Notelert Privacy Policy
Last Updated: July 24, 2026
1. Introduction
Notelert ("we", "our", "the application") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our Notelert mobile application, web application, and related services.
This policy is provided when personal data is collected and remains permanently accessible from the Android app, the Obsidian plugin, and our website. Our Terms of Service govern use of the service; this privacy notice is not a request for marketing consent.
Data controller: Joaquim Frances, Verdaguer 5, Odena, Barcelona, Spain. You can contact the controller at notelert@proton.me.
2. Information We Collect
2.1. Account Information
You can create a Notelert account either with Google Sign-In in Android or by verifying an email address in the Obsidian plugin. Depending on the method used, we collect:
- Email address: The Google account email or the email you verify in the plugin
- Name and profile picture: If supplied by Google Sign-In (optional)
- Internal user ID: A unique identifier used to keep your data together across installations
- Account source and verification status: Whether the identity was created by Google or verified email and when it was verified
If you later sign in to Android with the same verified email, the email-created profile is merged into the Google-authenticated account so reminders, usage, and plugin links remain associated with one account.
2.1.1. Trial Abuse Prevention
To prevent repeated deletion and re-creation of an account solely to obtain additional trials, we create a keyed cryptographic fingerprint of the normalized, verified email address. We do not retain the email address in this anti-abuse record. The fingerprint is used only to determine whether that verified email has already received a trial in the preceding six months.
2.2. Notification Information
To provide the reminder service, we collect and store:
- Notification title and message: The content of your reminders
- Scheduled date and time: When you want to receive notifications
- Notification type: Whether it's a time-based or location-based notification
- Notification status: Whether it has been read, completed, or canceled
- Obsidian links: If the notification is linked to an Obsidian document
2.3. Location Information
For location-based notifications, we collect:
- Saved locations: Addresses, place names, and geographic coordinates (latitude and longitude) that you manually save
- Geofencing data: Information needed to trigger notifications when you enter or exit specific areas
- Location permissions: We request access to your location in the foreground and background to provide location-based reminders
Important Note: We do not continuously track your location in real-time. We only use location when:
- You create or edit a saved location
- The application needs to verify if you are inside or outside a specific geographic area to trigger a notification
2.4. Google Calendar Information (Optional)
If you connect your Google Calendar account, we collect:
- OAuth access tokens: Access and refresh tokens to access your Google Calendar
- Calendar events: Title, description, date and time of events created in your calendar
- Event IDs: Identifiers of events created in Google Calendar linked to your notifications
This information is used solely to synchronize your notifications with Google Calendar. You can disconnect Google Calendar at any time from the application settings.
2.5. Device Information
To provide push notifications and improve the service, we collect:
- Device token: Unique identifier for sending push notifications to your device
- Device type: Platform (iOS or Android) and device model
- Operating system: Operating system version
- Installation ID: Unique identifier of the application installation
2.6. Obsidian Plugin Information (Optional)
If you use the Obsidian plugin for Notelert:
- Authentication token: A unique token generated to link your Notelert account with the Obsidian plugin
- Token expiration date: When the authentication token expires
- Token status: Whether the token is active or has been revoked
- Installation identifier: A random identifier used to bind email verification and sensitive account actions to the requesting plugin installation
2.7. Premium Subscription Information
If you subscribe to Notelert Premium:
- Subscription status: Whether you have an active subscription
- Expiration date: When your subscription or trial period expires
- Product ID: Identifier of the purchased subscription product
- Billing information: Provider, Stripe customer and subscription identifiers where applicable, plan, status, and renewal or expiration date. Stripe, Google Play, or the applicable app store processes card and bank details; Notelert does not store them.
2.8. Usage Information
We keep the preferences needed to operate the app. Optional diagnostics are collected only if you switch them on in Android settings:
- Language preferences: Language selected in the application
- Notification settings: Whether you have enabled push notifications, email notifications, etc.
