Sunote ("App," "we," "us," or "our") respects your privacy. This Privacy Policy explains how personal data is collected, used, stored, and shared when you use the Sunote app.
Sunote is an iOS app developed by Ufuk Özen. It is an AI-powered note-taking assistant that supports audio recording, speech recognition, AI summaries, action items, quizzes, flashcards, mind maps, and note chat.
| Data Type | Description | How It Is Collected |
|---|---|---|
| Audio Recordings | Audio files recorded or imported through the App, stored locally in .m4a format | When you record or import audio |
| Speech Transcripts | Text generated from audio recordings | Through Apple's Speech framework; recognition may be on-device or may use Apple services when on-device recognition is unavailable or not selected |
| Note Content | Text you write or content generated by AI | User input / AI generation |
| Web URLs | Links submitted to fetch an article on the device | User input |
| Photos | Images added from the camera or photo library and stored locally when used in a note | User selection |
| Folders and Tags | Organization metadata you create for notes | User-created |
| Data Type | Description | Purpose |
|---|---|---|
| Device Attestation Data | App Attest key ID and client instance ID | Securing AI API requests |
| App Account Token | Anonymous user identifier provided by StoreKit 2 | Subscription management |
| Transaction Data | Subscription JWS evidence provided by StoreKit | Subscription validation |
| AI Operation Metadata | Feature, trigger, note identifier, request-key prefix, prompt size/token estimates, model/provider, token usage, outcome, app version/build, and error information | Request handling, rate limiting, security, billing, reliability, and service quality |
Sunote may store summaries, action items, quiz questions, mind maps, flashcards, note chat history, and suggested follow-up questions from your note content. It may also infer a local category using on-device text-matching rules; this classification does not use the remote AI provider.
| Purpose | Data Used |
|---|---|
| Creating and editing notes | Audio recordings, transcripts, note content, photos, URLs |
| AI features | Selected plain text from a note, transcript, extracted web page, or generated summary; image features may additionally use compressed images and limited local OCR text |
| AI Chat | Bounded note content, your question, and a limited recent chat history |
| Web note creation | The URL is fetched directly from the website on your device; extracted page text is stored in the local note and may later be sent for remote summarization |
| Subscription management and validation | App Account Token and transaction JWS data |
| Device security and API rate limiting | App Attest key ID and client instance ID |
| Service quality and debugging | Minimized or operational AI API usage logs |
Your main note library, including notes, audio recordings, photos, and transcripts, is stored on your device by default. Notes, folders, tags, and action items are stored in SwiftData. Audio files are stored under Documents/Recordings/ and photos under Documents/Images/.
Sunote does not provide CloudKit, iCloud, or other Sunote-managed cross-device note synchronization. Limited data may still be sent to third-party services when needed for AI features, speech recognition, subscription validation, web page retrieval, security checks, and rate limiting.
Because the library is local-first, deleting the App, losing or resetting the device, clearing local App data, or local storage corruption may make notes, recordings, photos, transcripts, and AI outputs unavailable. Apple controls the behavior of iCloud device backups and restores. Sunote does not provide its own cloud backup, cross-device sync, or recovery service and does not guarantee that locally unavailable data can be restored. Before deleting the App or changing devices, create your own copy using the export or sharing options available in the App.
When you choose a remote AI feature, the content needed for that feature is sent through this production route:
iPhone (local note data) -> Sunote Cloudflare Worker -> OpenRouter -> Google Gemini 2.5 Flash Lite
| Provider | Data Shared | Purpose | Policy |
|---|---|---|---|
| OpenRouter | Feature-specific plain text, selected transcripts, extracted web-page text, limited chat context, AI questions, and compressed images for image AI | Routes requested AI processing to Google Gemini 2.5 Flash Lite | OpenRouter Privacy and OpenRouter Data-Collection Policy |
| Google Gemini 2.5 Flash Lite | The feature-specific payload routed by OpenRouter | AI summaries, action items, quizzes, flashcards, mind maps, image analysis, and note chat | Google Gemini API Terms and Google Privacy |
| Cloudflare Worker infrastructure | Remote AI request payloads, App Attest/security data, request metadata, and subscription/service-operation data | Sunote proxy, queueing, polling, rate limiting, security, and subscription validation | Cloudflare Privacy |
| Apple Speech framework / Speech Recognition | Audio or speech data when recognition is not completed on-device | Speech-to-text. Sunote prefers on-device recognition when supported and enabled; Apple services may be used when on-device recognition is unavailable or not selected | Apple Privacy |
| Apple StoreKit / App Store | Subscription transaction and purchase information | Subscription purchase, management, and validation | Apple Privacy |
| Website operators | The URL request and normal network/request data when you ask the App to fetch a web page | Returning the web page requested by you | The website operator's own policy |
| YouTube embedded player | Video ID from an existing locally stored legacy note | Displaying the original video for legacy notes only; Sunote cannot create new YouTube notes or retrieve transcripts | Google Privacy |
Sunote does not require a name, email address, phone number, password, precise location, contacts, or health-data profile. Apple handles payment-card information for App Store purchases, and Sunote does not receive your card number. However, any of these types of information may appear in note text, transcripts, audio, photos, web content, or chat messages that you choose to process.
