Privacy Policy
Version 1.0 — Last updated: 20 August 2026
Snownotes is operated by Sirap Pty Ltd (ACN 652 857 844) ("we", "us"), a company incorporated in New South Wales, Australia. This policy explains what personal information we collect when you use Snownotes at snownotes.co and in the Snownotes apps, how we use it, and the choices you have. For any question or request about your data, email info@snownotes.co. For the purposes of the GDPR, Sirap Pty Ltd is the data controller.
The short version
- We collect the minimum a notes service needs: your email address, your notes, and the technical records that keep the service secure.
- We run no analytics, no advertising trackers, and we never sell your data.
- We never use your notes to train AI models.
- AI features send note content only to a provider you configure yourself, only when you use them.
- Your data is stored in Australia.
What we collect
Account. Your email address and password. Passwords are stored as salted hashes, never in plain text. If you sign in with Google or GitHub (where offered), we instead receive your email address, name, and profile picture from that provider.
Your notes. The notes you write, including version history and an edit log (which account changed a note, and when). We keep these so sync, version recovery, and collaborative editing work. If you add collaborators to a note, they can see the note, its edit history, and your email address.
Waitlist and invites. If you join the waitlist, we store your email address. Invites record the invited email address and when the invite was used.
Security records. Sign-in session records (including when a session was last active), email-verification tokens, and password-reset requests. Password-reset requests include the IP address they were made from, to prevent abuse.
Server logs. Like any web service, our servers record requests — IP address, browser type, the page or endpoint requested, and the time — for security and diagnostics. Logs used to diagnose sync problems reference your account and note identifiers, but never note content. We keep server logs for no more than 30 days.
What we don't collect
We use no analytics or session-replay tools, no advertising or social-media trackers, and no fingerprinting. Our cookies are limited to what the service needs to function — see the Cookie Policy. We make no automated decisions about you and build no profiles.
AI features
AI features are optional and only run against a provider you configure:
- Local models (for example LM Studio or Ollama): your note content goes directly from your device to the local server you configured. It never touches our servers.
- Cloud providers (for example OpenAI, Anthropic, or Google): your API key is stored only in your browser. When you use an AI feature, the request — including the note content it needs — passes through our server to the provider you chose. We relay it in transit only: we do not store or log the content or your key.
- Content you send to a provider is handled under that provider's own terms and privacy policy, and may be processed wherever that provider operates.
- We never use your notes to train AI models, and we do not permit providers to do so on our behalf.
How and why we use information
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service: storing, syncing, and displaying your notes, and collaboration you initiate | Performance of our contract with you |
| Transactional email: account verification, password resets, account and service notices | Performance of our contract with you |
| Keeping the service secure and preventing abuse (security records, server logs) | Our legitimate interest in running a safe service |
| Telling waitlist members when they can join | Consent, given when you join the waitlist |
| Complying with law | Legal obligation |
We do not send marketing email without your separate consent, and every such email will include an unsubscribe link. Providing your email address is necessary to have an account; everything else is optional.
Where your data lives and who processes it
Snownotes is hosted on Amazon Web Services in Sydney, Australia (region ap-southeast-2). Our sub-processors:
- Amazon Web Services — hosting and email delivery.
If you are in the EEA or the UK, note that your data is stored in Australia, a country that does not have an EU or UK adequacy decision. We collect it directly from you and protect it as this policy describes.
AI providers you configure act at your direction, not ours, and are not sub-processors. We will update this list if it changes.
How long we keep it
- Account data and notes: for as long as your account is active.
- Note version history: thinned over time (older snapshots are progressively consolidated).
- Email-verification tokens: 24 hours. Invites: 14 days by default. Sign-in sessions: 30 days of inactivity.
- Password-reset records: 30 days.
- Server logs: no more than 30 days.
- Deleted accounts: deactivated immediately; we remove the account's personal data from our production systems and backups within 30 days of your request.
Your rights
You can ask us to access, correct, delete, or export your data at any time by emailing info@snownotes.co. We acknowledge requests within 7 days and respond within 30 days. We may ask you to confirm the request from the email address on your account.
If you are in the EEA or the UK, the GDPR applies to you. In addition to the above, you have the right to object to processing based on our legitimate interests, to restrict processing, to data portability, and to withdraw any consent you have given (without affecting what was done before you withdrew it). If you think we have handled your data wrongly, tell us first so we can fix it; you also have the right to complain to the supervisory authority where you live.
In Australia, you can complain to us first and, if you are not satisfied with our response, to the Office of the Australian Information Commissioner (OAIC).
Security
Data is encrypted in transit (TLS). Passwords are hashed. Access to production systems is limited. No service is perfectly secure, and Snownotes is in beta — please export notes you cannot afford to lose.
If a data breach is likely to put you at risk, we will tell you without undue delay, and we will notify the relevant authority within the time the law requires (72 hours under the GDPR).
Children
Snownotes is not directed at children under 16. Do not create an account if you are under 16.
Changes
We will post changes on this page, bump the version, and update the date above. For material changes we will notify you by email or in the app before they take effect.
Contact
Sirap Pty Ltd (ACN 652 857 844) — info@snownotes.co