- Theme settings: Light/dark theme preference
- Debug logs: Only if you enable debug mode (optional)
- Optional diagnostics: App events such as reminder received/opened and crash diagnostics. We do not send reminder content, email addresses, locations, or a Notelert account ID to Firebase Analytics or Crashlytics for this purpose.
2.9. Technical Information
When optional diagnostics are enabled, Firebase may process technical device/app information and its app-instance identifier to diagnose issues and improve reliability. Advertising, ad-personalisation, and account-level analytics identifiers are disabled.
- Error logs: Information about errors that occur in the application
- Performance information: Application performance metrics (only in debug mode)
2.10. iPhone and App Store Waiting List Information (Optional)
If you voluntarily sign up for our iPhone waiting list on our website:
- Email Address: We collect and store your email address.
- Registration Timestamp: The date and time you signed up.
Consent to email updates: By submitting your email on the waitlist form, you consent to receiving emails from Notelert about the iPhone beta, App Store release timeline, and related iOS product updates for that waitlist. This is separate from marketing emails unrelated to the iOS launch.
This data is stored securely in Cloud Firestore (within the "iPhoneList" collection) and is used exclusively to notify you when the Notelert iOS/App Store version is released, as well as providing relevant product updates. You can unsubscribe or request the deletion of your email from this list at any time by contacting us.
3. How We Use Your Information
We use the collected information to:
3.1. Provide the Service
- Create, schedule, and send notifications according to your preferences
- Manage time-based and location-based reminders
- Synchronize notifications with Google Calendar (if enabled)
- Provide integration with the Obsidian plugin
- Manage your account and subscription
- Manage the iPhone and App Store waiting list to send you launching notifications (if you voluntarily signed up)
3.2. Improve the Service
- Diagnose and resolve technical issues
- Analyze application usage to improve functionality
- Develop new features and capabilities
3.3. Communication
- Send push notifications about your reminders
- Send transactional verification codes and reminder emails when enabled, subject to the limits of your plan
- Respond to your inquiries and support requests
3.4. Legal Compliance
- Comply with legal obligations
- Protect our rights and prevent fraud
- Respond to valid legal requests
4. Third-Party Services
Notelert uses the following third-party services that may collect information:
4.1. Google Services
- Google Sign-In: For authentication and account creation
Privacy Policy: https://policies.google.com/privacy - Google Calendar API: To synchronize events with your calendar (optional)
Privacy Policy: https://policies.google.com/privacy - Google Maps API: For address search and geocoding
Privacy Policy: https://policies.google.com/privacy
4.2. Firebase (Google Cloud Platform)
We use Firebase for:
- Firebase Authentication: User authentication
- Cloud Firestore: Storage of user data, notifications, locations, device tokens, and waiting list emails
- Cloud Functions: Server-side processing and business logic
- Firebase Cloud Messaging (FCM): Push notification delivery
Firebase Privacy Policy: https://firebase.google.com/support/privacy
Diagnostics choice: Firebase data required to authenticate, store reminders, and deliver FCM messages remains necessary for the service. Firebase Analytics and Crashlytics collection are disabled by default and only enabled after you turn on Optional diagnostics in Android settings; you can withdraw that choice there at any time.
4.3. Expo
We use Expo for application development and distribution:
- Expo Updates: Application updates
- Expo Notifications: Local notification management
- Expo Location: Location services
Expo Privacy Policy: https://expo.dev/privacy
4.4. Stripe / Google Play Store / Applicable App Store
For Premium subscriptions, payment processing is handled through:
- Google Play Billing: For Android devices
- Stripe: For subscriptions purchased from the Obsidian plugin or Notelert website
These services process your payment information. We do not store or have access to credit card information.
4.5. Email Delivery Providers
We use Resend for transactional delivery of verification codes and reminders. Resend processes the destination email address and message content solely to deliver those messages. We do not use reminder email addresses for marketing.
