Noteh - Notes & Checklists
Privacy Policy for Noteh - Notes & Checklists
Applies to the “Noteh - Notes & Checklists” app (“Noteh” or “the app”) for iOS and Android.
This is an English translation of the German policy, provided for convenience.
01
Overview
Noteh works without a user account and without registration, contains no advertising and no advertising or marketing trackers. Your notes and checklists are stored on your device; we operate no server of our own.
Data leave your device in these cases:
- Error reports to the Sentry service, switched on when you dismiss the welcome note, can be switched off in the settings (section 4).
- Synchronisation of your notes and checklists into your own Google Drive, only if you switch it on (section 5).
- Contact, store and rating at your initiative; besides that, crash reports that the operating system itself sends to the respective store (section 6).
A separate privacy policy applies to our website spryloop.com.
02
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
René FitzkeGrünauer Straße 129e12557 BerlinDeutschlandEmail: noteh.app@spryloop.com
03
Data on your device
The app stores your notes and checklists (titles, content, items, times) and your settings locally in the protected app storage that other apps cannot read. We have no access to them. Local storage is necessary to use the app (Art. 6 (1) (b) GDPR, § 25 (2) no. 2 of the German TDDDG). On Android the app needs only the internet permission.
The app is excluded from your device’s cloud backup (the Google cloud backup and the iCloud backup respectively); after a reinstall your notes and checklists are therefore only still there if you use synchronisation (section 5). Via the system settings (“Clear app data”, Android) or by deleting the app you remove all local data; data in your Google Drive are unaffected.
04
Error and crash reports (Sentry)
What happens. If the app crashes or a technical error occurs, it automatically sends a technical report to the Sentry service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA so that we can find and fix the error.
Your switch. Error reports are off until you switch them on: on a fresh installation, as soon as you dismiss the welcome note that points out the error reports; otherwise in the settings under “Send error reports”. There you can switch them off again at any time; after that the app sends no more reports.
Content of a report. Time, app version, device model and operating system, language, technical device state, the error message with program flow and a short chronicle of the last steps in the app in technical names; plus a random installation identifier without name or account details so that reports from the same device belong together, and your IP address during transmission. Reports are not designed to contain the content of your notes and checklists; the app removes content fields before sending. An unintended transmission of individual details inside an error message cannot be entirely ruled out, however.
Legal basis. Art. 6 (1) (f) GDPR; our legitimate interest is to detect technical errors and keep the app working and secure.
Sentry as processor. Sentry processes the reports on our behalf under a data processing agreement and stores them in its EU region (Germany) for at most 30 days. As Sentry is a US company, access from the USA cannot be ruled out; Sentry bases this on the EU-U.S. Data Privacy Framework and the EU Commission’s standard contractual clauses. Sentry’s privacy policy: https://sentry.io/privacy/. Transfer safeguards: https://sentry.io/legal/dpa/ (Schedule 3).
05
Synchronisation via Google Drive (optional)
Voluntary, off by default. The app can keep your notes and checklists in step across your own devices if you switch synchronisation on in the settings; from then on it runs automatically.
What is transferred. Your notes and checklists with full content, titles and times. Plus technical synchronisation data without name or account details. Synchronisation data are encrypted in transit using HTTPS.
Where the data sit. In a hidden app data area of your own Google Drive that, of your apps, only this app can read (“drive.appdata” permission); the app cannot see your other Drive files. We operate no server for this and have no access to the data.
Google as controller. Google is responsible for the storage in your Google account, in the EEA Google Ireland Limited, Dublin; the privacy policy of your Google account applies (https://policies.google.com/privacy). Google may also process the data outside the EEA, in particular in the USA.
Signing in to Google. When you sign in, Google also shows your basic account details (name, email address, profile picture). The app neither stores nor displays them; it keeps only a non-reversible checksum of your account identifier to detect an account change.
Legal basis. Your consent under Art. 6 (1) (a) GDPR, which you give by switching the feature on and withdraw at any time by switching synchronisation off. If you are under 16, please switch synchronisation on only with your parents’ consent.
Switching off and deleting. Switching off pauses the exchange on this device. “Delete cloud data” in the settings deletes the state from your Google Drive for all devices and revokes the app’s access to your Google account; your local notes and checklists are kept. You can also revoke access in the security settings of your Google account; you then delete the data in Drive yourself under “Settings” → “Manage apps” → “Options” → “Delete hidden app data”.
This app’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
06
Contact, store and rating
Email contact. The app can prepare an email to us and fills in the app name and version in the subject line; it is sent only by you. If you write to us, we process your message and sender address in order to answer it (Art. 6 (1) (b) or (f) GDPR). Our mailbox is operated in Germany by 1&1 Mail & Media GmbH, Montabaur (WEB.DE), which stores the messages as our processor. We delete the correspondence once the matter is resolved and no retention obligations stand in the way.
Google Play. When you download, update or rate the app, Google Play processes data under its own responsibility; Google’s privacy notices apply. Google Play also provides us with automatically generated crash reports and aggregated statistics without personal reference, which we evaluate to keep the app stable (Art. 6 (1) (f) GDPR).
App Store. When you download, update or rate the app, the App Store processes data under its own responsibility; Apple’s privacy notices apply. Automatically generated crash reports and aggregated statistics without personal reference are provided to us by Apple only if you have consented to sharing them with app development teams under “Analytics & Improvements” in your iOS settings; we evaluate them to keep the app stable (Art. 6 (1) (f) GDPR).
Rating. The app may occasionally ask whether you would like to rate it; the rating itself runs through the respective store’s dialog.
07
Your rights
You have the rights of access, rectification, erasure, restriction of processing and data portability (Art. 15 to 20 GDPR) and can withdraw consent at any time (Art. 7 (3) GDPR). Withdrawal does not affect the lawfulness of processing based on your consent before its withdrawal. An informal message to the address in section 2 is enough. We generally cannot attribute error reports to a person; we can fulfil access or erasure for them only if you provide details that enable attribution (Art. 11 GDPR).
Objection (Art. 21 GDPR). On grounds relating to your particular situation, you can object at any time to processing we base on Art. 6 (1) (f) GDPR, i.e. the error reports and the evaluation of store statistics. You stop the error reports yourself via the “Send error reports” switch; otherwise an informal message is enough. We will then stop processing the data unless compelling legitimate grounds prevail or the processing serves the establishment, exercise or defence of legal claims.
Complaint. Under Art. 77 GDPR you can lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, https://www.datenschutz-berlin.de.
Last updated: 19 September 2026