Privacy Policy
This policy explains how Doppler HQ, Inc. ("Doppler", "we", "us") handles information when you use footnotes, its website at footnotes.rest, and related services.
1. Information footnotes handles
Depending on the features you use, the app can handle:
- note text, titles, timestamps, speech transcripts, and other writing;
- photographs, audio recordings, and video or frame data you deliberately capture;
- precise latitude and longitude when you grant foreground location permission, used to label where a note began;
- camera, microphone, speech-recognition, photo-library, and location permission states;
- your Apple or Google account identifier, name, email address, provider account data, session information, and encrypted provider tokens when you sign in;
- diagnostic state needed to save notes, retry hosted feature workflows or optional enrichment, and recover from interruptions.
The website links to Footnotes on the Apple App Store and Google Play. Apple or Google may process information when you follow those links under their own policies. If you complete our early-access survey, we collect the answers and contact details you choose to provide. Contacting us through Instagram or email causes those providers to process the information you send under their own policies.
2. On-device storage and permissions
The cloud notebook stores acknowledged notes and media in Footnotes cloud systems, with a device cache and pending edits and recordings in application storage. Pending work is not yet saved to the cloud and can be lost if the app is deleted before upload finishes. After sign-in, Footnotes automatically recovers accessible older local vaults into the account linked to that migration, with resumable progress and verified uploads. Temporarily unavailable sources are retried; restoring access to another folder may require the system picker. Migration does not automatically delete originals. During onboarding, Footnotes asks for camera access as the photo step begins, microphone and speech-recognition access as the voice step begins, and foreground location access before you keep the note so it can label where the note happened. At other times, it asks for those permissions when their related capture experience begins. Captures and scanned pages are not automatically copied to Photos or a user-selected folder. Footnotes accesses your photo library when you choose media to import; explicit sharing and export can create copies outside the app. You can decline or later change these permissions in your device settings. A denied permission affects only its related feature.
Your operating-system or device-backup settings may create copies under Apple, Google, or your backup provider's terms. Footnotes hosted service content is separate from those device backups. Production builds automatically run background hosted operations for your cloud notebook, described in section 3.
3. Hosted features and enrichment
The cloud notebook requires Apple or Google sign-in. The authentication service and notebook service use separate logical databases. Signing into the same account on another device lets you access notes and media that have been acknowledged by the cloud service.
Cloud workflows handle notebook content, titles, photos, recordings, transcripts, location, generated summaries, timestamps, note colour, settings, and related metadata in private systems operated for Footnotes. Writes can remain pending while disconnected and retry when the app reconnects. Existing local vaults and older hosted backups are separate import sources.
The Footnotes team accesses hosted notebook content only where needed to operate the service, investigate a fault, respond to a support request you raise, or carry out internal product research into how Footnotes is used. That access is logged separately from ordinary analytics and is never sent to PostHog.
When you request cloud transcription and summaries, configured cloud workers process the note's source media and writing using Google Cloud processing services. Generated results are associated with source revisions and remain separate from your writing.
4. Website and app analytics
We use PostHog on the website and automatically in the production app to understand whether Footnotes works and which product flows are used. App analytics can include screen and lifecycle events, capture type, permission outcomes, app environment, platform and app/build version. The app uses a pseudonymous analytics identifier bound to your signed-in account across devices; it does not use your email or sign-in identifier as the analytics identity. Onboarding, sign-in and permission steps taken before you sign in are kept only in the app's memory and sent with your account's analytics after you sign in; nothing is sent if you never sign in or if analytics is off for your account. Development and preview analytics are disabled. Website analytics can include page views, sessions, page category and store, social, or early-access link choices. On the early-access survey page, PostHog also processes the survey answers and any contact details you deliberately submit so that we can arrange research conversations and manage early access.
Our app analytics implementation is designed not to send note text, titles, transcripts, email addresses, note identifiers, hosted owner or device identifiers, photographs, recordings, media paths, or location. We disable automatic IP-based geographic enrichment in the PostHog configuration and do not enable session replay for Footnotes. Network providers still receive an IP address as part of ordinary internet transport.