5. Information Sharing
We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
We share information only in the following circumstances:
5.1. Service Providers
We share information with service providers who help us operate the application, such as:
- Google (Firebase, Google Sign-In, Google Calendar, Google Maps)
- Expo (development platform)
- Resend (transactional email delivery)
- Hosting and cloud service providers
These providers are contractually obligated to protect your information and may only use it for specified purposes.
5.2. Legal Compliance
We may disclose information if necessary to:
- Comply with a court order, subpoena, or legal process
- Respond to government requests
- Protect our rights, privacy, security, or property
- Prevent fraud or illegal activity
5.3. Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
6. Data Security
We implement technical and organizational security measures to protect your information:
6.1. Technical Measures
- Encryption in transit: All communications use HTTPS/TLS
- Encryption at rest: Sensitive data is stored encrypted in Firebase
- Authentication: Data access protected by user authentication
- Security rules: Firestore Security Rules ensure only you can access your data
- Secure tokens: Authentication tokens are stored securely
6.2. Organizational Measures
- Limited access: Only authorized personnel have access to data
- Regular audits: We regularly review and update our security practices
- Monitoring: We monitor data access to detect suspicious activity
6.3. Limitations
Although we implement robust security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
7. Data Retention
7.1. Active Data
We retain your information while:
- Your account is active
- We need to provide the service
- It is necessary to comply with legal obligations
7.2. Account Deletion
When you delete your account:
- We cancel pending Notelert cloud tasks and delete account data, reminders, locations, device records, quota records, and authentication tokens from our active systems
- We delete verified email mappings, one-time account-action challenges, and linked plugin installations
- We delete the Firebase authentication identity for Google-authenticated accounts
- We delete stored Google Calendar credentials. Events already created in your Google Calendar remain in your Google account and can be removed there
Trial-abuse record: after deletion, we retain only the keyed cryptographic fingerprint described in section 2.1.1, its creation date, and its expiry date for up to six months from the verified-email trial claim. It is isolated from the deleted account and automatically removed at expiry. We use it solely to prevent repeated trial claims.
Subscriptions: Account deletion does not automatically cancel a subscription managed by Stripe, Google Play, or another app store. Cancel it with the billing provider before deleting the account to prevent future renewals.
Delivery records and required retention: We retain email delivery records for up to 90 days and Resend webhook event records for up to 30 days, then remove them through an automated cleanup. Residual copies may remain temporarily in restricted service-provider backups until their normal overwrite cycle. Data that must be retained for security, fraud prevention, accounting, or another legal obligation will be isolated, access-restricted, and retained only for the applicable period.
7.3. Anonymous Data
We may retain anonymized and aggregated data that does not personally identify any user for analytical and service improvement purposes.
8. Your Rights (GDPR and CCPA)
If you reside in the European Union, California, or other jurisdictions with data protection laws, you have the following rights:
8.1. Right of Access
You can export your data from Android or from Account & Privacy in the Obsidian plugin. A fresh one-time code sent to the verified email is required when exporting from the plugin. Authentication credentials and provider tokens are excluded from the export for security.
8.2. Right of Rectification
You can correct or update your information at any time through the application or by contacting us.
8.3. Right to Deletion ("Right to be Forgotten")
You can delete the global account from Android, from Account & Privacy in the Obsidian plugin, or through our public account deletion page. Plugin and web deletion require a fresh one-time code sent to the verified email.
8.4. Right to Object
You can object to processing based on legitimate interests, including the six-month trial-abuse fingerprint. Contact us for a case-by-case review; an objection may mean that a new trial cannot be granted while the anti-abuse rule applies.
8.5. Right to Data Portability
You can request that your data be transferred to another service provider. You can export your data from the application.
8.6. Right to Restriction
You can request that we limit the processing of your personal data in certain circumstances.
