Last revised on May 25, 2018.
Your privacy is important to us. This policy sets out our privacy practices and explains how we handle the data we collect when you use Notejoy's sites, services, mobile apps, desktop apps, products, and content ("Notejoy Services").
What We May Collect and Why
We collect and store personal data about you in order to provide our collaborative notes service. We share minimal data with our service providers. We collect your data in order to:
- Provide, test, promote, and improve Notejoy Services
- Provide a customized product experience
- Gather usage statistics of Notejoy Services
- Fight spam, fraud, and other abuse of Notejoy Services
We may collect the following personal data about you:
Logged Out Users
- Website and session activity
- IP address
- Browser and referrer
Logged In Users
- Name and profile information
- Author image
- Email address (non-public)
- Session activity (security)
- IP address
- Browser and referrer
- Library, notebook, and note content created by user
- Usage data including note view history, note interactions (comments, reactions, stars)
- Billing information and history
In addition to this, when you create your Notejoy account, and authenticate via a third-party service, we may collect, store, and periodically update the contact lists associated with that third-party account, so you can connect with existing contacts from that service who are on Notejoy.
Notejoy Services offers collaboration features, which allow you to create and share content to those you have designated as having access to it. As a function of the collaborative nature of the Notejoy Services and based on the permissions and settings you choose, the use of such features enables the sharing of content with people you want to collaborate with or with the public. Due to this sharing, it may be possible for third parties with permission to access this content to derive identifying personal data from notes, whether by reading, inference, supplemental research, or automated extraction and analysis. Where such personal data may reveal special category protected data, it is processed on the basis that it is manifestly made available by the user. Notejoy allows you to control access to your content by modifying sharing settings. Users may also choose to use the service for individual usage without sharing their data with others. However, if you do not agree with and accept the risks of such usage, you may not use Notejoy Services.
We maintain two types of logs: server logs and event logs. By using Notejoy Services, you authorize Notejoy to transfer, store, and use your data in the United States and any other country where we operate.
Sometimes we'll send administrative emails about your account, service changes, or new policies. You can't opt out of these emails. We'll also send you non-administrative emails, including notifications, newsletters, and digests, which you can opt out of at any time.
We won't email you to ask for your password or other account information. If you do receive such an email, send it to us to investigate.
Disclosure of Your Data
As a rule, we don’t share your personal data outside the company. We won’t sell your personal data. We may share your personal data with third parties in limited circumstances, including: (1) with your consent; (2) to a vendor or partner who meets our data protection standards; or (3) when we have a good faith belief it is required by law, such as pursuant to a subpoena or other legal process.
If we’re going to share your data in response to legal process, we’ll give you advance notice so you can challenge it (for example by seeking court intervention), unless we’re prohibited from doing so by law or court order. We will object to requests for data about users of our site that we believe to be improper.
We share minimal personal data with third-party processors in order to provide Notejoy Services. These processors offer at least the same level of data protection as that set out in this statement. This includes the following categories of recipients:
- Hosting, Storage, & Other Infrastructure
- Communication & Support
- Payment Processors
Notejoy provides Notejoy Services in conjunction with Stripe as our payment processor. Companies acting as our payment processors may collect and store personal data related to your billing information and history in order to provide their services, and may collect and store personal data and business data to prevent fraud and other abuse.
Notejoy also leverages Google API Services to improve the overall Notejoy experience. You can login with your Google account, embed G Suite documents, spreadsheets, and slides into a note, and easily share notes with other G Suite domain users. To enable these integrations, Notejoy leverages Google APIs to let you login, discover other G Suite users, and find and embed Google Drive files. These are enabled with Google OAuth APIs, ensuring that Notejoy never has access to your Google credentials. Notejoy caches information about any embedded Google Drive files with a note, including document name, author, url, and last modified date. This information is deleted from Notejoy when you permanently delete the note containing the embedded document.
Some embeds may request your personal data, such as an email address, through a form. If you choose to submit your data to a third party this way, we don't know what they may do with it. So, please be careful when you see embedded forms on Notejoy asking for your email address or any other personal data. Make sure you understand who you are submitting your data to and what they say they plan to do with it. We suggest that you do not submit personal data to any third-party through an embedded form.
Data Retention & Your Account
Notejoy retains personal data associated with your account for the lifetime of your account. If you would like to delete your personal data, you can cancel your account at any time from your Account Settings with instructions available here. Canceled accounts will no longer be accessible for your login upon initiating deletion and your personal data will be removed within 30 days. If you cancel your account, your account and content may be unrecoverable. To protect data from accidental or malicious destruction, we may also retain cached or archived copies of data about you for a certain period of time. If you delete your account, your account and content may be unrecoverable. It may take several additional days for your personal data to be de-indexed from search engines, depending on those search engines’ practices, over which Notejoy may have limited or no control.
If your account is managed by a team admin, you will also need to contact the team admin in order to initiate account deletion of data shared in team libraries. We will retain personal data we process on behalf of our customers as directed by paying customers. Notejoy will retain this personal data as necessary to comply with legal obligations, resolve disputes, and enforce agreements.
To delete your payment or billing data, you will need to do so with your payment provider, as Notejoy only has minimal secure access to those records as needed to provide Notejoy Services.
For users who are inactive for extended periods of time, we may close your account to satisfy our obligations under applicable law, and in accordance with our data retention policy. If that happens, we will try to notify you before taking any action.
We use encryption (HTTPS/TLS) to protect data transmitted to and from our site. However, no data transmission over the Internet is 100% secure, so we can’t guarantee security. You use the Service at your own risk, and you’re responsible for taking reasonable measures to secure your account (like using a strong password).
Notejoy may periodically update this Policy. We’ll notify you about significant changes to it. The most current version of the policy will always be available here.
Additional Information for European Union Users
Where Notejoy collects and stores personal data about non-users, it does so under performance of contract obligations with users who use Notejoy Services to publish content hosted by Notejoy. In such cases, users authoring such content containing personal data of third parties are responsible for that content. Notejoy will consider related complaints in compliance with the General Data Protection Regulation’s rights of the data subject, as well as rights of expression and access to information.
Notejoy is hosted in the United States. By using Notejoy Services, you authorize Notejoy to transfer, store, and use your information in the United States and any other country where we operate. Where your data is disclosed to our processors, it is subject by contract to at least the same level of data protection as that set out in this statement.
- If you sign up for a Notejoy account, you may at any time request an export of your note data for download. Learn how to do this here.
- You may correct information associated with your account from Account Settings.
- You may withdraw consent by canceling your account at any time through the Account Settings page. Learn how to do this here.
- You may object at any time to the use of your personal data by contacting us. If your complaint relates to alleged misuse of your personal data by a third party, it may result in suspension of that post or account in keeping with relevant law, public interest, our contractual obligations, and the rights of expression and access to information of others.
- You may at any time lodge a complaint regarding the processing of your personal data by Notejoy with the Supervisory Authority of your EU member state.