Přejít na obsah

Privacy

Privacy Policy

Last updated: June 2026

The short version

We collect your email address and encrypted vault content. We never store or read the plaintext of your notes or files. We do not sell your data to anyone. You can delete everything at any time.

What we collect

  • Email address: used to identify your account and send you check-in reminders and vault delivery notifications.
  • Name (optional): displayed to your recipients when they receive vault content.
  • Phone number (optional, Pro/Guardian): if you add a phone number for SMS check-in alerts, we store it to send you notifications and verification codes. Your phone number is transmitted to Twilio (our SMS provider) to deliver these messages.
  • Telegram chat ID (optional, Pro/Guardian): if you connect Telegram for check-in alerts, we store your Telegram chat ID so we can send you notifications.
  • Vault content: your notes and files, stored encrypted. We don't read them. Unlike Sealed Vault, Notenz holds the key needed to deliver your vault automatically, so we technically could. See our Security page for details.
  • Recipient and trusted contact details: names, email addresses, and (optionally) phone numbers you add for your recipients and trusted contacts. These are stored so we can deliver your vault and send notifications to those people.
  • Check-in settings: your check-in interval and grace period preferences.
  • QR-Vault PIN (Guardian): if you generate a QR-Vault, we store a bcrypt hash of your 6-digit PIN. We never store the PIN itself in a readable form.
  • IP address and basic request logs: retained briefly for security and debugging. Not used for tracking or advertising.

What we do NOT collect

  • ✗ We do not use advertising trackers or pixels
  • ✗ We do not share your data with third-party advertisers
  • ✗ We do not read the plaintext of your vault content
  • ✗ We do not build profiles for marketing purposes

Third-party services we use

We use a small number of specialist providers to run Notenz. Each only receives the minimum data needed for its job, and each has its own data protection agreement with us.

  • Resend: email delivery. Your email address is shared with Resend to send you notifications.
  • Lemon Squeezy: payment processing. Lemon Squeezy handles billing; we do not store your card details.
  • Supabase: database hosting for your account and vault data, and encrypted file storage for vault file attachments. Files are encrypted before they reach this storage.
  • DigitalOcean: application hosting (the servers that run Notenz).
  • Telegram: if you connect your Telegram account for check-in alerts (Pro/Guardian), your Telegram chat ID is stored so we can send you notifications.
  • Twilio: if you verify a phone number for SMS check-in alerts (Pro/Guardian), your phone number and the content of those messages are shared with Twilio to send them. Twilio is based in the United States. See the International Transfers section below.
  • Sentry: error tracking, so we can find and fix bugs. Error reports are scrubbed of vault content and sensitive fields before being sent.
  • Umami: privacy-friendly website analytics. Cookieless, no personal data or cross-site tracking.

International data transfers

Most of your data stays within the EU on DigitalOcean and Supabase infrastructure. Some sub-processors are based in the United States:

  • Resend: your email address is shared to send transactional notifications. Resend provides SCCs as a transfer mechanism under GDPR Article 46(2)(c).
  • Lemon Squeezy: your email address is shared for billing. Lemon Squeezy provides SCCs under GDPR Article 46(2)(c).
  • Twilio: if you enable SMS notifications, your phone number and message content are shared. Twilio participates in the EU-U.S. Data Privacy Framework and provides SCCs under GDPR Article 46(2)(c).
  • Sentry: anonymised error reports are sent to help us debug issues. Error data is scrubbed of vault content and personal identifiers before transmission. Sentry participates in the EU-U.S. Data Privacy Framework.

All transfers listed above rely on an adequate safeguard in place under GDPR Article 46.

Legal basis for processing

We process your personal data on the following legal grounds under GDPR Article 6:

  • Contract performance (Article 6(1)(b)): processing your email address, vault content, check-in settings, and notification channels (phone, Telegram) is necessary to provide the Notenz service you signed up for. This includes a short onboarding email sequence (Days 1, 2, and 4 after signup) to help you set up your vault. You can unsubscribe from these at any time via the link in each email.
  • Legitimate interest (Article 6(1)(f)): we retain minimal audit records and IP logs to maintain security and debug issues. We believe this interest is proportionate and does not override your rights.
  • Legal obligation (Article 6(1)(c)): billing records are retained for up to 7 years to comply with German tax and financial reporting requirements.

Partner program

If you signed up via an invitation from a Notenz partner (for example, a financial advisor or estate planning firm), your account is linked to that partner organisation. The partner can see your email address, account status, and the date of your last check-in. They cannot see your vault contents, recipients, or any other personal data. You can download all data we hold about you at any time from Settings > Export my data.

How long we keep your data

Your data is retained while your account is active. The table below covers each data type:

  • Vault notes and files : Until you delete them, or 30 days after vault execution, or 30 days after subscription freeze, whichever comes first.
  • Two-Person Secret file copies : When a file vault item is delivered as a Two-Person Secret, an encrypted copy is stored temporarily to allow any 2 of the recipients you selected to coordinate and download. This copy is retained for up to 90 days from vault execution, then permanently deleted. The copy is stored encrypted; Notenz cannot read its contents.
  • Account data (email, settings) : Until you delete your account, or 30 days after vault execution.
  • Execution audit record : Kept indefinitely. This is a minimal record only, containing your email address, execution date, deletion date, and item count. No vault content is included.
  • Activity log (audit events) : Retained while your account is active. Deleted when your account is deleted.
  • Billing records : Retained for up to 7 years to comply with financial regulations.

If you delete your account manually, all vault content, recipients, and personal data are permanently deleted immediately.

Your rights (GDPR)

If you are in the EU or UK, you have the following rights regarding your personal data:

  • Access: request a copy of all data we hold about you. Use the Export my data feature in Settings.
  • Rectification: correct inaccurate data from your account settings.
  • Erasure: delete your account and all associated data from Settings. Account deletion is immediate. We will process manual erasure requests submitted by email within 30 days.
  • Portability: download your data in a machine-readable format using the Export feature.
  • Objection: object to processing based on legitimate interest. Email us and we will review within 30 days.
  • Restriction: request that we restrict processing of your data while a dispute is resolved.

You also have the right to lodge a complaint with a supervisory authority. In Germany, the competent authority is the Federal Commissioner for Data Protection and Freedom of Information (BfDI): www.bfdi.bund.de. You may also contact the data protection authority in your country of residence.

We will respond to all data rights requests within 30 days.

Cookies

We use a session cookie to keep you logged in and a CSRF security cookie to protect forms against cross-site request forgery. No third-party cookies or tracking cookies of any kind are used.

Data controller

The data controller responsible for this service is:
Ahmed El Taweel, trading as Klarschritt (Einzelunternehmen)
Irmtraud-Morgner-Straße 11, 10318 Berlin, Germany
[email protected]

Contact

Privacy questions or data requests: [email protected].