1. Who we are, and how to contact us

FancyNotes is provided by Big Dog Software Development, a sole trader based in the United Kingdom. For the purposes of UK GDPR and EU GDPR, we are the data controller for the personal data described in this policy.

If you have any question, request, or concern about your data or this policy, email us at support@fancynotes.co. We'll do our best to get back to you promptly.

This policy applies to the FancyNotes apps (Android, iOS, Windows, macOS), our website at fancynotes.co, and our guest web collaboration pages.

2. The data we collect, and where it comes from

We only collect what FancyNotes actually needs to work. Here's everything, grouped by type:

Account and identity information — provided by you when you sign up or edit your profile:

  • Email address
  • Password — we never store this in plain text; our authentication system keeps only a salted cryptographic hash of it
  • Display name
  • Avatar (an emoji you pick, and/or an image you upload)
  • Optional profile background image

If you sign up or sign in with Google Sign-In or Sign in with Apple instead of a password, that provider supplies us with your name and email address. Apple also lets you use its "Hide My Email" feature, which gives us a private relay address instead of your real one — we fully support that.

Content you create — this is the heart of the app, all provided directly by you:

  • Notes: rich text, checklists, spreadsheets
  • Voice recordings
  • Sketches and drawings
  • Handwriting
  • Inline images
  • Journal and calendar events (title, description, dates and times)
  • Folders you organise your notes into

Communications — provided by you as you use the app:

  • Group chat messages and 1:1 direct messages (message text)
  • Contacts you add to the app, including any nickname you give them

Sharing and social information — generated as you use FancyNotes' collaborative features:

  • Groups you create or join (name, description, membership list)
  • Your activity feed (a record of sharing/collaboration events relevant to you)
  • Note-sharing permissions (who you've shared which note with, and at what permission level)
  • Your online/offline presence status, visible to people you share notes or groups with

Technical information — collected automatically to make the app work:

  • A push-notification token (Google Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) and a platform label ("android" or "ios")
  • Your IP address — this is inherent to how the internet works: any server your device talks to (ours, Google's, Apple's) can see it. Our backend's API gateway also records this in standard access-log metadata, kept for 7 days (see §8, Retention)

We do not collect: device fingerprints, advertising identifiers, or your precise location. We have no reason to, and we don't want it.

If you're a guest (you've opened a shared note via a link, without a FancyNotes account): we store the display name you type in, and show it to the people you're collaborating with on that note.

3. How and why we use your data

We use your data for one purpose: to provide and secure the FancyNotes service you signed up for. Specifically:

  • Storing, syncing and displaying your notes, events and other content across your devices
  • Delivering push notifications
  • Powering in-app search
  • Enabling sharing, groups, and chat between you and your collaborators
  • Authenticating you and keeping your account secure
  • Keeping the service reliable and free of abuse

We do not use your data for advertising, we do not sell it, we do not build behavioural profiles from it, and we don't run third-party analytics or tracking of any kind. There is nothing to opt out of, because it isn't happening in the first place.

For each way we use your data, we rely on one of the following lawful bases:

Legal basisWhat it covers
Performance of a contractRunning the core service you signed up for: your account, storing and syncing your notes, sharing, groups, and chat. We can't provide FancyNotes without processing this data.
Legitimate interestsKeeping the service secure, preventing abuse, maintaining reliability, and showing presence status to your collaborators. We've weighed this against your privacy and consider it a fair, expected part of running a shared collaboration tool.
ConsentAnything you can separately switch on or off: granting the app permission to send push notifications on your device, and using the microphone with cloud-based speech transcription (voice-to-text). You can withdraw this consent at any time through your device settings.
Legal obligationHandling data-rights requests (see §9) and any other obligation the law places on us.

4. Third parties and sub-processors

We keep the list of organisations who can see any of your data very short. Here it is, in full:

Google LLC

  • Firebase Cloud Messaging (FCM) delivers push notifications to Android devices. Google receives your device's push token. Our push messages are "data-only" — they do not contain your note or message text; the actual content is resolved locally on your device after the notification arrives.
  • If you sign in with Google Sign-In, Google processes your name and email address as part of that sign-in flow.
  • If you use voice-to-text transcription on Android, your spoken audio is sent to Google's speech-recognition service to be transcribed.
  • Separately, FancyNotes' handwriting recognition and image text-recognition (OCR) run entirely on your device using Google's ML Kit. Only a one-time model file is downloaded from Google; your handwriting strokes and images are never sent to Google (or anywhere) for this feature.

Apple Inc.

  • Apple Push Notification service (APNs) delivers push notifications to iOS devices, in the same data-only fashion described above.
  • If you sign in with Sign in with Apple, Apple processes your name and email address (or a private relay address, if you choose "Hide My Email").
  • If you use voice-to-text transcription on iOS, your spoken audio is sent to Apple's speech-recognition service to be transcribed.

Our own infrastructure
Everything else — your account, notes, media, chat messages, and search index — is stored on servers we operate ourselves (under the fancynotes.co domain), running open-source components we self-host: a PostgreSQL database, a self-hosted Supabase instance (authentication, API, realtime sync, storage), MinIO object storage, a Meilisearch search index, and our own custom sync server. We do not hand your data to any managed third-party cloud database, backend-as-a-service, or analytics platform.

What we don't do

To be completely clear: FancyNotes contains no advertising SDKs, no crash-reporting SDKs, no third-party analytics, and no tracking technology of any kind. The only outside parties who ever see any of your data are Google and Apple, and only for the specific, narrow purposes listed above.

5. International transfers

Because Google and Apple are global companies, the push-notification, sign-in, and speech-transcription processing described in §4 may involve your data being processed on servers outside the UK and European Economic Area (EEA). Where this happens, it's covered by the relevant legal safeguards — such as the UK's International Data Transfer Agreement, the EU's Standard Contractual Clauses, or an applicable adequacy decision — as provided under each company's own privacy terms.

For our own infrastructure: your account, notes, media, and other content are stored on servers we operate in a data centre in the United Kingdom, so your core data stays in the UK. The only processing that takes place outside the UK is the third-party push-notification, sign-in, and speech-transcription handling described in §4, under the safeguards noted above.

6. Sharing and visibility

FancyNotes is built for sharing — here's exactly how visibility works:

  • Notes and events you share with a person, or with a group, become visible to that person, or to everyone currently in that group. If you share something with a group, every current member can see it — including anyone who joins the group later, for as long as the share remains active.
  • Guest share links let anyone holding the link view — and, if you enable it, edit — the shared note for the lifetime of the link (7 or 30 days, your choice when you create it). You can revoke a link at any time, which immediately cuts off access.
  • Your presence (whether you're currently online) is visible to people you share notes or groups with.
  • Profile pictures and background images can be viewed by other signed-in FancyNotes users generally — this is what makes contact lists and shared spaces work smoothly (for example, seeing a collaborator's avatar next to their name).

We never share your data with anyone outside of what's described here and in §4 — no marketing partners, no data brokers, no one else.

7. How we protect your data

We take security seriously, and we want to be precise about exactly what that means:

In transit: every connection between the app and our servers uses TLS — HTTPS for API calls, secure WebSockets for real-time sync and chat. Nothing goes over the wire unencrypted.

On your device: your local note database is encrypted at rest (using SQLCipher), and cached images are separately encrypted (AES-GCM). Your login session is stored in your operating system's secure credential storage (e.g. Android Keystore, iOS/macOS Keychain, Windows credential storage), not in plain text.

On our servers — please read this carefully: your content is stored so that FancyNotes can do the things you rely on it for — syncing across your devices and full-text search. This means your note content is not end-to-end encrypted. Because our servers need to index and search your notes, and merge edits between your devices, our systems — and by extension, the people who operate them — can technically access the content of your notes if needed to run, maintain, or support the service. This is a deliberate trade-off to support server-side search and sync, and we think you deserve to know about it plainly, not have it buried in fine print.

