Privacy Policy
MoNote · Last updated 22 September 2026 · Terms of Service
MoNote is a voice journal. You talk, it writes down what you said and files it so you can find it again. That means it handles some of the most personal things you have — including health information about you and about people you care for. This page says exactly what happens to it, who else sees it, and how to get rid of it.
The short version
- There is no account. No email, no name, no password. Your phone holds a random token and that is the whole of your identity to us.
- Your words are never rewritten, and the recording is kept so you can hear any note back in your own voice.
- Two companies process your recordings on our behalf — Deepgram turns speech into text, Anthropic turns text into notes. Both are in the United States. Neither may use your data to train models: every request to Deepgram carries the opt-out from its Model Improvement Program, and Anthropic's terms exclude training.
- Your data lives in Frankfurt, Germany.
- Deleting is real and immediate. One control in Settings erases the recordings, the notes and the account row. There is no soft delete and no backup we hold back.
- We do not sell your data, and there is no advertising inside your journal.
1. Who we are
MoNote is operated by Viacheslav Apasov Pr Racunarsko Programiranje Beograd, preduzetnik, registered in Serbia at Zivka Petrovica 52 (company number 66878112). We are the controller of the personal data described here.
Contact for anything on this page: privacy@monote.me.
2. What we handle, and why
| What | Why | Basis (EEA/UK) |
|---|---|---|
| Audio recordings you make | To transcribe them, and so you can play a note back in your own voice | Performance of a contract; explicit consent where the content is health data |
| Transcripts and notes — including what you say about symptoms, medication, appointments and the people in your life | To split, file and search your journal, and to answer questions about it | Performance of a contract; explicit consent for health data |
| A device token, your chosen language and time zone | To connect your phone to your journal and resolve "two in the morning" to the right hour | Performance of a contract |
| Usage records — counts and costs of transcription and processing, tied to your device token | To keep the service running and stop it being abused | Legitimate interests |
| Purchase status, if you subscribe | To know whether your subscription is active | Performance of a contract |
| Crash reports, if enabled | To find and fix crashes | Legitimate interests |
| Server logs, including IP address | Security and troubleshooting | Legitimate interests |
Health information, said plainly
Much of what people record here is health information — a temperature, a medication, what a doctor said, a blood pressure reading. In the EEA and UK that is a special category of personal data and in California it is sensitive personal information. We process it only to provide the journal to you, and only because you have chosen to record it. You can withdraw that consent at any time by deleting your data, which removes it in full.
You may also record things about other people — a child, a parent, a partner. That is what the app is for and we do not restrict it, but those people have rights over their information too. Record what you would be comfortable having recorded about you, and be aware that some countries limit what you may keep about another adult without telling them.
What we never do
- We do not sell or share your personal information, in any sense including the broad definitions used by California law.
- We do not use your recordings, transcripts or notes to train any model — ours or anyone else's.
- We do not show advertising inside your journal, and no advertiser receives anything you recorded.
- We do not read your journal. Staff access is limited to what is needed to fix a fault you have reported.
3. Who else sees it
These companies process data on our behalf, under contract, and may not use it for their own purposes:
| Who | What they receive | Where |
|---|---|---|
| Deepgram | Your audio recording, to transcribe it. Every request is sent with the opt-out from Deepgram's Model Improvement Program, so the audio is held only for as long as the request takes to process and is never used to train their models. | United States |
| Anthropic | Your transcript, and — when you ask a question — your notes. Not used for training; Anthropic deletes what it received within 30 days. | United States |
| DigitalOcean | Hosting; holds everything at rest | Frankfurt, Germany |
| Apple / Google | Subscription purchase and status. They never receive journal content. | United States and elsewhere |
| RevenueCat | Subscription status against your device token. No journal content. | United States |
| Sentry, if enabled | Crash diagnostics. Configured not to send personal data, and it never receives journal content. | Frankfurt, Germany |
| Google AdMob, if advertising is enabled in your version | A device advertising identifier, for non-personalised ads only. No journal content. | United States |
We use no third-party analytics product. There is no Google Analytics, no Firebase, no PostHog, no Amplitude and no advertising or attribution SDK of that kind anywhere in the app, and nothing about how you use MoNote is sent to another company.
What we do keep is a small record of what the app did — on our own server in Germany, beside the rest of your data. That a recording was started and how long it ran. That notes were kept, and how many. That a free-plan limit was reached. That the subscription screen was opened. That something was looked up again later.
It never contains anything you said. Not a recording, not a transcript, not a note, not a name, not what you typed into search. Each entry is one event name from a fixed list, plus a handful of numbers and short labels — the server refuses anything longer, so there is no field a sentence fits into. It is attached to your device token like everything else here, it leaves our server to nobody, and delete everything deletes it with the rest.
We keep it because there is otherwise no way to tell whether the app works: whether people can get a recording made at all, whether a limit is stopping them, whether anyone ever finds again what they wrote down. In the EEA and UK the lawful basis is our legitimate interest in knowing that the product functions, and you can object to it. If this ever grows beyond what is described here, this page will say so before it happens.
4. Leaving Europe
Your data is stored in Germany, but transcription and note-writing happen in the United States. Where we transfer personal data out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), together with the processors' own certifications and safeguards.
If you would rather your recordings never left Europe, MoNote is not currently able to offer that, and we would rather say so than bury it.
5. How long we keep things
| What | How long |
|---|---|
| Recordings, notes, subjects, categories | Until you delete them, or delete everything |
| Device record | Until you delete everything |
| Usage records | While your device exists; removed with it |
| What the app did (event records) | While your device exists; removed with it |
| Idempotency records | 7 days |
| Server access logs | Rolling, roughly 100 MB, typically days to weeks |
| Backups | 14 days, then destroyed |
| Copies at Deepgram (audio, during transcription) | The duration of the request only |
| Copies at Anthropic (transcript and notes) | Deleted within 30 days |
A recording lives exactly as long as the notes it backs. One recording usually produces several notes, so it is kept while any of them remains, and deleted — file and record together — when the last one goes. There is no fixed expiry: the recording is what makes "your words are never rewritten" something you can check rather than something we assert, and the moment you are most likely to want to check is months later rather than weeks. Deleting everything deletes every recording immediately.
6. Your rights
Wherever you live, you can see your data (it is all in the app), export it (Settings → Your words), and delete it (Settings → delete everything). Deletion is immediate and complete: recordings, notes and the device row all go, and the next backup cycle removes the rest.
Because there is no account, we cannot look you up. If you email us we may not be able to identify your data without information only your phone holds — which is a privacy feature, and a limitation.
If you are in the EEA or the UK
Under the GDPR and UK GDPR you have the right of access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time without affecting what happened before. You may complain to your national supervisory authority — in Germany, where the data is held, that is the BfDI; you may also complain to the authority where you live.
If you are in California
Under the CCPA/CPRA you have the right to know, delete, correct, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for anything beyond providing the service you asked for — so there is nothing to opt out of. We will not discriminate against you for exercising any right.
If you are in Brazil
Under the LGPD you have the rights of confirmation, access, correction, anonymisation or deletion, portability, and information about sharing. The mechanisms above apply, and you may contact us at the address in section 1.
Elsewhere
We apply the standard above to everyone. If your local law gives you more, it applies too, and you should contact us.
7. Children
MoNote is for adults and is not directed at children. We do not knowingly let under-16s create a journal.
Adults do use it to keep records about children, which is one of the things it is for. Those records are yours to keep and yours to delete, and they are covered by everything on this page.
8. Security
Everything travels over TLS. Your device token is stored only as a hash, so a copy of our database does not let anyone in. Access to the server is restricted to the operator, and tokens are stripped from logs. The backup copies that leave the server are encrypted with a key the server does not hold. No system is perfect, and we would rather say that than imply otherwise.
9. Changes
If this page changes in a way that affects you, we will say so in the app before it takes effect. The date at the top always reflects the current version.
10. Contact
privacy@monote.me — or by post at the address in section 1.