resolved against a locally held, offline geolocation database queried within Our own infrastructure; it is not transmitted to any third party for this purpose. Only the country is derived (no more granular location, such as region or city, is determined), only the resulting country and currency are returned, and the IP address is not stored, logged, or associated with You in connection with this purpose. (A separate signup country code derived once at Account creation is stored as Account Data; see Section 5.1(a).) The currency so determined is a default suggestion only; You may select a different available currency at checkout.

(j) Newsletter Data — where You subscribe to Our optional Newsletter, data generated by and necessary for the management and delivery of that Newsletter:

  • the content categories You have selected, namely one or more of: product updates, tips and tricks, technical announcements, company news, and Beta Programme communications;
  • the timestamps at which You opted in and at which You last updated Your Newsletter preferences;
  • a persistent, unique unsubscribe token generated for Your subscription, which enables one-click unsubscription from any Newsletter email without requiring You to sign in;
  • a per-recipient delivery record generated for each Newsletter dispatch, containing a snapshot of the recipient email address and language locale taken at the time of sending, the delivery status, the number of delivery attempts, and the time of successful dispatch.

(k) Advertising Measurement Data — data transmitted to the Advertising Networks so that We may measure the effectiveness of Our paid advertising (Section 11.4):

  • on the Website: the page called, the referrer, the language, the IP address, the user agent, technical particulars of the device and browser, the UTM parameters of the address called, the event measured (Section 11.4.1), and advertising identifiers including the identifier of a preceding advertisement click;
  • in the Application: the start of the Application and the completion of a Pro Plan purchase, in the case of a purchase together with the Plan purchased, the purchase amount, and the currency, together with the IP address and the advertising identifiers generated or read by the Microsoft advertising measurement component deployed for that purpose.

Which of this Advertising Measurement Data is transmitted in any given case depends on Your consent; Section 11.4 sets out what is transmitted with consent and what is transmitted without it.

(l) Campaign Identifier — a short text value denoting the campaign through which You reached the Website, stored on Your device where You have given the corresponding consent (Section 11.3).

5.2 What We do NOT store

We do not store on Our own systems any of the following, all of which remain exclusively with Stripe:

(a) card numbers, the last four digits of card numbers, expiry dates, or card verification values (CVC);
(b) payment-method tokens beyond the abstract Stripe references in Section 5.1(g);
(c) billing address details beyond what is needed to render an Invoice;
(d) tax identification numbers (the Pro Plan is currently sold B2C only);
(e) bank account numbers or SEPA mandate details.

5.3 No special-category data

We do not Process any special category of Personal Data within the meaning of Article 9(1) GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation).


6.1 Mapping

For each Processing purpose, We set out below the categories of Personal Data Processed and the legal basis under Article 6(1) GDPR.

