Privacy notice
NoteQuote keeps the lines you mark in paper books. This notice explains what we collect when you use the website, join the waitlist, or use the NoteQuote app on iPhone or on the web, why we collect it, who helps us process it, how long we keep it, and what you can do about it.
The short version
- Reading a page happens on your iPhone: text recognition and highlight detection run on the device. No photo or passage is sent to an AI service.
- Your library is yours. It reaches our servers only when you sync it, share it or publish it.
- No ads, no tracking across apps or websites, no selling or renting of your data.
- You can export your library and delete your account at any time, from the app.
- The waitlist keeps your email address only to write to you about NoteQuote’s launch, and every email has a link to leave it.
Who we are
NoteQuote is made by Erari (“we”, “us”). We are the data controller for the personal data described here. For anything about your data, write to support@erari.co.
What we collect, and why
When you visit the website
The website is served by Cloudflare. Like every web host, it receives your IP address and browser details with each request and keeps short-lived logs to run and protect the site. We do not use analytics, advertising or tracking cookies on the website.
When you join the waitlist
- What: your email address, the language of the page, whether you would like to be considered for the TestFlight beta, when you agreed, and a salted one-way hash of your IP address.
- Why: to send one welcome email now and one email when NoteQuote is on the App Store (and, if you asked, a TestFlight invitation). The IP hash only limits how many sign-ups one network can make in a day; we never store the address itself.
- Spam protection: the form uses Cloudflare Turnstile, which loads only when you reach the form and checks, from your browser’s signals, that a person is signing up.
- Leaving: every email ends with a link to leave the list, and mail apps that support it show their own Unsubscribe button. When you leave, we keep your address marked as unsubscribed so that we never write to it again; if you would rather we erase it completely, write to us.
When you create an account
- Your email address, your name, your date of birth (to confirm you are 16 or older), an optional profile photo, and a username made from your name or email.
- If you sign in with Apple or Google, the identifier and email address they give us, and with Google, your profile photo if you choose to use it.
- Which version of the Terms of Service and of this notice you accepted, and when.
- Sign-in codes are sent to your email address. We use your account details to run your account, keep it secure, and send messages about it (for example, a sign-in code or a notice before a cloud copy is deleted).
Your library
- Books, sections, notes and quotes, cover and page photos, and voice notes. They are kept on your iPhone first. They are stored on our servers when you use sync (a Lite or Pro plan), use the web app, share a book, or publish it to the web.
- For plan limits we keep counts without content, such as how many camera pages or voice notes were saved in a month.
- When you look up a book, the title, author or ISBN you type is sent to Open Library (Internet Archive) to find the edition. We do not keep the query.
Sharing a book and publishing it
- People in a shared book see each other’s name, photo and @username, and who wrote which note; the book’s owner also sees members’ email addresses. While a shared book is open, the others see that you are there and in which section, in real time; this is not stored.
- Invitations sent by email are stored only as a one-way code and a partly hidden address. Requests to join, reports of content and blocks are kept to run and protect sharing.
- If you publish a book to the web, its page shows only what you choose (photos are off unless you turn them on), is hidden from search engines unless you list it, and is removed when you stop publishing.
Subscriptions
Purchases are made through the App Store. RevenueCat tells the app which plan you have; it receives your account’s random identifier and your purchase status, never your payment details.
Notifications
If you allow notifications, we store your device’s push token to send sharing notifications (for example, someone joined your book). Their text includes the person’s name and the book’s title and is delivered by Apple Push Notification service. You can turn each kind off in Settings or mute a single book.
Crash reports
The iPhone app sends crash and error reports to Firebase Crashlytics (Google) so that we can fix problems. They contain technical details such as the device model, the app and system versions and what the app was doing, but no notes, photos, email address or account identifier. You can turn them off in Settings → Privacy → “Send crash reports”, which also deletes reports not yet sent.
In your browser (web app)
The web app keeps your sign-in session, a device identifier, your settings, and drafts of sections you have not saved yet in your browser’s storage, so that it works offline and resumes where you left off. Signing out clears your session.
What stays on your iPhone
The camera, text recognition (Apple’s Vision framework) and the detection of what you highlighted or underlined all run on your iPhone. Search runs on your iPhone too. We do not send your photos or passages to any artificial-intelligence or cloud text-recognition service.
