Ringnote

Privacy Policy

App: RingnoteDeveloper: RingnoteLast Updated: 2026/June/27

Privacy Policy — Ringnote.ai

Last Updated: June 19, 2026

Ringnote (“we,” “our,” or “us”) operates the Ringnote mobile application (the “App”). Ringnote utilizes a proprietary, patent-pending architecture (Application No: LK/P/1/24004) featuring a local-first data framework paired with a cloud-based authentication system. This Privacy Policy explains how we collect, store, use, disclose, and protect your information in strict compliance with the Google Play Developer Policy and international data protection regulations.

By downloading, installing, or using the App, you agree to the data practices described in this policy. If you do not agree with any part of this policy, please do not use the App.

Minimum Age Requirement & Minor Protections

The App is not directed at children, and we do not knowingly collect personal information from anyone under 16 years of age. If you are located in the United States, the threshold for digital consent is 13 years of age, subject to applicable parental consent requirements for users under 18. If we learn that we have collected personal information from a child under the applicable legal age threshold without verified parental consent, we will delete that information promptly. If you believe a child has provided us with personal data, please contact us using our team email details.

Cloud Infrastructure, Account Data, & System Logs (Supabase)

While your conversational data remains locally on your device, we maintain a secure centralized database managed via our third-party infrastructure sub-processors solely to manage user accounts, authentication, application routing, and usage tracking.

Account Profile Data: Depending on your chosen registration method, we collect and store your name, email address, unique authentication identifiers, and/or mobile number on our cloud servers. Passwords are secured using cryptographic hashing techniques.

System and Operational Logs: To maintain application performance, prevent system abuse, and manage resource billing, our infrastructure automatically processes and logs metadata related to your account. This includes tracking note usage quotas, token metrics, endpoint usage timestamps, and cost tracking logs.

Data Retention: We retain your account profile and associated operational logs for as long as your account remains active. If you request account deletion, we will permanently purge your profile data from our live databases within 30 days, except where limited records are strictly required for legal, tax, or fraud-prevention purposes.

Core Privacy Philosophy: Local Storage & Data Loss Disclaimer

To maximize your privacy, Ringnote does not upload or store your private notes, text summaries, task lists, or historical call records on our cloud servers.

Local Processing: All generated text notes, conversational summaries, task lists, and chat histories are saved strictly within your device’s secure local storage.

Data Loss Liability Disclaimer: Because this data is kept strictly on your physical hardware, Ringnote does not maintain duplicates or backups on its cloud infrastructure. You are solely responsible for managing your local content. Ringnote accepts zero responsibility or liability for any permanent data loss, corruption, or deletion resulting from app uninstallation, clearing app cache/system data in device settings, factory resets, or device damage/loss.

Audio Files & Transient Processing: Voice notes exist in temporary transit memory during real-time processing. Audio data is securely transmitted via encrypted tunnels to our third-party AI processing infrastructure (Google Gemini API). Audio files are held in secure, ephemeral transit staging storage managed by the AI provider solely for the duration of the real-time inference loop and are automatically deleted immediately after text generation. We never write or save your raw audio files to permanent cloud disks.

Device Permissions & Prominent Disclosures

To function as an automated, post-call assistant, the App requires specific device permissions.

Prominent Disclosure Requirement: In compliance with Google Play Policies, the App will display a clear, plain-language runtime notification dialog inside the interface before requesting sensitive system permissions. These permissions are used strictly to provide core, user-initiated features and are never used to harvest background activity or aggregate your historical data.

  • Call Logs and Phone State (READ_CALL_LOG, READ_PHONE_STATE): Used in real time, exclusively to detect when a phone call ends to look up the immediate caller name or phone number. This data is used solely to instantly map and sync the post-call note overlay to that specific contact or number within your local workspace. We do not index, store, log, or upload your historical logs or caller identities to any external servers.
  • Contacts (READ_CONTACTS): Used strictly for internal, user-initiated note-taking within the App. When a user manually taps the plus (“+”) icon inside the application interface, this permission allows them to browse and select a contact locally to file a manual note underneath it. Your contact directory is handled entirely locally and is never transmitted or shared externally.
  • Microphone (RECORD_AUDIO): Used solely to capture your voice when you manually tap the record button to dictate an audio note via our GUI overlay. It never listens continuously or automatically.
  • System Overlay / Notifications / Draw Over Apps: Used to display our user interface overlay or push a local prompt to your screen immediately after a call ends or when an alarm reminder triggers, allowing you to interface with the app’s full-screen tools over other active applications.