#PurposeCategories of Personal DataLegal Basis
1Creation, authentication, and maintenance of Your AccountAccount DataArt. 6(1)(b) GDPR — performance of a contract
2Provision of the Application to YouAccount Data; TelemetryArt. 6(1)(b) GDPR — performance of a contract
3Verification of Your email addressAccount DataArt. 6(1)(b) GDPR — performance of a contract
4Sending transactional communications relating to the Account (e.g., email verification, welcome message)Account DataArt. 6(1)(b) GDPR — performance of a contract
5Diagnosis and resolution of errors and defects in the ApplicationTelemetryArt. 6(1)(f) GDPR — legitimate interests (maintaining a reliable Service)
6Statistical evaluation of feature usage for product improvement (including Pro Plan feature usage)Telemetry; Attribution DataArt. 6(1)(f) GDPR — legitimate interests (improving the Application)
7Statistical evaluation of Website usage and acquisition channelsWebsite Analytics DataArt. 6(1)(a) GDPR — consent, once You have consented to the Analytics category; until You have made Your decision, and where You refuse, Art. 6(1)(f) GDPR — legitimate interests (understanding Website usage to a limited extent, Section 11.2(b))
8Evaluation of in-Application attribution responsesAttribution Data; TelemetryArt. 6(1)(f) GDPR — legitimate interests (understanding how Users discover the Application)
9Consideration and implementation of user-submitted FeedbackFeedback Data; Correspondence DataArt. 6(1)(f) GDPR — legitimate interests (improving the Application)
10Sending Our optional Newsletter (product updates, tips and tricks, technical announcements, company news, and Beta Programme communications) to Users who have subscribed to the relevant content categoriesAccount Data (email, given name); Newsletter DataArt. 6(1)(a) GDPR — consent
11Processing of payment and execution of the Subscription or One-Time Purchase contract (including initial purchase, Trial Period management, automatic renewal, plan changes, cancellation, and refund)Billing Data; Account Data (email)Art. 6(1)(b) GDPR — performance of a contract
12Sending transactional Subscription and One-Time Purchase communications (purchase receipt, renewal receipt, Trial-Period-ending notice, renewal reminder, payment-failure notice, expiring-card notice, cancellation confirmation, refund confirmation, price-change notice) directly or through StripeAccount Data (email); Billing DataArt. 6(1)(b) GDPR — performance of a contract
13Issuing Invoices and retaining Invoices and other billing recordsBilling Data; Statutory RecordsArt. 6(1)(c) GDPR — legal obligation (§ 132 Bundesabgabenordnung)
14Determination, collection, and reporting of value-added tax via the EU One-Stop-Shop schemeBilling DataArt. 6(1)(c) GDPR — legal obligation
15Fraud prevention and risk management in respect of Subscription and One-Time Purchase payments (via Stripe Radar, Base tier)Billing Data; transaction metadata (Stripe-side: IP address, device fingerprint, behavioural signals)Art. 6(1)(f) GDPR — legitimate interests (preventing fraudulent transactions; safeguarding the integrity of the payment mechanism)
16Determining the currency in which prices are displayed to You, by resolving the IP address of the device accessing the pricing or checkout interface (in the Application or on the Website) to a country against a locally held, offline geolocation databaseCurrency-Geolocation Data (IP address, Processed transiently)Art. 6(1)(f) GDPR — legitimate interests (presenting prices in the currency likely relevant to You and reducing confusion at the point of sale; You may select a different available currency at checkout)
17Compliance with other legal obligations not covered by rows 13 or 14As requiredArt. 6(1)(c) GDPR — legal obligation
18Establishment, exercise, or defence of legal claimsAs necessaryArt. 6(1)(f) GDPR — legitimate interests
19Keeping a record of Your Newsletter consent and of any subsequent withdrawal (unsubscription), including the persistent unsubscribe token, in order to demonstrate the lawfulness of Newsletter Processing and to give effect to Your withdrawal by suppressing further Newsletter emailsNewsletter Data (consent and withdrawal record)Art. 6(1)(f) GDPR — legitimate interests (accountability under Article 7(1) GDPR and giving effect to Your withdrawal)
20Providing context for user support and assistance (the country associated with the IP address used at sign-up)Account Data (signup country code)Art. 6(1)(f) GDPR — legitimate interests (contextualised support; a coarse, unverified signal not used for any decision concerning You)
21Measuring the effectiveness of Our paid advertising on the Website, including the attribution of a click on a referral to the Microsoft Store to a preceding advertisement click (Section 11.4.1)Advertising Measurement DataArt. 6(1)(a) GDPR — consent to the Ad measurement category; in the cases described in Section 11.4.3, Art. 6(1)(f) GDPR — legitimate interests (economical deployment of a limited advertising budget)
22Measuring the effectiveness of Our paid advertising in the Application, including the attribution of an Application start and of a Pro Plan purchase to a preceding advertisement click (Section 11.4.2)Advertising Measurement DataArt. 6(1)(a) GDPR — consent
23Attributing Your visit to the campaign through which You reached the Website, including passing that attribution to the Microsoft Store where You follow a referral there (Section 11.3)Campaign IdentifierArt. 6(1)(a) GDPR — consent to the Ad measurement category
24Inclusion in advertising audiences and personalised delivery of advertisements by the Advertising Networks (Section 12.3)Advertising Measurement DataArt. 6(1)(a) GDPR — consent to the Personalised ads category; in the cases described in Section 11.4.3, Art. 6(1)(f) GDPR — legitimate interests (economical use of a limited advertising budget)

6.2 Provision of Personal Data is voluntary but contractually required

Provision of Account Data and (in respect of the Pro Plan) Billing Data is voluntary, but without it We cannot perform the contract: an Account cannot be created without the relevant Account Data, and a Pro Subscription or One-Time Purchase cannot be concluded without the relevant Billing Data.

6.3 Telemetry before Account creation

Telemetry described in Section 5.1(b) is collected from the device on which the Application is installed before and independently of Account creation. The legitimate-interests assessment supporting this collection is available on request to privacy@noteastic.app.

