Privacy Policy

Last updated: 24 September 2026 ← Back home

This policy explains how Doppler HQ, Inc. ("Doppler", "we", "us") handles information when you use footnotes, its website at footnotes.rest, and related services.

1. Information footnotes handles

Depending on the features you use, the app can handle:

The website links to Footnotes on the Apple App Store and Google Play. Apple or Google may process information when you follow those links under their own policies. If you complete our early-access survey, we collect the answers and contact details you choose to provide. Contacting us through Instagram or email causes those providers to process the information you send under their own policies.

2. On-device storage and permissions

The cloud notebook stores acknowledged notes and media in Footnotes cloud systems, with a device cache and pending edits and recordings in application storage. Pending work is not yet saved to the cloud and can be lost if the app is deleted before upload finishes. After sign-in, Footnotes automatically recovers accessible older local vaults into the account linked to that migration, with resumable progress and verified uploads. Temporarily unavailable sources are retried; restoring access to another folder may require the system picker. Migration does not automatically delete originals. During onboarding, Footnotes asks for camera access as the photo step begins, microphone and speech-recognition access as the voice step begins, and foreground location access before you keep the note so it can label where the note happened. At other times, it asks for those permissions when their related capture experience begins. Captures and scanned pages are not automatically copied to Photos or a user-selected folder. Footnotes accesses your photo library when you choose media to import; explicit sharing and export can create copies outside the app. You can decline or later change these permissions in your device settings. A denied permission affects only its related feature.

Your operating-system or device-backup settings may create copies under Apple, Google, or your backup provider's terms. Footnotes hosted service content is separate from those device backups. Production builds automatically run background hosted operations for your cloud notebook, described in section 3.

3. Hosted features and enrichment

The cloud notebook requires Apple or Google sign-in. The authentication service and notebook service use separate logical databases. Signing into the same account on another device lets you access notes and media that have been acknowledged by the cloud service.

Cloud workflows handle notebook content, titles, photos, recordings, transcripts, location, generated summaries, timestamps, note colour, settings, and related metadata in private systems operated for Footnotes. Writes can remain pending while disconnected and retry when the app reconnects. Existing local vaults and older hosted backups are separate import sources.

The Footnotes team accesses hosted notebook content only where needed to operate the service, investigate a fault, respond to a support request you raise, or carry out internal product research into how Footnotes is used. That access is logged separately from ordinary analytics and is never sent to PostHog.

When you request cloud transcription and summaries, configured cloud workers process the note's source media and writing using Google Cloud processing services. Generated results are associated with source revisions and remain separate from your writing.

4. Website and app analytics

We use PostHog on the website and automatically in the production app to understand whether Footnotes works and which product flows are used. App analytics can include screen and lifecycle events, capture type, permission outcomes, app environment, platform and app/build version. The app uses a pseudonymous analytics identifier bound to your signed-in account across devices; it does not use your email or sign-in identifier as the analytics identity. Onboarding, sign-in and permission steps taken before you sign in are kept only in the app's memory and sent with your account's analytics after you sign in; nothing is sent if you never sign in or if analytics is off for your account. Development and preview analytics are disabled. Website analytics can include page views, sessions, page category and store, social, or early-access link choices. On the early-access survey page, PostHog also processes the survey answers and any contact details you deliberately submit so that we can arrange research conversations and manage early access.

Our app analytics implementation is designed not to send note text, titles, transcripts, email addresses, note identifiers, hosted owner or device identifiers, photographs, recordings, media paths, or location. We disable automatic IP-based geographic enrichment in the PostHog configuration and do not enable session replay for Footnotes. Network providers still receive an IP address as part of ordinary internet transport.

Before sign-in, production mobile builds may ask PostHog whether an app update is recommended or required. This check uses a shared platform label rather than an account or device identifier, does not send note content or analytics events, and is separate from behavioral analytics. The app compares its installed build number locally. An optional update dismissal is stored on the device.

Production mobile builds use Sentry for crash and unhandled-error diagnostics, separately from product analytics. Reports include error messages, stack traces, device model, app/build and operating-system information, connection type (Wi-Fi or cellular) when sign-in fails, crash-free session counts, and a short trail of recent app activity (screen names, capture steps, and which network requests the app made, without their contents). Your account appears in Sentry only as a random-looking identifier that cannot be traced back to you, so we can tell how many people a problem affects. We do not attach notes, photographs, audio, video, transcripts, screenshots, session replays, or console logs. Email addresses, sign-in tokens, and web address parameters are removed on the device, and native crash reports are additionally scrubbed by Sentry before storage. Sentry receives an IP address during transport, but this project is configured not to store it. Development and preview builds do not send these diagnostics.

5. How we use information

We use information to provide capture and playback, save and synchronize cloud notebooks, preserve pending captures on the device, perform enrichment you initiate, conduct internal product research, respond to early access and support requests, measure reliability and feature use, prevent abuse, and comply with law. We do not sell notebook content or use it for targeted advertising.

6. When information is shared

We share information only as needed with:

7. Retention and deletion

Moving a cloud note to Trash hides it from the active library and allows restoration. Permanent deletion removes its canonical content and schedules original media and generated files for cleanup. Cleanup retries also cover uploads that finish after deletion. Short-lived media links already issued may remain usable until they expire or the object is removed. Content-free identifiers can remain to prevent old devices or legacy imports from recreating permanently deleted notes. Service backups remain subject to reasonable backup cycles and legal obligations.

Deleting the cloud library does not delete older local vault originals, separate legacy backups, copies saved to Photos or device backups, or the authentication account. Copies sent to an independently configured enrichment endpoint are outside the cloud library's deletion path. Contact us to request deletion of associated legacy hosted data or your account.

Signing out closes the visible cloud library and pauses that account's pending work without deleting its account or cloud content. Account and provider-link records remain while the account is active. We retain early access and support communications while responding to you, handling abuse, or meeting legal requirements. Analytics follows configured provider retention settings. You can request deletion of your account, associated hosted data, support information, or analytics through our account deletion page. We may need enough information to verify and complete the request.

8. Security

We use reasonable technical and organizational safeguards appropriate to a small product. No storage or transmission method is completely secure. Keep your device protected and do not treat Footnotes as the only copy of information you cannot afford to lose.

9. International processing

Doppler HQ, Inc. is a United States company. Our providers may process information in the United States, Singapore, and other countries where they operate. Those places may have different data-protection laws from where you live.

10. Children

Where local law requires parental consent for a child to use a service like Footnotes, they may use it only with that consent. Contact us if you believe a child provided information to our website or hosted services without appropriate consent.

11. Your rights

You can stop using Footnotes, delete individual notes, uninstall the app, ask us to delete associated hosted data, decline device permissions, change permissions in device settings, or stop contacting us about early access. Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to our processing of personal information. Email us to make a request.

12. Changes to this policy

We will update this page and its date when Footnotes' data practices materially change. Where appropriate, we will provide an additional notice in the app or by email.

13. Contact

For privacy questions or requests, email hi@doppler.life.

Data controller: Doppler HQ, Inc., 3830 94th Ave NE, Yarrow Point, WA 98004, United States.