Privacy policy
Effective date: 26 August 2026
What we hold, and where it is kept
The short version. Recall Note runs in your browser, and keeps a copy of your collection on our servers so that you find it again on another device and so that the features that run on our side can work on it. An account signs you in. We sell nothing to anyone, we show no advertising, we run no analytics, and we never train anything on your data. When you use a feature that relies on a language model or on speech recognition, the passages or the audio that request needs are sent to the provider named in section 6, for that request only; nothing is sent otherwise.
1. Who is responsible
The controller of your personal data is [À COMPLÉTER : éditeur : nom et forme juridique], [À COMPLÉTER : adresse]. For anything concerning your data, write to recallnote@proton.me.
This policy covers the Recall Note website and the Recall Note application. It does not cover the sites of the companies listed in section 6, each of which has its own policy.
2. What runs on your device, and what runs on our side
The application is built to work in your browser first. What follows happens on your own machine, with the network switched off if need be:
- opening a PDF and displaying its pages;
- extracting its text, so a highlight can be anchored to the exact passage;
- highlighting, and turning a passage into a card;
- reading the labels drawn inside a captured figure: the character recognition runs in your browser, from files this site serves itself. No pixel of your figures is sent anywhere;
- scheduling your reviews;
- exporting everything to a standard
.apkgfile.
Your collection lives in your browser's own storage, and your preferences (theme, language, chosen accent) in a handful of local keys. What each one holds is listed in the cookie and storage policy.
Three things run on our side, and they are the only ones. A copy of your collection is synchronised to our servers as you work, so that you find it again on another device and so that a journal you share can be read by the people you share it with. The files you import and the lectures you record are stored in our object storage. And the features that need a language model (the tutor, the generators, the formatting and the correction of a recorded lecture) or speech recognition (the transcription of a lecture you record) go through our server, which forwards to the providers named in section 6 only what that request needs.
3. What an account is, and the little it holds
An account signs you in, and carries your collection. What follows is the complete list of what we hold about you.
What we hold about you
- Your email address, which identifies the account.
- Your password, never in clear. It is held as an irreversible hash by our authentication provider; we cannot read it, and neither can anyone who obtains the database.
- A session token, stored by your browser so that you stay signed in.
- The date the account was created.
What is attached to the account, on our servers
Your collection as synchronised (journals, notes, cards, review history, the documents you import and their files, the journals you share and follow), your plan (free, Lecture or Lecture+) and, if you subscribe, the identifiers our payment provider gives us for your customer record and your subscription. Your card number never reaches us: it is typed into a form served by the payment provider (section 6). The .apkg export remains the way to carry your cards to another tool.
4. What we never do
- We never sell, rent or hand over your data to anyone for their own purposes.
- There is no advertising on this site or in the application, and no advertising identifier of any kind.
- There is no analytics and no tracker. No audience measurement script, no third-party pixel, no session recording: not on the marketing pages, not in the application.
- We do not profile you, and no decision about you is taken automatically.
- Nothing you write or import is sent to an AI model unless you ask for it. The tutor, the generators, the formatting and the correction of a recorded lecture send the passages that request needs to the language-model provider named in section 6, for that request only; recording a lecture sends its audio to the speech-recognition service named there. Nothing is sent otherwise.
- We do not read your documents. Access is restricted by the technical measures described in section 9, and we open a collection only if you ask us to in writing, for support.
- We never train anything on your data.
5. Why we hold it, and on what legal basis
- Running the service: the account that signs you in, under the contract between you and us (GDPR art. 6.1.b).
- Keeping the service standing: preventing abuse, and the technical logs that make a failure diagnosable. Our legitimate interest in a service that works, weighed against the small amount of data involved (art. 6.1.f).
- The feedback you send us from the application: your consent, given by the act of writing to us (art. 6.1.a).
6. Who else touches your data
We use four companies to run the service. They act on our instructions, under a contract, and may not use your data for their own purposes.
