CuteNote Privacy Policy
Last updated: September 12, 2026
This Privacy Policy explains how CuteNote ("we," "us," or "our") handles personal information in connection with the website at cutenote.co and its related features (the "Service"). It covers visitors, account holders, and people whose information is included in material processed through the Service. Contact support@biostore.cc with privacy questions or requests.
This Policy accompanies our Terms of Service. It does not govern independent websites you link to, payment services you use directly, or recipients to whom you send an exported note.
1. Information we process
Information you provide
- Account information: your email address, account identifiers, authentication and verification records, and profile information supplied through a supported sign-in provider, such as a name or profile image.
- Source material: submitted URLs, pasted text, uploaded documents and images, audio and video, and recordings you choose to submit. These materials may contain your information or information about other people.
- Generated content and questions: extracted text, transcripts, notes, summaries, mind maps, questions submitted to note chat, generated answers, and related source and processing metadata.
- Billing information: customer and subscription identifiers, selected plans, transaction and invoice references, payment status, and usage allowances. Stripe processes subscription payments; we do not store full card numbers. Card details are handled by the payment processor.
- Support and feedback: messages, account details, attachments, and diagnostic information you provide when requesting help or reporting a problem.
Information collected through use
We process technical and activity information such as IP addresses in service logs, browser and device information, timestamps, visited pages, referral or campaign attribution, account or browser identifiers, feature interactions, generation status, processing duration, errors, and quota usage. These records help us operate the Service, understand how features are used, and investigate failures or abuse.
Information from other sources
We receive information from authentication providers when you sign in, from payment providers about transactions and subscriptions, and from source websites or processing providers when retrieving or transforming material you submit. A source URL can itself contain identifying or confidential information; review links before submitting them.
2. Why we use information
We use information to:
- Authenticate users, maintain sessions, secure accounts, and respond to account requests.
- Retrieve source material, transcribe recordings, parse documents, generate notes and answers, and provide storage, export, and sharing features.
- Process subscriptions, administer usage allowances, reconcile payments, and send necessary billing or account messages.
- Diagnose failed jobs, provide support, measure feature usage, and improve reliability and usability.
- Detect fraud, misuse, unauthorized access, and other security threats.
- Meet legal obligations, keep necessary business records, resolve disputes, and protect legitimate rights.
Where applicable data protection law requires a legal basis, we rely on performance of our agreement with you for requested services; legitimate interests in operating, securing, supporting, and improving the Service where those interests are not overridden by your rights; legal obligations for required records and disclosures; and consent where required, including for optional tracking or particular processing. You may withdraw consent where it is our legal basis without affecting prior lawful processing.
3. AI, transcription, and document processing
To deliver requested features, relevant source material, extracted text, images, transcripts, or questions may be sent to external AI, speech-to-text, or document-processing providers. For note chat, relevant note content and conversation context may be included with your question. Which provider processes a request depends on the feature and service configuration.
Private content still needs to be processed by the systems and providers delivering that feature. A private visibility setting limits public access to the note; it does not mean that processing takes place only on your device.
This Policy does not promise that every external provider has identical retention practices or a zero-retention arrangement. Contact us if you need information about the providers used for a particular feature, including their retention and model-training terms, before submitting material subject to special confidentiality requirements. Permission to process content for note generation does not by itself authorize unrelated use of your private content to train general-purpose models.
4. Public and private notes
Notes created from supported public links may be public by default. Public notes, including their titles, generated content, and source attribution, may be available to people without an account, appear in discovery pages, be indexed by search engines, and be shared or copied. Source material may contain personal information even when it is publicly accessible elsewhere.
Notes created from pasted text, uploads, and recordings are treated as private. Some link sources are also classified as private. Check the visibility associated with a note, and use available controls to make an eligible public note private. Avoid submitting confidential content through a public source workflow.
Changing visibility or deleting a note limits its availability through CuteNote but cannot recall copies held by other people, exports you have distributed, or third-party search caches. Exported files are subject to the privacy practices of the services and people you share them with.
5. When information is shared
We share information as needed in the following circumstances:
- Service providers: hosting and processing infrastructure, authentication, storage, transactional email, payments, product analytics, AI generation, transcription, and document extraction. These functions include services such as Vercel, Supabase, Stripe, Resend, and PostHog, together with the model and processing providers used for your request. Provider configurations may change as the Service develops.
- Your requested actions: retrieving a source from an external website, publishing a public note, following an external link, or using an export or integration. Source websites may receive ordinary request information when their content is fetched.
- Support and security: authorized personnel and providers may access information needed to investigate your support request, troubleshoot a failed job, or address abuse and security incidents.
- Legal requirements and protection: when reasonably necessary to comply with applicable law or valid legal process, investigate unlawful activity, or protect users and legitimate rights.
