Nota : Quick NotesNota : Quick Notes

Legal

Privacy Policy

Last updated September 12, 2026

This Privacy Policy applies to the Nota : Quick Notes mobile application for Android, iOS and iPadOS (the “App”) and to this website at nota-solution.quantyr.co (together, the “Service”). It explains what data Nota : Quick Notes collects, why we collect it, who we share it with, how long we keep it, and how you can get it deleted.

The short of it: your notes live on your device, the only cloud copy is one you put in your own Google Drive, and nothing about what you write is used to profile you. We are the data controller for the account data described below; contact us at support@quantyr.co with any question about this policy.

The short version

  • Your notes, images and imported PDFs are stored in the app’s private storage on your device.
  • Cloud sync is a Pro feature and is opt-in. It copies your notes to a Nota Notes folder in your own Google Drive. We never hold a copy of your notes.
  • You sign in with Google, Apple, or an email address and password. Google and Apple sign-in never give us your password; email sign-in is handled by Firebase Authentication.
  • Payments go through Stripe. We never see or store your card number.
  • No analytics SDK, no tracking pixels, no advertising, no crash-reporting SDK, no selling of data.
  • Deleting your account from the profile screen removes everything, immediately.

1. What we collect

Everything the Service holds about you, at a glance. Each row is expanded below.

  • Account

    User ID, email address, display name, which sign-in provider you used.

    Why:
    To create and identify your account across devices, and to send account and security notices.
    Where:
    Our server (Malaysia / EU region) and Firebase Authentication.
    How long:
    Until you delete your account.
  • Subscription & billing

    Stripe customer ID, plan, status, period dates, card brand and last four digits as Stripe reports them.

    Why:
    To run the Pro subscription, unlock paid features and show your billing state.
    Where:
    Our server and Stripe. Card numbers are entered on Stripe's pages and never reach us.
    How long:
    While your account exists; Stripe keeps its own records as tax and anti-fraud law requires.
  • Google Drive binding

    The Google account ID and email address of the Drive that holds your Nota Notes folder.

    Why:
    So your other devices sync to the same folder and a different Google account cannot be connected by mistake.
    Where:
    Our server.
    How long:
    Until you delete your account or ask us to unbind it.
  • Saved signatures (Pro)

    Up to three signatures as vector data — the strokes you drew, or the text you typed and its styling.

    Why:
    So the signatures you saved are available on every device you sign in on.
    Where:
    Our server.
    How long:
    Until you delete them in the app or delete your account.
  • Your notes

    Notes, drawings, text, images, imported PDFs, folders and folder covers.

    Why:
    They are the product. We do not read them or hold a copy.
    Where:
    Your device. With Pro and Drive connected, also a Nota Notes folder in your own Google Drive. Never on our servers.
    How long:
    Until you delete them, the app, or that Drive folder.
  • Technical logs

    Request time, endpoint, app version, sync schema level, IP address.

    Why:
    To keep the service running, debug failures and block abuse.
    Where:
    Our server.
    How long:
    At most 30 days.

Account information. When you sign in, Firebase Authentication gives us a stable user ID, your email address, your display name (if the provider supplies one) and which provider you used. We keep these on our server to create your account and to attach your subscription and signature library to it.

Subscription and billing. If you subscribe to Pro, we keep your Stripe customer ID, the plan you chose, its status and period dates, and the last few digits of the card on file as Stripe reports them. Card numbers themselves are entered on Stripe’s pages and never touch our systems.

Drive binding. When you connect Google Drive, we record which Google account (its stable ID and email address) holds your Nota Notes folder, so a second device can be pointed at the same folder and a different Google account cannot be connected by mistake.

Saved signatures (Pro). Up to three signatures you choose to keep in your library are stored on our server as vector data (the strokes or the typed text and its styling) so they are available on every device you sign in on. Signatures you place on a page are stored with that note, not with us.

Technical requests. The app calls our server to sign in, check whether an update is required, read the price list, and manage your subscription. Those requests carry your app version and, for sync, the schema level of your notes. We keep ordinary server logs of them for a short time to keep the service running.

2. Your notes

Everything you write or draw is saved to your device as you go — the note metadata in a local database and the content, images and PDF pages as files in the app’s private folder. That storage is protected by your device’s own encryption and lock screen; the app does not add a separate encryption layer of its own.

If you subscribe to Pro and connect Google Drive, the app keeps a copy of every note, folder, image and PDF page in a Nota Notes folder in your Drive, using Google’sdrive.filepermission — which only lets the app see and edit files it created itself. That data is governed by Google’s privacy policy and your Google account. It does not pass through our servers.

Handwriting recognition runs entirely on your device using Google ML Kit. The language model is downloaded from Google once and stored on the device; your strokes are never sent anywhere for recognition.

3. How Nota : Quick Notes uses Google user data

Two separate things, each opt-in: signing in with Google, and — on Pro — connecting Google Drive so your notes back up to a folder you own. Sign-in never asks for Drive; Drive is a second consent you can decline.

  • openidSign in with Google

    A stable, opaque Google user ID.

    Why: To create your account (through Firebase Authentication) and recognise you on any device.

  • emailSign in with Google

    Your Google account email.

    Why: Shown in your profile so you can confirm the right account; used for account and billing notices, not marketing.

  • profileSign in with Google

    Display name and profile picture URL.

    Why: Shown in the profile screen.

  • drive.fileConnecting Google Drive (Pro)

    Permission to create and edit files the app itself created in your Drive — a Nota Notes folder.