Before sign-in, production mobile builds may ask PostHog whether an app update is recommended or required. This check uses a shared platform label rather than an account or device identifier, does not send note content or analytics events, and is separate from behavioral analytics. The app compares its installed build number locally. An optional update dismissal is stored on the device.
Production mobile builds use Sentry for crash and unhandled-error diagnostics, separately from product analytics. Reports include error messages, stack traces, device model, app/build and operating-system information, connection type (Wi-Fi or cellular) when sign-in fails, crash-free session counts, and a short trail of recent app activity (screen names, capture steps, and which network requests the app made, without their contents). Your account appears in Sentry only as a random-looking identifier that cannot be traced back to you, so we can tell how many people a problem affects. We do not attach notes, photographs, audio, video, transcripts, screenshots, session replays, or console logs. Email addresses, sign-in tokens, and web address parameters are removed on the device, and native crash reports are additionally scrubbed by Sentry before storage. Sentry receives an IP address during transport, but this project is configured not to store it. Development and preview builds do not send these diagnostics.
5. How we use information
We use information to provide capture and playback, save and synchronize cloud notebooks, preserve pending captures on the device, perform enrichment you initiate, conduct internal product research, respond to early access and support requests, measure reliability and feature use, prevent abuse, and comply with law. We do not sell notebook content or use it for targeted advertising.
6. When information is shared
We share information only as needed with:
- PostHog, which processes limited app and website analytics and early-access survey submissions on our behalf;
- Sentry, which processes limited production mobile crash diagnostics on our behalf;
- our website hosting provider, which delivers footnotes.rest;
- Apple and Google, when you sign in, follow a store link, or install Footnotes through their services;
- private cloud storage, database, and processing providers, including Google Cloud, used for hosted Footnotes features;
- an enrichment endpoint you or a Footnotes build configures, when you use enrichment;
- professional advisers, authorities, or counterparties when required by law or a corporate transaction; and
- other providers you choose to contact, such as Instagram or email.
7. Retention and deletion
Moving a cloud note to Trash hides it from the active library and allows restoration. Permanent deletion removes its canonical content and schedules original media and generated files for cleanup. Cleanup retries also cover uploads that finish after deletion. Short-lived media links already issued may remain usable until they expire or the object is removed. Content-free identifiers can remain to prevent old devices or legacy imports from recreating permanently deleted notes. Service backups remain subject to reasonable backup cycles and legal obligations.
Deleting the cloud library does not delete older local vault originals, separate legacy backups, copies saved to Photos or device backups, or the authentication account. Copies sent to an independently configured enrichment endpoint are outside the cloud library's deletion path. Contact us to request deletion of associated legacy hosted data or your account.
Signing out closes the visible cloud library and pauses that account's pending work without deleting its account or cloud content. Account and provider-link records remain while the account is active. We retain early access and support communications while responding to you, handling abuse, or meeting legal requirements. Analytics follows configured provider retention settings. You can request deletion of your account, associated hosted data, support information, or analytics through our account deletion page. We may need enough information to verify and complete the request.
8. Security
We use reasonable technical and organizational safeguards appropriate to a small product. No storage or transmission method is completely secure. Keep your device protected and do not treat Footnotes as the only copy of information you cannot afford to lose.
9. International processing
Doppler HQ, Inc. is a United States company. Our providers may process information in the United States, Singapore, and other countries where they operate. Those places may have different data-protection laws from where you live.
10. Children
Where local law requires parental consent for a child to use a service like Footnotes, they may use it only with that consent. Contact us if you believe a child provided information to our website or hosted services without appropriate consent.
11. Your rights
You can stop using Footnotes, delete individual notes, uninstall the app, ask us to delete associated hosted data, decline device permissions, change permissions in device settings, or stop contacting us about early access. Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to our processing of personal information. Email us to make a request.
12. Changes to this policy
We will update this page and its date when Footnotes' data practices materially change. Where appropriate, we will provide an additional notice in the app or by email.
13. Contact
For privacy questions or requests, email hi@doppler.life.
Data controller: Doppler HQ, Inc., 3830 94th Ave NE, Yarrow Point, WA 98004, United States.