What we don’t do
- We don’t show ads and don’t use advertising identifiers.
- We don’t track you across other companies’ apps or websites.
- We don’t sell, rent or trade personal data.
- We don’t use product analytics today. If we ever add them, they will be optional and asked for first.
- We don’t make decisions about you by automated means that have legal or similar effects.
Who processes data for us
These providers process personal data on our behalf, only to provide NoteQuote, under their own security and data-protection terms.
| Provider | What for | Where |
|---|---|---|
| Supabase | Accounts, the database, stored photos and voice notes, sharing in real time | Tokyo, Japan |
| Cloudflare | Hosting the website and web app, Turnstile spam protection, request logs | Global network |
| Resend | Sending email: sign-in codes, account notices, the waitlist emails | Sent from Tokyo, Japan; a US company |
| RevenueCat | Knowing which plan you have | United States |
| Google (Firebase Crashlytics) | Crash and error reports from the iPhone app | United States |
| Apple | Sign in with Apple, App Store purchases, push notifications | United States |
| Sign in with Google, if you use it | United States | |
| Open Library (Internet Archive) | Book lookup by title, author or ISBN (the query only) | United States |
We may also disclose data when the law requires it, or to protect the rights and safety of our users and of NoteQuote.
Why we are allowed to
Under the EU and UK General Data Protection Regulation (GDPR) and Türkiye’s Personal Data Protection Law No. 6698 (KVKK), we rely on:
- Providing the service you asked for (a contract with you): your account, library, sync, sharing, publishing, subscriptions and the messages these need.
- Your consent: the waitlist emails and push notifications. You can withdraw it at any time, without affecting what happened before.
- Our legitimate interests, balanced against yours: keeping NoteQuote secure, preventing spam and abuse, and fixing crashes (which you can turn off).
- Legal obligations, such as keeping records the law requires.
Where your data is
Your account and library are stored in Tokyo, Japan. Some providers above are based in or process data in other countries, including the United States. When personal data leaves Türkiye, the European Economic Area or the United Kingdom, we rely on the safeguards the law provides for such transfers, such as standard contractual clauses or adequacy decisions.
How long we keep it
| Your account and library | Until you delete them or your account |
|---|---|
| A deleted book | In Recently Deleted for 30 days, then deleted for good |
| Your account, when you delete it | Deleted at once: your library, photos, voice notes, push tokens, your Apple sign-in link and your subscription record. A content-free record that the deletion happened is kept for 30 days. In books you shared, your notes stay for the others, shown as written by a former member. |
| The cloud copy after a paid plan ends | 30 days (Lite) or 90 days (Pro), with email reminders, then deleted from our servers; the copy on your iPhone stays |
| Sharing records | Ended invitations and requests to join: 30 days. Ended memberships: 90 days. Sent notifications: 7 days |
| The waitlist | Until you leave it; after that only the mark that you left, unless you ask us to erase it |
| Crash reports and logs | For the limited periods our providers keep them |
Your choices and rights
In the app you can, at any time:
- export your library (Settings) or a single book;
- correct your profile and remove your photo (My Page);
- delete your account (My Page → Delete Account), on iPhone or on the web;
- turn crash reports and each kind of notification off, and stop publishing a book.
You also have the right to ask whether we process your data and to get a copy of it; to have it corrected or erased; to restrict or object to its processing; to receive it in a portable format; to learn who it was shared with and for what purpose; and, under KVKK Article 11, to object to a result against you that comes only from automated analysis, and to claim compensation for damage caused by unlawful processing.
Write to support@erari.co from the address on your account. We answer within 30 days. You can also complain to a data-protection authority: in Türkiye the Personal Data Protection Board (KVKK), in the EU the authority of your country, in the UK the Information Commissioner’s Office.
Age
NoteQuote is for people aged 16 and over; we ask for your date of birth to confirm it. If you believe a younger person has given us personal data, write to us and we will delete it.
Security
Data travels encrypted (HTTPS). Access to your data on our servers is limited to your account and the people you share a book with, enforced by the database itself. Invitation emails and links are stored only as one-way codes, and the app can be locked with Face ID. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires.
Changes to this notice
When we change this notice, we update the date above. If a change is significant, we will tell you in the app or by email before it applies.
Contact
Erari · support@erari.co