We may disclose data to competent authorities only when required by law, court order, or valid legal process.
Onboarding does not grant AI processing permission. Immediately before the first remote AI request, Sunote shows a feature-specific consent sheet that names the data sent, Sunote's Cloudflare Worker, OpenRouter, and Google Gemini 2.5 Flash Lite, and explains the purpose of the transfer. Sunote asks for your explicit permission before enabling that AI request.
If you choose Not Now, the note or transcript remains saved and editable, no AI network request is sent, and the sheet appears again when you explicitly select an AI feature. You can change permission for future AI processing in Settings → Privacy → AI Data Sharing. Withdrawal applies to future requests and does not automatically erase content already processed by a provider.
If an audio recording, meeting, or note contains another person's voice or personal data, you are responsible for obtaining any permissions required by applicable law.
If the GDPR applies to you, you may have rights of access, rectification, erasure, restriction, portability, and objection. Because Sunote does not use a traditional account system and your main note library is stored on your device, you can delete individual notes and use the App's available sharing/export options. Sunote does not provide an automated server-side account-deletion or full-library export endpoint. For pseudonymous backend records, contact us; requests are manually assessed and records may be retained where required or technically necessary for security, subscriptions, accounting, or legal obligations.
California residents may have rights to know, access, and delete personal data, and to be free from discrimination for exercising privacy rights. We do not sell your data.
Under Turkish Personal Data Protection Law No. 6698 (KVKK), the data controller is Ufuk Özen. Processing purposes are described in this Policy, and rights under KVKK Article 11 remain available.
You must use the App in compliance with local laws, registration requirements, licensing rules, data transfer rules, consumer protection rules, and content rules that apply where you are located. Sunote may restrict access where legal, technical, or platform requirements prevent a feature from being provided.
For privacy requests, contact info@ufukozen.com. We aim to respond within 30 days, subject to applicable law and verification requirements.
Sunote is not directed to children under 4. We do not knowingly collect personal data from children under 4.
| Measure | Description |
|---|---|
| App Attest | AI API requests are validated using Apple's hardware-backed attestation system. |
| HTTPS (TLS) | Network communication is encrypted. |
| Challenge-Response | An attestation challenge is used before AI requests. |
| Rate Limiting | Multiple rate-limiting rules help prevent abuse. |
| Idempotency | Request key hashing helps prevent duplicate request execution. |
| Data Minimization | Only the data needed for a feature is collected or transmitted. |
| Local Storage | The main note library is stored on-device rather than in Sunote cloud storage. |
No security measure is perfect, but we design the service to reduce unnecessary data exposure.
The Sunote app does not use cookies and does not include tracking or analytics SDKs. In-app behavior is not used for advertising tracking or profiling.
If we identify a security incident that affects your personal data, we will notify competent authorities and affected users within the period required by applicable law.
For AI processing and related service operations, your data may be transferred to the United States and other countries where Cloudflare, OpenRouter, Google, Apple, or a website operator processes requests. The repository does not guarantee a particular regional processing location. The applicable transfer mechanism depends on the provider relationship, jurisdiction, and applicable law; we will use legally required safeguards where applicable.
| Permission | Purpose |
|---|---|
| Microphone | Recording audio to create notes. |
| Speech Recognition | Converting audio recordings to text through Apple's native Speech framework. |
| Camera | Capturing images that may be used for AI-assisted notes. |
| Reminders | Exporting action items to Apple Reminders. |
We may update this Privacy Policy from time to time. Updates will be published on our website and may be announced in the App. For material changes, we will provide an in-app notice where appropriate.
Important: The current production configuration routes selected user content through OpenRouter to Google Gemini 2.5 Flash Lite via the Sunote Cloudflare Worker to generate summaries, quizzes, flashcards, action items, mind maps, image analysis, and chat responses. AI-generated content may be inaccurate, is not professional advice, and should be reviewed before you rely on it.
AI features run only after you grant permission. The current App does not send raw audio files to OpenRouter or Google Gemini for note summarization. Data handling by OpenRouter and Google Gemini is subject to their applicable terms and privacy policies.
| Contact Method | Details |
|---|---|
| info@ufukozen.com | |
| Developer | Ufuk Özen |
| App Name | Sunote |
The following is a conservative summary for App Store Connect privacy responses. Data is not used for tracking or advertising.
| Data Category | Collected? | Linked to User? | Purpose |
|---|---|---|---|
| Audio Data | Yes | Yes | App Functionality |
| User Content | Yes | Yes | App Functionality |
| Identifiers | Yes | Yes | Security, Subscription Management |
| Purchase History | Yes | Yes | Subscription Management |
| Usage Data (AI operation metadata) | Yes | Yes | Service Quality, Rate Limiting, Security, Billing |
| Diagnostics | Yes | Yes | Debugging, Security |
| Photos/Videos | Yes | Yes | App Functionality |