6.4 Newsletter subscription is optional and separate from the contract

Subscription to the Newsletter (Section 5.1(j)) is entirely optional. It is not a condition of creating an Account, of using the Application, or of purchasing or maintaining the Pro Plan, and We do not make the performance of any contract conditional on Your consent to receive the Newsletter. You may subscribe or decline freely, and the sole legal basis on which We send the Newsletter is Your consent under Article 6(1)(a) GDPR (see also Article 7(4) GDPR on the prohibition of bundling such consent with a contract).

You may withdraw Your consent and unsubscribe at any time, with effect for the future and without affecting the lawfulness of Newsletter emails sent before the withdrawal. Every Newsletter email contains a one-click unsubscribe mechanism that operates without requiring You to sign in; You may also withdraw Your consent by adjusting Your Newsletter preferences in the Application or by contacting Us at privacy@noteastic.app. Any record We retain after You unsubscribe is limited to what is necessary to give effect to Your withdrawal and to demonstrate compliance (Section 6.1, row 19, and Section 9.2).

6.5 Legitimate-interests assessment for Website analytics and advertising measurement

Where We rely on Article 6(1)(f) GDPR for the Processing described in Section 6.1, rows 7, 21, and 24, We have documented the balancing of Our interests against Your interests, rights, and freedoms that this requires. It is available on request to privacy@noteastic.app.

You may object to that Processing under Article 21(1) GDPR on grounds relating to Your particular situation. Where Processing is carried out for direct-marketing purposes, You may object under Article 21(2) GDPR without giving reasons. Section 11.6 describes how an objection takes practical effect on the Website and in the Application, and states openly where the means available to Us are limited.


7. Recipients and Sub-Processors

7.1 Confidentiality and contracts

Where We share Personal Data with Sub-Processors, We do so under a written contract that requires the Sub-Processor to Process Personal Data only on Our documented instructions, to maintain confidentiality, to implement appropriate technical and organisational measures, and to comply with the Sub-Processor obligations imposed by Article 28 GDPR.

7.2 Sub-Processors

The following Sub-Processors Process Personal Data on Our behalf:

Sub-ProcessorRolePersonal Data ProcessedLocation
Microsoft Ireland Operations Ltd (Azure App Service)Hosting of back-end APIAccount Data; Correspondence Data; Telemetry in transit; Billing Data in transitEEA (Ireland)
Microsoft Ireland Operations Ltd (Azure Database for PostgreSQL)Primary databaseAccount Data; Billing DataEEA (Ireland)
Microsoft Ireland Operations Ltd (Azure Monitor, Application Insights)Telemetry collection; diagnostic logging; error reportingTelemetryEEA (Ireland)
Microsoft Ireland Operations Ltd (Azure Communication Services)Sending transactional emails (Account and Subscription) and, where You have subscribed, delivering Our optional Newsletter, via the same email relayAccount Data (email, given name); Newsletter DataEEA (Europe region)
Microsoft Ireland Operations Ltd (Azure Key Vault, Entra ID, Static Web Apps, Azure DNS)Supporting infrastructure (secrets, administrator identity, Website hosting, DNS)Limited incidental exposureEEA (Ireland)
Stripe Payments Europe Limited (Ireland)Payment processing, Subscription billing, Stripe Tax, Customer Portal, Stripe Radar (Base), Stripe Billing, transactional billing communicationsBilling Data; Account Data (email); transaction metadata; IP address; device fingerprintEEA (Ireland); see Section 8 for any onward transfer to Stripe, Inc. (United States)
PostHog Inc. (via first-party reverse proxy at anal.noteastic.app)Website analyticsWebsite Analytics DataEEA (PostHog Cloud EU, Frankfurt)
Grafana Labs, Inc.Observability and log aggregationTelemetryEEA (EU Cloud stack)
Google LLC (Google Workspace / Gmail)Receipt and storage of inbound emailCorrespondence DataEEA (Google Workspace EU data-residency)

7.3 Independent Controllers

Certain third parties Process Personal Data as Independent Controllers in respect of their own services and not on Our behalf. In particular:

(a) Stripe acts as Independent Controller for the purposes of:

(i) fraud prevention and risk scoring under Stripe Radar (in respect of the elements of that Processing that fall outside the scope of Our instructions);
(ii) regulatory compliance, including know-your-customer (KYC), anti-money-laundering, and sanctions screening obligations imposed on Stripe under European Union and Member State financial-services law; and
(iii) the sending of Stripe-direct emails to You (purchase receipt, renewal receipt, refund confirmation, payment-failure notice, renewal reminder, Trial-Period-ending notice, expiring-card notice).

In these capacities, Stripe Processes Personal Data subject to its own published privacy policy. We recommend that You review it at https://stripe.com/privacy.

