To move focus out of the editor, press Escape and then Tab.

Privacy Policy

Version 1.0 — Last updated: 20 August 2026

Snownotes is operated by Sirap Pty Ltd (ACN 652 857 844) ("we", "us"), a company incorporated in New South Wales, Australia. This policy explains what personal information we collect when you use Snownotes at snownotes.co and in the Snownotes apps, how we use it, and the choices you have. For any question or request about your data, email info@snownotes.co. For the purposes of the GDPR, Sirap Pty Ltd is the data controller.

The short version

  • We collect the minimum a notes service needs: your email address, your notes, and the technical records that keep the service secure.
  • We run no analytics, no advertising trackers, and we never sell your data.
  • We never use your notes to train AI models.
  • AI features send note content only to a provider you configure yourself, only when you use them.
  • Your data is stored in Australia.

What we collect

Account. Your email address and password. Passwords are stored as salted hashes, never in plain text. If you sign in with Google or GitHub (where offered), we instead receive your email address, name, and profile picture from that provider.

Your notes. The notes you write, including version history and an edit log (which account changed a note, and when). We keep these so sync, version recovery, and collaborative editing work. If you add collaborators to a note, they can see the note, its edit history, and your email address.

Waitlist and invites. If you join the waitlist, we store your email address. Invites record the invited email address and when the invite was used.

Security records. Sign-in session records (including when a session was last active), email-verification tokens, and password-reset requests. Password-reset requests include the IP address they were made from, to prevent abuse.

Server logs. Like any web service, our servers record requests — IP address, browser type, the page or endpoint requested, and the time — for security and diagnostics. Logs used to diagnose sync problems reference your account and note identifiers, but never note content. We keep server logs for no more than 30 days.

What we don't collect

We use no analytics or session-replay tools, no advertising or social-media trackers, and no fingerprinting. Our cookies are limited to what the service needs to function — see the Cookie Policy. We make no automated decisions about you and build no profiles.

AI features

AI features are optional and only run against a provider you configure:

  • Local models (for example LM Studio or Ollama): your note content goes directly from your device to the local server you configured. It never touches our servers.
  • Cloud providers (for example OpenAI, Anthropic, or Google): your API key is stored only in your browser. When you use an AI feature, the request — including the note content it needs — passes through our server to the provider you chose. We relay it in transit only: we do not store or log the content or your key.
  • Content you send to a provider is handled under that provider's own terms and privacy policy, and may be processed wherever that provider operates.
  • We never use your notes to train AI models, and we do not permit providers to do so on our behalf.

How and why we use information

PurposeLegal basis (GDPR)
Providing the service: storing, syncing, and displaying your notes, and collaboration you initiatePerformance of our contract with you
Transactional email: account verification, password resets, account and service noticesPerformance of our contract with you
Keeping the service secure and preventing abuse (security records, server logs)Our legitimate interest in running a safe service
Telling waitlist members when they can joinConsent, given when you join the waitlist
Complying with lawLegal obligation

We do not send marketing email without your separate consent, and every such email will include an unsubscribe link. Providing your email address is necessary to have an account; everything else is optional.

Where your data lives and who processes it

Snownotes is hosted on Amazon Web Services in Sydney, Australia (region ap-southeast-2). Our sub-processors:

  • Amazon Web Services — hosting and email delivery.

If you are in the EEA or the UK, note that your data is stored in Australia, a country that does not have an EU or UK adequacy decision. We collect it directly from you and protect it as this policy describes.

AI providers you configure act at your direction, not ours, and are not sub-processors. We will update this list if it changes.

How long we keep it

  • Account data and notes: for as long as your account is active.
  • Note version history: thinned over time (older snapshots are progressively consolidated).
  • Email-verification tokens: 24 hours. Invites: 14 days by default. Sign-in sessions: 30 days of inactivity.
  • Password-reset records: 30 days.
  • Server logs: no more than 30 days.
  • Deleted accounts: deactivated immediately; we remove the account's personal data from our production systems and backups within 30 days of your request.

Your rights

You can ask us to access, correct, delete, or export your data at any time by emailing info@snownotes.co. We acknowledge requests within 7 days and respond within 30 days. We may ask you to confirm the request from the email address on your account.

If you are in the EEA or the UK, the GDPR applies to you. In addition to the above, you have the right to object to processing based on our legitimate interests, to restrict processing, to data portability, and to withdraw any consent you have given (without affecting what was done before you withdrew it). If you think we have handled your data wrongly, tell us first so we can fix it; you also have the right to complain to the supervisory authority where you live.

In Australia, you can complain to us first and, if you are not satisfied with our response, to the Office of the Australian Information Commissioner (OAIC).

Security

Data is encrypted in transit (TLS). Passwords are hashed. Access to production systems is limited. No service is perfectly secure, and Snownotes is in beta — please export notes you cannot afford to lose.

If a data breach is likely to put you at risk, we will tell you without undue delay, and we will notify the relevant authority within the time the law requires (72 hours under the GDPR).

Children

Snownotes is not directed at children under 16. Do not create an account if you are under 16.

Changes

We will post changes on this page, bump the version, and update the date above. For material changes we will notify you by email or in the app before they take effect.

Contact

Sirap Pty Ltd (ACN 652 857 844) — info@snownotes.co