- Cloudflare: hosting of the site, of the application and of our server, object storage of the files you import and of the lectures you record, and speech recognition for recorded lectures (a Whisper model run by Cloudflare). [À COMPLÉTER : entité contractante et adresse ; localisation des données du stockage objet et des traitements, à relever dans les documents de Cloudflare]
- Supabase: accounts and the database. The email address, the password hash and the session described in section 3, and the synchronised copy of your collection. The project is hosted in the European Union, in the Paris region. [À COMPLÉTER : entité contractante et adresse]
- DeepSeek: the language model behind the tutor, the generators, the formatting and the correction of recorded lectures. It receives the passages a request needs, for that request only. [À COMPLÉTER : entité contractante, pays et adresse ; conditions du fournisseur sur la conservation et l'entraînement, à relever dans ses documents ; encadrement du transfert hors Union européenne]
- Stripe: payments. The card details you type go to Stripe and never to us; we receive the identifiers of your customer record and of your subscription, and the state of your plan. [À COMPLÉTER : entité contractante et adresse]
Where it is stored. Your account and the synchronised copy of your collection live in the European Union, in the Paris region of our database provider. [À COMPLÉTER : localisation du stockage objet Cloudflare et des traitements du modèle de langage]
7. How long we keep it
- Your account: for as long as it exists.
- After you delete your account: it is removed with everything attached to it. Backups roll off after [À COMPLÉTER : délai de rotation des sauvegardes].
- Feedback you send us: [À COMPLÉTER : durée].
- Anything held only in your browser: until you clear your browser's data for this site. We cannot delete it for you, because we cannot see it.
8. Deleting everything
You can delete your account from the application's settings. It is a real deletion and not a flag: the account, the profile and the synchronised collection attached to it are removed from our database. [À COMPLÉTER : suppression des fichiers du stockage objet et du client chez le prestataire de paiement, à vérifier]
Your local collection lives on your device and stays readable there with the network switched off; a copy is also kept on our servers, so that you find it again on another device. Clearing your browser's data for this site removes it.
9. How it is protected
- Everything that travels (your collection, your files, the account requests) goes over an encrypted connection.
- Your collection is readable only by your account, and by the people you have chosen to share a journal with: the database enforces it row by row.
- Your password is held as an irreversible hash, never in clear.
No system is beyond reach. If you believe you have found a security flaw, write to recallnote@proton.me and we will answer.
10. The feedback button
When you send us feedback from inside the application, we receive your message, the name of the screen you were on, your email address if you chose to give one, and the identifier of your account if you were signed in. Nothing else travels with it: not your cards, not your documents.
11. Your rights
You may ask us for access to your data, for its correction, for its erasure, for a portable copy, for a restriction of a processing, or object to one carried out on the basis of our legitimate interest. Where a processing rests on your consent, you may withdraw it at any time, and that does not call into question what was done before.
Write to recallnote@proton.me. We answer within one month; if the request is complex we will tell you so within that month and take up to two more. Access to your own data costs nothing.
You may also lodge a complaint with a supervisory authority: in France, the CNIL, 3 place de Fontenoy, 75007 Paris.
Two of these rights are already in your hands without writing to anyone: portability, because you can export your whole collection to a standard .apkg file at any time, review history included; and erasure, through the deletion described in section 8.
12. Cookies
This site sets no cookie and loads nothing from a third party. The application stores what it needs to work offline and to keep you signed in, and none of it tracks you. What is stored, why, and for how long is set out in the cookie and storage policy.
13. Age
Recall Note is meant for students of 15 and over, which is the age from which French law lets someone consent on their own to the processing of their data. If you are under 15, a parent or guardian must agree on your behalf before you create an account. We do not knowingly hold data about younger children; if you believe we do, write to recallnote@proton.me and we will erase it.
14. Changes to this policy
If we change what we do with your data, we change this page and move the effective date at the top. A change that materially affects you will be announced in the application before it takes effect, not slipped in.
15. Getting in touch
For any question about this policy, or to exercise any of the rights in section 11: recallnote@proton.me.