(b) Microsoft Corporation acts as Independent Controller for Microsoft Store services made available to You as a Microsoft Store account-holder, including Microsoft Store reviews and Microsoft Store telemetry available to Us via Partner Center.

(c) Google LLC and Microsoft Corporation act as Independent Controllers in respect of the third-party authentication flows referenced in Section 15.

(d) The following Advertising Networks act as Independent Controllers in respect of the Advertising Measurement Data they receive directly from Your device. They determine the purposes and means of that Processing themselves, use the data for their own purposes as well, including the improvement of their own services, and do not Process it on Our instructions. We conclude no data-processing agreement with them for that Processing, because they do not act as Processors. We do not transmit customer or prospect lists to them:

Advertising NetworkSurface concernedRecipient’s privacy notice
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland (Microsoft Advertising)Applicationhttps://privacy.microsoft.com/en-us/privacystatement
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Ads)Websitehttps://business.safety.google/privacy/
Reddit Netherlands B.V., Keizersgracht 62, 1015 CS Amsterdam, Netherlands (Reddit Ads)Websitehttps://www.reddit.com/policies/privacy-policy

This role is to be distinguished from the other relationships with the same corporate groups: the Microsoft services in Section 7.2 are provided on Our behalf, and the roles under paragraphs (b) and (c) above concern the Microsoft Store and third-party sign-in. None of those relationships covers advertising measurement.

7.4 Disclosures required by law

We may disclose Personal Data to public authorities where required to do so by binding order of a competent authority or by applicable law.

7.5 Changes to the Sub-Processor list

We may add or replace Sub-Processors. Where We do so in connection with paid Subscriptions, We will update this Section 7.2 in advance of any new Processing.


8. International Transfers

8.1 EEA primary residency

Personal Data Processed by Us or by Our Sub-Processors is Processed within the EEA. Our principal Sub-Processors operate from the EEA, with data residency in Ireland or another EEA Member State (see Section 7.2). Section 8.4 applies to the Advertising Measurement Data that passes directly from Your device to the Advertising Networks.

8.2 Onward transfers in respect of Stripe

Although Stripe Payments Europe Limited is Our contracting party and operates from Ireland, certain onward transfers to Stripe, Inc. (United States) or other Stripe group entities outside the EEA may occur in the course of Stripe providing the Subscription-billing service. Where such transfers occur:

(a) Stripe relies on the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR; and, where applicable;
(b) Stripe, Inc. is certified under the EU–U.S. Data Privacy Framework or its successor instrument; further information is published by Stripe at https://stripe.com/en-at/legal/data-privacy-framework.

8.3 PostHog and Grafana

PostHog Inc. and Grafana Labs, Inc. are incorporated in the United States but operate the Processing on EEA infrastructure. Standard Contractual Clauses apply to any parent-entity access that would amount to a transfer.

8.4 Advertising Networks

The following applies to the transmission of Advertising Measurement Data to the Advertising Networks identified in Section 7.3(d), each of which is answerable for the lawfulness of its own onward transfers:

(a) Microsoft Advertising. Our contracting party is Microsoft Ireland Operations Limited, established in Ireland. Transfers within the Microsoft group of companies, including transfers to the United States, are governed by the Microsoft privacy notice referenced in Section 7.3(d).

(b) Google Ads. Our contracting party is Google Ireland Limited, established in Ireland. Under the terms it applies to Independent Controllers, Google characterises the transmission of European data to that entity as a transfer within the EEA for which Standard Contractual Clauses are not required. Google answers as Independent Controller for onward transfers within the Google group of companies.

(c) Reddit Ads. Our contracting party is Reddit Netherlands B.V., established in the Netherlands; the Processing of the event data transmitted takes place at Reddit, Inc. in the United States. Reddit warrants compliance with the EU–U.S. Data Privacy Framework for that transfer. Should that Framework not apply or cease to be in force, the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR are deemed agreed between Us and Reddit.

8.5 Schrems II awareness

We are aware of the limits imposed by the Court of Justice of the European Union in Schrems II (C-311/18) on transfers to jurisdictions affording lesser standards of protection. We rely on the Sub-Processors named above on the basis that they offer the safeguards required by Article 46 GDPR for any onward transfer. That assessment holds only to a limited extent for the transfers under Section 8.4: there, Our influence extends no further than whether, and on what conditions, We bring the transfer about at all.


9. Retention Periods

9.1 General principles

We retain Personal Data only for as long as necessary for the purpose for which it was Processed, unless a longer retention period is required by law or is necessary for the establishment, exercise, or defence of legal claims.