    Why: To back up and sync your notes, folders, images and PDF pages between your devices. The app cannot see any other file in your Drive.

What Nota : Quick Notes does NOT do

  • · Does not read, send or manage your Gmail.
  • · Does not access Contacts, Calendar or Photos through your Google account.
  • · Does not see files in your Drive other than the ones it created.
  • · Does not sell, share or use your Google data for advertising, analytics or model training.
  • · Does not copy your notes to our own servers — synced notes live only in your Drive.

Where your data lives

  • · Notes, images and imported PDFs are stored in the app’s private storage on your device.
  • · With Pro and Drive connected, a copy of each note is kept in the Nota Notes folder of your own Google Drive.
  • · Our servers hold your account record, subscription status, which Google account your Drive is bound to, and (Pro) up to three saved signatures.
  • · All traffic is encrypted in transit (TLS).
  • · Delete your account from the profile screen: the Drive folder, your server records, the Firebase user and every note on the device are removed straight away.

You can revoke Nota : Quick Notes’s access at any time from your Google Account permissions page.

4. Limited Use of Google user data

Nota : Quick Notes’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, and specifically for the Google Drive data the App can reach:

  • We use Google user data only to provide and improve the features you asked for — signing you in, and backing up and syncing your notes to the Nota Notes folder in your own Drive.
  • We do not transfer Google user data to third parties, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.
  • We do not use Google user data for serving advertisements of any kind.
  • We do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models. Handwriting recognition runs entirely on your device.
  • No human reads your Google user data, except with your explicit consent for a specific support request, where it is necessary for security purposes (such as investigating abuse), or to comply with applicable law.
  • The App requests the narrowest Drive scope available, drive.file, which grants access only to files the App itself created. It cannot list, open or modify anything else in your Drive.

5. What we don’t collect

  • We don’t use analytics or crash-reporting SDKs to observe how you use the app.
  • We don’t serve ads and don’t share data with ad networks.
  • We don’t sell your data to anyone, for any reason.
  • We don’t hold your notes on our servers, so nobody at Nota : Quick Notes can read them.
  • We don’t collect your precise location, contacts or camera.

6. Who we share data with

We use a small number of providers to run the Service. Each processes only what it needs:

  • Firebase Authentication (Google) — sign-in for all three providers, email verification and password reset emails.
  • Google Drive — sync storage, in your own account, only when you connect it.
  • Google ML Kit — downloads the on-device handwriting model. Recognition itself happens on the device.
  • Stripe — checkout, subscription billing and the billing portal.
  • Apple — Sign in with Apple, only when you choose it.

We don’t share your data with anyone else, except where required by applicable law (for example a valid legal request).

7. How we protect your data

  • All traffic between the App and our servers, and between the App and Google, is encrypted in transit with TLS.
  • Notes on your device sit in the App’s private storage, protected by your device’s own encryption and lock screen.
  • Data in your Google Drive is protected by your Google account and its own security settings, including any two-factor authentication you have enabled.
  • Our database is encrypted at rest and reachable only from our application servers. Administrative access is limited to the maintainers of the Service and requires individual, multi-factor-protected accounts.
  • We never receive or store your Google, Apple or card credentials. Sign-in is handled by Firebase Authentication and payments by Stripe, both on their own pages.
  • If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by applicable law.

8. Your rights and controls

You can, at any time, from inside the app:

  • Export any note as a PDF or as PNG images and share or save it.
  • Disconnect Google Drive. Notes stay on the device; the copy in your Drive stays in your Drive for you to keep or delete.
  • Cancel Pro from Billing & Subscription; it stays active until the end of the paid period.
  • Delete your account (see below).

Depending on where you live you may also have rights under the GDPR, the CCPA, Malaysia’s PDPA or similar laws — including the right to a copy of your data or to have it corrected or deleted. Email support@quantyr.co and we’ll help.

9. Deleting your account

Profile → Delete account asks you to confirm your identity again, then, in one pass: deletes the Nota Notes folder in your Google Drive (if connected), cancels your subscription and deletes your Stripe customer, removes your saved signatures, scrubs your account record on our server, deletes your sign-in identity, and erases every note, folder and image the app holds on that device. This happens immediately and cannot be undone.

Step-by-step instructions, the full list of what is deleted and what is kept, and how to request deletion if you cannot get into the app, are on the Delete your account page.

10. Data retention

We keep each kind of data only as long as it is needed for the purpose it was collected for:

  • Account record (user ID, email, display name, provider) — for as long as your account exists. Deleted when you delete your account.
  • Subscription and billing record — for as long as your account exists, then retained by Stripe for the period its own policy and applicable tax and anti-fraud law require.
  • Drive binding (which Google account holds your folder) — until you delete your account or we unbind it at your request.
  • Saved signatures — until you delete them in the App or delete your account.
  • Notes, images and PDFs — on your device until you delete them or the App; in your Google Drive until you or we delete that folder. We hold no copy.
  • Server request logs — no more than 30 days, then discarded.
  • Deletion tombstone — a record containing no personal data, kept indefinitely so the deletion itself stays auditable.

11. Children

Nota : Quick Notes is not directed at children under 13. If you believe a child has created an account, contact us and we’ll delete it.

12. International transfers

Our providers may process data outside your country. Where required, we rely on standard contractual clauses or equivalent safeguards.

13. Changes to this policy

If we make material changes we’ll say so in the app or by email before they take effect.

14. Contact

Privacy questions or requests? support@quantyr.co.

Questions? Email support@quantyr.co.