Automated Data Collection & Analytics Disclosure

When you interact with the App, certain system and interaction metadata is collected automatically by standard operating system workflows and embedded developer software development kits (SDKs):

  • IP Address & Network Data: We automatically collect your Internet Protocol (IP) address as part of standard network communication, API routing, and backend hosting infrastructure services. This data is used strictly for security diagnostics, standard API routing, authentication verification, and service operations.
  • Device Identifiers: The App utilizes integrated framework packages that inherently interact with device identifiers (such as Android ID or Advertising ID) provided by Google Play Services to monitor backend session authentication and core app integrity.
  • Firebase Analytics: We use Google Analytics for Firebase to automatically collect specific application interaction data, app lifecycle events, and device metadata. This data is compiled as aggregated statistics to help us diagnose app crashes, understand user navigation patterns, and improve application performance.
  • Analytics Limitations & Controls: While you can reset or limit your mobile hardware Advertising ID via your native device settings (e.g., via Android Settings → Google → Ads), please note that this reset does not completely disable baseline, non-targeted Firebase behavioral event collection.

Real-Time AI Processing & Sub-Processors

To convert your natural language text or audio inputs into structured summaries and alarms, your inputs are routed through an enterprise processing pipeline.

Google Gemini API: Real-time data is transmitted via an encrypted (HTTPS/TLS) connection to the Google Gemini model for live inference. Under enterprise developer API terms, data sent through this API is processed temporarily to generate your summary and is not used by the AI provider to train public foundational models.

Approved Sub-Processor List: We utilize the following contractually bound sub-processors to safely deliver our core services and maintain our network routing:

  1. Supabase Inc. (Cloud account database, endpoint logging, and secure authentication management).
  2. Render Services (Cloud application server hosting, backend execution, and secure API network routing).
  3. Google LLC / Gemini API (Enterprise AI language and audio processing pipeline).
  4. Google Firebase (Secure user authentication and aggregated usage analytics).

European Union (GDPR) and UK Legal Basis for Processing

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases pursuant to Article 6 of the General Data Protection Regulation (GDPR):

  • Performance of a Contract: To create your account, manage your digital subscription balances, and deliver our core automated note-taking services.
  • Your Explicit Consent: For specific device-level triggers, such as granting runtime microphone, overlay, or phone state permissions.
  • Legitimate Interests: To maintain the cryptographic security of our app, monitor server routing, review crash diagnostics via Firebase analytics, prevent server-side API abuse, and enforce platform safety measures.

Your Data Rights (Access, Portability, and Deletion)

Depending on your location, you may hold rights under local data protection laws (such as the GDPR and CCPA), including:

  • The right to access the personal data we hold about your account.
  • The right to request the correction or permanent deletion of your account profile data.
  • The right to data portability (receiving your profile information in a portable format).
  • The right to object to or restrict certain processing behaviors.
  • The right to lodge an official complaint with your local data protection authority.

Account Deletion: You may request permanent deletion of your account profile data (name, email, phone number) from our databases at any time by contacting us via our account deletion page.

Local Content Deletion: To clear your notes, summaries, and automated reminders, you can delete specific entries within the App interface, clear the App’s cache inside your device operating system settings, or uninstall the App entirely.

Data Security Standards

We implement industry-standard administrative and technical security safeguards to defend your data. All data moving between the App, Render, Supabase, Firebase, and the Gemini API is fully protected via encryption in transit using HTTPS/TLS protocols. User passwords and cloud authentication channels are protected using strong data hashing mechanisms.

In the unlikely event of a data breach affecting your account information, we will notify affected users and relevant supervisory authorities as required by applicable law.

Changes to This Policy & Notice Period

We may update this Privacy Policy from time to time. If we make material changes to how we handle your personal data, we will notify you through the App interface or via your registered email account at least 14 days before the changes take effect, allowing you to review the revised terms under standard regulatory transparency guidelines. Your continued use of the App after the 14-day notice period expires constitutes acceptance of the revised policy.

Contact Us & Data Protection Inquiries

If you have questions regarding this Privacy Policy, wish to exercise your data rights, or request permanent cloud account deletion, please contact us at: