Privacy Policy
1. Data controller
Data controller: Pierre Ostrowiecki. Contact: hello@undernote.app. Legal notice: undernote.app/en/legal-notice. Version of 4 September 2026.
2. Data we collect
Undernote collects only what is necessary to operate the service.
- Account: email address, password (hashed by our authentication provider, never readable in plain text), username, optional bio and profile photo, language chosen in the app.
- Content: your notes (text, photos, audio recordings, chosen GPS position, audience, reading and visibility radii, lifetime), comments, likes, echoes, narrative threads, conversation messages, notes you have read, list of blocked accounts.
- Points campaign: your points calculated at each weekly settlement, the optional declaration of your referrer and referral links (referrer and referrals).
- Technical: push notification tokens (to send you alerts), timestamps of your age attestation and acceptance of the terms of use, notification preferences.
Your date of birth is requested at registration solely to verify the minimum age: it is not stored. Only the timestamp of the attestation is kept.
3. Legal bases
In accordance with Article 13(1)(c) of the GDPR, here is the legal basis for each category of processing.
- Performance of contract (Art. 6(1)(b) GDPR): creating and managing the account, publishing and reading notes and content, operating the map, conversations and messaging, sending operational notifications (new followers, likes, comments, echoes), authentication by email or third-party login.
- Legitimate interest (Art. 6(1)(f) GDPR): security of the service and prevention of abuse (moderation, anti-fraud system for the points campaign, retention of moderation decisions), retention of data from banned accounts to prevent abusive behaviour and recidivism, crash reports (improving app stability; you can exercise your right to object at any time via Settings, Privacy, Crash reports). For other processing based on legitimate interest (security, moderation, anti-fraud, banned account data), you may exercise your right to object by writing to hello@undernote.app.
- Consent (Art. 6(1)(a) GDPR): optional push alerts (bells, notification preferences adjustable at any time), declaration of a referrer in the points campaign.
- Legal obligation (Art. 6(1)(c) GDPR): retention and transmission of reports to the competent authorities when a legal obligation requires it (DSA Art. 18, LCEN Art. 6). The review of reports by our moderation team, which involves access to the data of both the reporting user and the reported profile, including photos and audio recordings, is covered by this legal basis.
4. Location
Your location is used to operate the map: finding notes within your radius. While the app is open, your last known position is sent to the server: a single point, overwritten on every update, never retained as a history. It is used to find notes around you, to avoid notifying you about a note outside its visibility radius, and, if you enable them, for proximity alerts and the weekly network digest. Your location is never shown to other users and is deleted with your account.
During a points campaign, approximate positions (about 2 km precision) are also retained for up to 8 weeks, solely to detect campaign fraud; they are never visible to other users and are deleted with your account.
When a user relays your note through an echo, their position at the time of the echo is copied and frozen as the centre of their echo bubble; this position data is retained for the lifetime of the carried note. In addition, the app collects a simulated-position indicator (detection provided by Android and iOS) transmitted to the server on every position update, solely to detect campaign fraud.
5. Address book
The "Find my people" feature is currently disabled: the app does not read your address book, and no phone number is collected or stored. Numbers declared in the past have been erased from our servers. If the feature returns, this policy will be updated before it is enabled.
6. Processors and transfers outside the EU
Undernote uses the following service providers. Each processes personal data under its own data protection commitments.
- Supabase Ireland Ltd (Ireland, European Union): database, authentication, storage of text content. Intra-EU transfer, no additional mechanism required.
- Cloudflare, Inc. (United States): storage of private photos and audio recordings (R2), website hosting, geocoding relay. Transfer covered by the EU-US Data Privacy Framework (DPF).
- Google LLC (United States): push notifications via Firebase Cloud Messaging (push notifications may contain an excerpt of the triggering content) and crash reports via Firebase Crashlytics. Transfer covered by the DPF.
- Google LLC (United States): authentication via Google sign-in, if you choose this option. Transfer covered by the DPF.
- Google LLC (United States): if you install the app on Android, the Google Play Install Referrer may contain the username of the person who invited you, transmitted to Google Play at the time of clicking the invitation link. Transfer covered by the DPF.
- Apple Inc. (United States): push notifications via APNs (push notifications may contain an excerpt of the triggering content) and authentication via Sign in with Apple, if you use an iOS device. Transfer covered by the standard contractual clauses included in Apple's developer agreements.
- Resend Inc. (United States, certified DPF participant no. 8907): sending of our transactional emails: one-time login codes (OTP), moderation emails (decisions concerning you and the outcome of your reports) and routing of feedback and bug reports submitted from the app to our contact address. Attached photos are transmitted as attachments.
- Zoho Corporation (contact mailbox hosted in European Union data centres): hosting of our contact mailbox (hello@undernote.app), where your emails, feedback and data-rights requests arrive. Any transfer outside the EU is governed by Zoho's data processing addendum (standard contractual clauses).
- OpenFreeMap: map tiles. Only anonymous tile requests are sent to it (no personal data).