9.2 Specific retention periods

CategoryRetention Period
Account DataFor the duration of the Account; deleted on Account termination (immediate hard-delete, no grace period), subject to the carve-out in Section 9.4
Telemetry and diagnostic data365 days from collection
Currency-Geolocation DataNot stored. The IP address is Processed transiently in memory to derive the associated country and is discarded immediately thereafter; it is not retained, logged, or associated with You for this purpose
Website Analytics Data held by Sub-Processor (PostHog)1 year from collection
Advertising Measurement Data held by Google Ads90 days from collection
Advertising Measurement Data held by Microsoft Advertising and by Reddit AdsDetermined by those recipients; the privacy notices referenced in Section 7.3(d) govern
Your decision on the cookie categories as stored on Your device (Section 11.2)1 year from the decision, after which We ask again
Further identifiers of Ours stored on Your device: the Campaign Identifier (Section 11.3) and the identifier placed by the Microsoft advertising measurement component in the Application (Section 11.4.2)No time limit, until You remove them. No expiry date and no automatic deletion is currently provided for these entries; Section 11.6 describes how You may remove them
Identifiers set on Your device by the Advertising NetworksAs determined by the Advertising Network concerned; see the privacy notices referenced in Section 7.3(d)
Feedback archives (Reddit, Microsoft Store reviews, external channels)3 years from the underlying communication date
Email correspondence at published contact addresses3 years from receipt
Newsletter subscription and consent record (selected categories, opt-in and update timestamps, unsubscribe token)For as long as You maintain an Account. On unsubscription the record is retained, as a record of Your consent and its withdrawal (Section 6.1, row 19), and is deleted when Your Account is terminated
Newsletter delivery records (per-recipient dispatch log: email and locale snapshot, delivery status, delivery attempts, dispatch time)30 days from the dispatch of the relevant Newsletter, after which the record is deleted or anonymised
Billing Data (Stripe customer identifier, Subscription and One-Time Purchase records, webhook event ledger, transaction history)7 years from the end of the financial year in which the underlying transaction was completed, in accordance with § 132 of the Austrian Federal Tax Code; see Section 9.4
Invoices7 years from the end of the financial year in which the Invoice was issued, in accordance with § 132 of the Austrian Federal Tax Code
Personal Data required to be retained by other applicable law (e.g., for tax or audit purposes)For the period prescribed by that law

9.3 Anonymisation as an alternative to deletion

Where Telemetry or Website Analytics Data can be effectively anonymised within the meaning of Recital 26 GDPR, We may retain the resulting non-personal data indefinitely for statistical purposes.

9.4 Carve-out for Billing Data and statutory retention

The seven-year retention requirement imposed by § 132 of the Austrian Federal Tax Code constitutes a legal obligation under Article 6(1)(c) GDPR. Notwithstanding any other provision of this Policy and notwithstanding Your exercise of the right of erasure under Article 17 GDPR, Billing Data and Invoices are retained for the statutory period, after which they are deleted or, where reasonable, fully anonymised. This carve-out is permitted under Article 17(3)(b) GDPR (Processing required for compliance with a legal obligation).


10. Your Rights as a Data Subject

10.1 Rights enumerated

Subject to the conditions and exceptions set out in the GDPR, You have the following rights in respect of Your Personal Data:

(a) the right of access, pursuant to Article 15 GDPR;
(b) the right to rectification, pursuant to Article 16 GDPR;
(c) the right to erasure (“the right to be forgotten”), pursuant to Article 17 GDPR, subject to Section 9.4;
(d) the right to restriction of Processing, pursuant to Article 18 GDPR;
(e) the right to data portability, pursuant to Article 20 GDPR;
(f) the right to object to Processing based on legitimate interests or direct marketing, pursuant to Article 21 GDPR;
(g) the right to withdraw consent at any time, pursuant to Article 7(3) GDPR, without affecting the lawfulness of Processing carried out before the withdrawal; and
(h) the right to lodge a complaint with a supervisory authority, as further described in Section 19.

10.2 Exercise

To exercise any of these rights, please contact Us at privacy@noteastic.app. We will respond within the time limits set by Article 12(3) GDPR. We may request information reasonably necessary to confirm Your identity before responding.

10.3 No fee

We do not charge a fee for the exercise of Data Subject rights unless a request is manifestly unfounded or excessive, in which case We may charge a reasonable fee or refuse the request in accordance with Article 12(5) GDPR.