- Business changes: in connection with a merger, acquisition, financing, restructuring, or transfer of the business, subject to appropriate confidentiality and applicable legal requirements.
We do not sell personal information or share it with third parties for their cross-context behavioral advertising. Public availability resulting from note visibility is described separately above.
6. Cookies, browser storage, and analytics
We use cookies and similar browser storage to maintain sign-in sessions, remember preferences, cache account state, and support features. Local browser state may include account-related information, recent activity, or recording recovery data. Some of this information can remain on your device until it expires or is cleared.
We use product analytics, including PostHog, to understand visits, feature interactions, generation outcomes, reading activity, and subscription flows. Analytics can associate activity with a browser identifier or signed-in account; it is not necessarily anonymous. Referral and campaign information helps us understand how people reach CuteNote.
You can manage cookies and site storage through your browser. Restricting storage may affect sign-in, saved preferences, or recovery of unsent recordings. Browser storage controls do not delete server-side notes or account records. Where optional tracking requires consent, applicable consent requirements govern that processing.
7. Recordings and information about other people
When you use recording features, the Service processes audio from the microphone or other audio source you select and permit through your browser. Recording workflows may keep local audio or recovery information on your device. Audio you submit for transcription or note generation is uploaded for processing.
You control what you record and submit. Obtain any required participant consent and avoid recording or uploading information you are not authorized to share. If your personal information appears in another person's note or source material, you may contact us to request review, identifying the relevant CuteNote URL or material where possible.
8. Storage locations and international transfers
CuteNote uses infrastructure and service providers that may process information in the United States and other countries outside your place of residence. Those countries may have different privacy laws. Where applicable law requires safeguards for an international transfer, the transfer must be supported by an appropriate legal mechanism, such as an adequacy decision or approved contractual safeguards. Contact us for information relevant to your request.
9. Retention and deletion
We retain account information and saved notes to provide ongoing access while your account and content remain available. Canceling subscription renewal does not itself delete your notes. Retention is also subject to account deletion, content removal, enforcement of the Terms, and any notified service discontinuation.
Submitted files, extracted material, intermediate processing results, and diagnostic records may have different retention periods from saved notes. We retain them as needed to complete processing, support retries or requested features, troubleshoot failures, protect the Service, and meet applicable obligations. We do not promise one fixed deletion period for every type of data.
You can delete notes through available controls and initiate account deletion through the account flow or request assistance from support. Deleting a note should not be understood as immediately erasing every associated upload, processing record, or backup. Contact us for a broader deletion request. Account deletion requires ownership verification and removes account data and associated source files through the deletion process.
Limited records may remain where necessary for legal, tax, accounting, fraud-prevention, or dispute-resolution purposes. Backups and third-party records may be removed through their applicable retention processes rather than immediately. Information that has been irreversibly anonymized may be retained. Copies already obtained by other users or external services are outside our deletion controls.
10. Security
We use technical and organizational safeguards intended to reduce unauthorized access, alteration, disclosure, and loss, including access controls and authentication measures. No online service or storage method is completely secure, and we cannot guarantee absolute security.
Protect your sign-in email and credentials, review what you make public, and use care on shared devices. Report suspected unauthorized access or a privacy incident to support@biostore.cc. Do not include passwords, verification codes, or full payment-card details in a report.
11. Your choices and privacy rights
Depending on your location and applicable law, you may have rights to access or obtain a copy of your personal information, correct inaccuracies, request deletion, receive portable data, restrict or object to processing, and withdraw consent where processing relies on it. You may also have the right to appeal a decision on a request and complain to a competent data protection authority. We will not discriminate against you for exercising applicable privacy rights.
Use note deletion, export, visibility, and account controls where available, or email support@biostore.cc. Include your account email if applicable and a description of your request. We may need proportionate information to verify your identity or an authorized representative's authority before disclosing or changing data. We will respond within the period required by applicable law and explain any applicable limitation or refusal.
You can stop submitting new material and manage local cookies or storage in your browser. Service and billing messages necessary to administer your account may still be sent while you use the Service. If we send optional marketing emails, you can unsubscribe using the instructions in those messages or contact support.
12. Children's privacy
The Service is not intended for children under 13 or the higher minimum age required by local law. We do not knowingly collect personal information from children below that age. If you believe a child has provided such information, contact us so we can investigate and take appropriate deletion or access-restriction steps. Users below the age of legal adulthood must meet the parent or guardian requirements in the Terms of Service.
13. Updates and contact
We may update this Policy to reflect changes in the Service, processing practices, or legal requirements. We will update the date above and communicate material changes through the Service or appropriate account communications. If a change requires consent, we will obtain it before carrying out the relevant processing.
For privacy questions, requests, or concerns, contact CuteNote Support at support@biostore.cc. Include your account email if applicable and enough detail for us to locate the relevant records.