8.7. Withdraw Consent
You can withdraw consent for optional diagnostics at any time in Android Settings → Privacy & Data, without affecting core reminder features.
To exercise these rights, you can:
- Use the built-in controls in Android or the Obsidian plugin
- Use the public deletion page
- Contact us at: notelert@proton.me
We will respond to your request within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent data-protection supervisory authority.
9. Application Permissions
Notelert requests the following permissions:
9.1. Location
- Foreground location: To create and manage saved locations
- Background location: To trigger notifications when you enter or exit specific geographic areas
Usage: These permissions are essential for location-based notifications. You can disable location access in your device settings, but this will limit the functionality of location-based notifications.
9.2. Notifications
- Push notifications: To send reminders and alerts
- Local notifications: To schedule notifications on the device
Usage: Essential for the main functionality of the application.
9.3. Internet and Network
- Internet access: To synchronize data with our servers
- Network status: To verify connectivity
Usage: Necessary to synchronize notifications, locations, and account data.
9.4. Local Storage
- Device storage: To save preferences and cache data locally
Usage: Improves performance and allows partial offline functionality.
10. Cookies and Similar Technologies
Notelert is a mobile application and does not use traditional cookies. However, we use similar technologies:
- Authentication tokens: To keep you signed in
- Local storage: To save preferences and cache data
- Device identifiers: To send push notifications
These technologies are essential for the application to function.
11. Children's Privacy
Notelert is not directed to children under 14 years of age, or the higher minimum age required in the person's jurisdiction. We do not knowingly collect personal information from children. If we discover that we have collected information from a child, we will delete it immediately.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
12. International Data Transfers
Our service providers may process data outside the European Economic Area, including in the United States. These transfers are not based on your general consent to this policy. Where required, we rely on an adequacy decision, the EU-U.S. Data Privacy Framework where the provider participates, or the European Commission's Standard Contractual Clauses and supplementary safeguards.
- Google / Firebase: cloud, authentication, messaging, and optional diagnostics. Firebase terms include Google's data-processing terms.
- Resend: transactional email delivery; its Data Processing Addendum incorporates transfer safeguards, including Standard Contractual Clauses.
- Stripe: payment processing; its Data Processing Agreement includes a Data Transfers Addendum and transfer mechanisms.
- Expo: app update and development services, where used.
You can request information about the applicable safeguards by contacting us. Payment providers and app stores may also act as independent controllers for their own payment and platform processing.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the new policy in the application
- Sending a push notification (if enabled)
- Updating the "Last Updated" date at the top
We encourage you to review this policy periodically. Continued use of Notelert after changes constitutes your acceptance of the revised policy.
14. Contact
If you have questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, you can contact us:
Email: notelert@proton.me
We will respond to your inquiry as soon as possible, generally within 30 days.
15. Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal data based on:
- Consent: For optional diagnostics, after you actively enable them in the Android settings; Google Calendar is processed when you request that optional integration
- Contract performance: To provide the service you have requested
- Legitimate interest: To maintain security, prevent fraud (including the limited six-month trial-abuse fingerprint), and operate aggregated reliability monitoring
- Legal obligation: To comply with legal requirements
16. Additional Information
16.1. Data Not Collected
We do not collect:
- Contact information from your address book
- Content of your messages or emails (except those you send through Notelert)
- Information from other applications installed on your device
- Biometric information
16.2. Data Shared with Obsidian Plugin
If you use the Obsidian plugin for Notelert:
- The plugin can access your notifications through a secure authentication token
- The plugin can display a limited account summary and, after fresh email verification, request a structured export of your data
- You can revoke only the current installation or delete the global account from the plugin
- Raw authentication, push, and Google OAuth credentials are never included in exports
16.3. Email Notifications
Email verification and reminder messages are transactional service communications sent through our servers and selected delivery provider. Free, trial, and Premium plans have different reminder limits. Your address is not used for unrelated marketing without separate consent.