10.4 Erasure and statutory retention

The right of erasure under Article 17 GDPR is qualified by Article 17(3)(b), which preserves Processing required for compliance with a legal obligation to which the Controller is subject. Accordingly, where You exercise the right of erasure:

(a) Account Data, Telemetry, Correspondence Data, Feedback Data, Attribution Data, and Website Analytics Data attributable to You are deleted (or anonymised) in accordance with Section 9;
(b) Billing Data and Invoices are retained for the period prescribed by § 132 of the Austrian Federal Tax Code (see Section 9.4) and deleted thereafter.

10.5 Rights against Independent Controllers

Where a third party Processes Personal Data as an Independent Controller (Section 7.3), We cannot satisfy Your rights in its stead. That applies in particular to the Advertising Measurement Data that the Advertising Networks receive directly from Your device. For that data, please address Your request directly to the recipient concerned; the routes provided for that purpose are described in the privacy notices referenced in Section 7.3(d).


11. Cookies and Similar Technologies

11.1 Application

The Application does not use cookies. Telemetry is collected through native operating-system mechanisms and is governed by Section 5.1(b) and Section 6.1. Where You have consented to advertising measurement in the Application, the Microsoft advertising measurement component deployed for that purpose places identifiers on Your device; Section 11.4.2 describes this.

11.2 Website

The Website uses cookies and similar technologies in four categories. You decide on the three consent-bearing categories separately in the Website banner; You may therefore consent to some of them and refuse the others.

(a) Necessary — required for the technical operation of the Website; this includes storing Your decision on the remaining categories, so that We need not ask You again on every visit. This category cannot be deselected and is used without consent on the legal basis of Article 6(1)(f) GDPR and the corresponding exception under the ePrivacy Directive.

(b) Analytics — concerns the collection of Website Analytics Data through PostHog (Section 5.1(f)). Collection begins with the first page view and therefore before You have made Your decision; until You have decided, and where You refuse, it takes place without cookies and without any persistent identifier on Your device, on the basis of Article 6(1)(f) GDPR (Section 6.5). Where You consent, it continues with cookies; from that point the legal basis is Article 6(1)(a) GDPR (consent) and the corresponding consent requirement under the ePrivacy Directive.

(c) Ad measurement — concerns the advertising identifiers by which the Advertising Networks measure which of Our advertisements led to a visit and to a click on a referral to the Microsoft Store (Section 11.4.1). The legal basis is Article 6(1)(a) GDPR (consent) and the corresponding consent requirement under the ePrivacy Directive, subject to the defaults described in Section 11.4.3.

(d) Personalised ads — permits the Advertising Networks, in addition, to include You in advertising audiences on the basis of Your visit and to deliver advertisements to You in personalised form (Section 12.3). This category may be chosen independently of Ad measurement: You may consent to the measurement and refuse the personalisation. The legal basis and the qualification correspond to paragraph (c).

11.3 Campaign Identifier

The Campaign Identifier (Section 5.1(l)) denotes the campaign through which You reached the Website, that is, its owner, source, channel, and name. It contains no information about You and is not randomly generated; it is identical for all visitors arriving from the same campaign and, of itself, does not allow You to be recognised.

Where You then follow a referral from the Website to the Microsoft Store, We append the Campaign Identifier to the Store address called, and it thereby reaches Microsoft.

The Campaign Identifier is stored only where You have consented to the Ad measurement category (Section 11.2(c)). Where You consent after the page has been called up, it is recorded at that moment, for as long as You are still on the Website. The legal basis is Article 6(1)(a) GDPR (Section 6.1, row 23) together with the corresponding consent requirement under the ePrivacy Directive. Section 11.6 describes how You may remove it.

11.4 Advertising measurement

We advertise Noteastic on a paid basis and measure which of that advertising leads to installations and purchases. For that purpose, Advertising Measurement Data (Section 5.1(k)) passes directly from Your device to the Advertising Networks identified in Section 7.3(d).

11.4.1 On the Website

The Website embeds the advertising components of Google Ads and of Reddit Ads by means of a Google tag manager. The success measured is Your click on a referral to the Microsoft Store; beyond that, the components report the calling of a page as such.

Where Your consent to Ad measurement is present, the Advertising Networks may in doing so set and read advertising identifiers on Your device and evaluate the identifier of a preceding advertisement click. Where You have also consented to Personalised ads, they may in addition use the data so obtained for the purposes described in Section 12.3. What Processing follows is determined by the Advertising Networks themselves, as Independent Controllers (Section 7.3(d)).

Where Your consent is not present, Section 11.4.3 applies.