- Nominatim / OpenStreetMap Foundation: geocoding of places searched on the map. When you search for a place, the text of your search is relayed by our server without your identity or IP address. Nothing else is shared with it.
7. Crash reports
If the app runs into a technical problem, a crash report is sent through Firebase Crashlytics, a Google service. This report contains technical information: device model, system version, technical device identifiers and the state of the app at the time of the incident. It does not contain your notes, your messages or your location. These reports are used only to fix bugs. You can turn them off at any time in Settings, Privacy, Crash reports.
8. Retention periods
Retention periods vary depending on the nature of the data.
- Ephemeral notes: permanently deleted upon expiry (1 day, 1 week or 1 month depending on your choice), including photos and audio recordings, during the daily automatic cleanup.
- Permanent notes and their content (text, photos, audio): retained for as long as the account exists, deleted when the account is deleted.
- Account and associated data (profile, comments, likes, echoes, threads, conversations, messages, follows and followers): retained for as long as the account exists, deleted when it is deleted.
- Current GPS position: a single point per user, overwritten on every update (no history retained), deleted with the account.
- Campaign anti-fraud data (approximate positions, push token switches, detection signals): automatically purged after 8 weeks at each weekly settlement.
- Campaign settlement data (points awarded, referrals): retained until the account is deleted.
- Campaign loyalty indicator: an indicator relating to your following activity (used to calculate the merit of participation length) is retained for the duration of your account.
- Referral link: the referrer-referral relationship is retained for as long as both accounts exist. It is automatically deleted when either account is closed.
- Reports and copies of content: a copy of the reported content is retained for moderation purposes and cooperation with the authorities, for the duration of the existence of both the reporting account and the reported profile. The copy is deleted when either of those accounts is deleted.
- Moderation decisions: each decision concerning you (hiding, restoration, removal, ban, outcome of a report) and its statement of reasons are retained for as long as your account exists and deleted with it.
- Campaign moderation decisions (anti-fraud review): records of fraudulent behaviour are retained for the duration of the account concerned and deleted with it. The legal basis is legitimate interest (prevention of abusive behaviour and recidivism).
- Notes you have read: retained until the account is deleted.
- List of blocked accounts: retained until the account is deleted.
- Banned accounts: in the event of a serious breach of the terms of use, an account may be permanently disabled. Associated data is retained to prevent abusive behaviour and to cooperate with the authorities. You may exercise your GDPR rights by writing to hello@undernote.app.
- Feedback and bug reports: the text of your feedback is transmitted by Resend to our contact address and retained in our mailbox until manually deleted. In the database, it is retained until your account is deleted. Attached photos are deleted from our servers at the next weekly cleanup, at most around ten days after submission; the email we receive remains our archive of the feedback.
- Push notification tokens: deleted with the account.
9. Your rights
In accordance with the GDPR and the French Data Protection Act (Loi Informatique et Libertés), you have the following rights:
- Access: obtain a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data (subject to legal exceptions, in particular retention obligations relating to moderation and cooperation with the authorities).
- Portability: receive your data in a structured, machine-readable format (where processing is based on your consent or on the performance of a contract).
- Objection: object to processing based on legitimate interest.
- Restriction: request the suspension of processing pending resolution of a dispute.
- Withdrawal of consent: withdraw consent previously given at any time (for example, optional alerts), without affecting the lawfulness of processing carried out before that withdrawal.
- Post-mortem instructions (your instructions on what happens to your data after your death): in accordance with Articles 85 and 86 of the French Data Protection Act, you may give instructions concerning the retention, deletion or communication of your data after your death. Send these instructions by email to hello@undernote.app. In the absence of instructions, your heirs may contact us to exercise certain rights.
Account deletion is directly available in the app (Settings, Delete my account). To exercise any other right, write to hello@undernote.app; we respond within one month. If a dispute is not resolved, you may lodge a complaint with the CNIL (French data protection authority) at cnil.fr or with the data protection authority of your country of residence.
10. Security
Undernote implements appropriate technical measures to protect your data:
- all communications between the app, our servers and our service providers are encrypted in transit (TLS);
- access to data in the database is restricted by Row-Level Security rules: each user can only read what their audience entitles them to;
- photos and audio recordings are stored in a private space and are only accessible via signed links with a limited lifespan, verified by the server;
- the moderation console is protected by dedicated authentication separate from the app.
11. Children
Undernote is for people who meet the minimum age set out in the terms of use (section 2 of the Terms). No data from minors below that age is intentionally processed. No advertising profiling is carried out on any user. A recommendation system is used to suggest notes and profiles in the Discover screen, based on your location, your follows and your reading history, with no advertising profiling or external behavioural analysis. Pushed recommendations are adjustable in the notification settings.
12. Cookies and trackers
The app uses no advertising cookies and no third-party trackers. No data is sold or used for advertising purposes.
13. Changes to this policy
This policy may change to reflect changes to the service or legal obligations. In the event of a substantial modification, you will be informed by an in-app notification with reasonable notice. Versions are dated; the version in force is always available at undernote.app/en/privacy.