What we do to limit that access and keep your content safe:

  • Database-level row security and per-user scoping, so your data is only queryable by you and the people you've explicitly shared it with
  • Private object storage for media (photos, voice recordings, sketches), accessed only via time-limited signed links — never publicly readable
  • Operator access to production data is limited to what's genuinely needed to run and support the service

If end-to-end encryption matters a great deal to you for a particular note, please bear this limitation in mind — search and multi-device sync are the reasons we don't offer it today.

8. How long we keep your data

  • We keep your account and content for as long as your account exists, or until you delete the specific item.
  • Deleted notes go to a recycle bin first, before being permanently removed — this gives you a safety net against accidental deletion.
  • Version history is kept automatically, but capped: older automatic snapshots are pruned over time, while named milestones (ones you've explicitly labelled) are kept indefinitely.
  • Analytics and diagnostic logs are automatically deleted after 7 days. Standard web-server access logs are retained for a short period (typically a few weeks) for security and troubleshooting, then rotated out.
  • We take routine backups of our database for disaster-recovery purposes, stored securely on our own infrastructure. When you delete content or your account, it's removed from our live systems immediately; any residual copy in a backup will age out and be overwritten on our normal backup rotation shortly afterwards.
  • Deleting your account removes your account and associated data from our live systems (see §10).

9. Your rights

If you're in the UK or EEA (UK GDPR / EU GDPR)

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Port your data to another service
  • Withdraw consent at any time, where we rely on consent (e.g. push notifications, voice transcription)

To exercise any of these, email support@fancynotes.co. We'll respond as required by law.

You also have two self-service tools built right into the app:

  • You → Privacy & Security → Delete Account — permanently erases your account and data
  • Backup & Restore — export your own notes as an encrypted file, any time you like

If you're unhappy with how we've handled your data, you have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO)ico.org.uk. If you're in the EU, you can also complain to your local data-protection authority.

If you're in California (CCPA/CPRA)

California residents have the right to:

  • Know what personal information we've collected about you
  • Delete your personal information
  • Correct inaccurate personal information
  • Opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising

We don't sell or share your personal information for cross-context behavioural advertising — there's nothing to opt out of, because we don't do it. We will never discriminate against you for exercising any of these rights.

To exercise any California privacy right, email support@fancynotes.co.

10. Account deletion

You're always in control. To permanently delete your FancyNotes account:

  1. Open the app and go to You → Privacy & Security → Delete Account
  2. Confirm — this is permanent and cannot be undone

This removes your account and everything associated with it: your notes, media, chats, calendar events, and profile. Please note: if you own any groups, ownership is automatically transferred to another member so the group continues without interruption. A group is only deleted if you're its sole member.

Or, email us at support@fancynotes.co and we'll delete it for you.

11. Children

FancyNotes is not directed to children under 13, and you must be at least 13 years old to create an account or use the service. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with personal data, please contact support@fancynotes.co and we will remove it.

Some jurisdictions set a higher age (for example, 16) for a young person to give their own consent to certain kinds of data processing. If that applies to you, please make sure a parent or guardian has given consent, or use the service under their supervision, in line with your local law.

12. Changes to this policy

We may update this policy from time to time — for example, if we add a new feature that changes what data we collect. If we make a material change, we'll update the effective date at the top of this document and, where appropriate, let you know in the app. We encourage you to check back periodically.

This policy is also published at https://fancynotes.co/privacy.

13. Contact us

Questions, requests, or complaints about this policy or your data:

Big Dog Software Development
Email: support@fancynotes.co
Website: fancynotes.co

UK supervisory authority: Information Commissioner's Office (ICO)ico.org.uk

See also our Terms of Service.