11.4.2 In the Application

The Application transmits Advertising Measurement Data to Microsoft Advertising where You have consented to this in the settings of the Application. The feature is switched off by default. Without Your consent, the component provided for that purpose is not brought into operation and nothing is transmitted.

Where You have consented, a message is sent to Microsoft Advertising on the start of the Application and on the completion of a Pro Plan purchase; in the case of a purchase it additionally contains the Plan purchased, the purchase amount, and the currency. The component originates from Microsoft and places identifiers on Your device in order to recognise it. Which particulars it transmits, and for how long Microsoft retains them, is determined by Microsoft; the privacy notice referenced in Section 7.3(d) governs.

Your decisions on the Ad measurement and Personalised ads categories are passed to the Google components as separate signals (the “Consent Mode”). For as long as no consent to Ad measurement is present, under Our configuration no advertising identifiers are set on or read from Your device, and the identifier of any preceding ad click is suppressed.

The Google components are nevertheless loaded. In doing so, they transmit Your IP address, Your user agent, the referrer, the page address, the time, and the state of Your consent decision to Google. That transmission takes place even where You have refused; We rely on it to gauge how Our advertising performs, at least in aggregated and estimated form. The legal basis for it is Article 6(1)(f) GDPR (Section 6.5).

The Reddit Ads component, by contrast, is not executed without Your consent. For as long as consent is not present, Reddit receives no data from the Website.

In the United States, in Canada with the exception of the province of Quebec, in Australia, in New Zealand, and in Japan, consent is granted by default, because the opt-out model is the arrangement provided for in those markets; in those markets the advertising identifiers described in Section 11.4.1 are set and read from the first page view onwards. The banner is displayed in those markets as well, and a refusal takes effect there immediately and to the same extent as everywhere else. Where Your browser sends a signal under the Global Privacy Control standard, the default does not apply.

11.5 Subscription checkout

Stripe Checkout, used in the course of subscribing to the Pro Plan, may set cookies on its hosted-checkout domain in accordance with Stripe’s own published cookie notice. Those cookies are not set by Us and are not under Our control.

11.6 Withdrawal, objection, and the limits of both

11.6.1 Website

Through the “Cookie settings” entry in the footer of the Website You may call up the banner again at any time and change Your decision for each category individually. A withdrawal takes effect from the moment You declare it; the lawfulness of the Processing carried out on the basis of Your consent up to that moment remains unaffected. Independently of that, We ask again after one year.

So that You may judge what a withdrawal achieves, We state openly what it does not achieve:

(a) We cannot recall data already transmitted to the Advertising Networks; they decide on its further Processing as Independent Controllers.
(b) We do not automatically remove identifiers placed on Your device before the withdrawal.
(c) We do not remove a Campaign Identifier already stored (Section 11.3) upon a withdrawal; it will, however, no longer be stored thereafter.
(d) The transmission to Google described in Section 11.4.3 continues to take place after a refusal.

The operations under (b) to (d) can therefore be effectively prevented only on Your device itself: by deleting the data stored for the Website in the settings of Your browser and by blocking the scripts or domains concerned, for example through the protection features of Your browser or a corresponding extension. We consider this statement more honest than the promise of a route of objection that We could not technically honour.

11.6.2 Application

You may switch off advertising measurement in the Application at any time in its settings. From that moment, nothing further is transmitted to Microsoft Advertising. Identifiers previously placed on Your device by the Microsoft component are not thereby removed.

11.6.3 Objection under Article 21 GDPR

You may object to the Processing that We base on Article 6(1)(f) GDPR by contacting Us at privacy@noteastic.app (Section 6.5). Where Processing is tied to Your Account, We give effect to an objection directly. For the operations on the Website described in Sections 11.3 and 11.4.3 We cannot do so: You are not identifiable to Us there, so We hold no identifier by which We could exclude You in future. In that respect We refer You to the means on Your device described in Section 11.6.1.


12. Automated Decision-Making and Profiling

12.1 No Article 22 decisions made by Us

We do not make decisions concerning You based solely on automated Processing, including profiling, that produce legal effects concerning You or similarly significantly affect You within the meaning of Article 22(1) GDPR.

12.2 Stripe Radar

In the course of payment processing, Stripe operates the Stripe Radar fraud-prevention system, which assigns a risk score to each transaction. Stripe may decline transactions on the basis of that score. We do not control the score and do not make payment-acceptance decisions solely on its basis; where Stripe declines a transaction, We may, in appropriate circumstances, review the decline and reinstate the transaction following manual review. The role of Stripe Radar is further described in Section 7.3.

12.3 Profiling for advertising purposes

Where Your consent to the Personalised ads category is present (Section 11.2(d)), or where the default under Section 11.4.3 applies in Your market, the Advertising Networks combine the Advertising Measurement Data they receive with the profiles they maintain about You and use it to build audiences and to deliver advertisements on a personalised basis. This is profiling within the meaning of Article 4(4) GDPR. Where You refuse this category while consenting to Ad measurement, that combination does not take place.

It does not give rise to a decision within the meaning of Article 22(1) GDPR: it determines only which advertising is shown to You outside the Services, and affects neither Your access to the Services nor the terms or prices offered to You. We carry out no profiling Ourselves, and We receive from the Advertising Networks no analyses relating to individuals, but aggregated campaign reports.


13. Security

13.1 Technical and organisational measures

We implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing, accidental loss, destruction, or damage, taking into account the nature, scope, context, and purposes of Processing and the risks to natural persons. These measures include:

(a) hashing of Personal Data used for Telemetry attribution where reasonably practicable;
(b) encryption in transit (TLS) for all data flows between the Application, the back-end API, and Sub-Processors;
(c) encryption at rest for the primary database and for backups;
(d) restriction of administrator access to production systems through Microsoft Entra ID and the principle of least privilege;
(e) operation of the primary database in a private network without public internet exposure;
(f) segregation of duties between Subscription / Billing Data flows and Account Data flows; and
(g) regular review of access logs and infrastructure audit events.

13.2 Breach notification

In the event of a Personal Data breach, We will notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR, and We will notify affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 GDPR.


14. Feedback from External Channels

We Process Personal Data made publicly available on the following channels for the purpose of considering user-submitted feedback in the development of the Application:

(a) Reddit: usernames, post or comment content, and direct messages that express opinions, requests, or feedback about Noteastic. Legal basis: Article 6(1)(f) GDPR (legitimate interests).

(b) Email correspondence at published contact addresses: as set out in Sections 5.1(d) and 9.2.

(c) Microsoft Store reviews: review content and the reviewer’s display name where shown in Partner Center. Legal basis: Article 6(1)(f) GDPR (legitimate interests).

Feedback Data is archived in a manual spreadsheet outside of the Account environment and is not linked to a User’s Account Data unless You expressly identify Yourself for that purpose.


15. Third-Party Authentication

Where You choose to create or sign in to Your Account using Google OAuth or Microsoft OAuth, the relevant provider transmits to Us a limited set of profile attributes (typically email address, given name, and family name) for the purpose of provisioning Your Account. We receive that data as Controller and Process it as Account Data; the provider Processes its own data flow as Independent Controller under its own privacy notice.


16. Microsoft Store

Where data flows from Microsoft Corporation to Us through Partner Center in connection with the Microsoft Store distribution of the Application (for example, aggregated acquisition data, demographic aggregates, and crash-report metadata), Microsoft acts as Independent Controller and We Process the data made available to Us as Controller for the purposes set out in Section 6.


17. Changes to this Privacy Policy

17.1 Right to amend

We may amend this Policy at any time.

17.2 Notice for material changes

(a) For material changes, We will give You no less than thirty (30) calendar days’ prior notice by email to the address associated with Your Account and, where practicable, by in-Application notice.
(b) Where the legal basis for a new Processing activity is consent, We will obtain that consent before the new Processing commences.

17.3 Non-material changes

For non-material changes, the amended Policy takes effect on publication.

17.4 Effective date

The effective date of the current version is shown at the head of this Policy.


18. How to Contact Us

For any matter arising under this Policy, including the exercise of Data Subject rights, please contact Our privacy contact at privacy@noteastic.app or write to:

Noteastic OG, Anton-Baumgartner-Straße 44, C8/1504, 1230 Wien, Österreich


19. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR. The supervisory authority of the Controller’s establishment is:

Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Wien, Österreich
www.dsb.gv.at

If You are resident in another Member State of the European Union or the European Economic Area, You may alternatively lodge a complaint with the supervisory authority in Your country of residence or place of work.


20. Severability and Governing Law

(a) If any provision of this Policy is held to be invalid, unenforceable, or void, the remaining provisions continue in full force and effect.
(b) This Policy is governed by the laws of the Republic of Austria, without prejudice to the application of the GDPR and other applicable European Union law, and without prejudice to the right of Data Subjects under Article 79 GDPR to seek judicial remedy in the courts of their habitual residence.


End of the Privacy Policy.

We use cookies to analyse how the site is used and to measure and personalise our advertising on Google and Reddit. See our Privacy Policy.