Privacy
Privacy Policy
Effective September 27, 2026 · 한국어 (the Korean version prevails if they differ)
CommonNote (the “Service”, operated by Jae Yoon Sung) processes personal data as described below, in line with Korea's Personal Information Protection Act and other applicable law. The Service shows no ads, uses no third-party analytics or trackers, and never sells personal data or shares it for advertising.
1. Purposes
- Accounts — confirming sign-ups (and approving them where enabled), identity checks, account recovery, sign-up result and security emails
- The Service — storing and syncing notes, attachments and messages; co-editing and authorship; notifications
- Paid plans — subscriptions, payment status, seats and storage, refunds and disputes
- Security — detecting unauthorised sign-ins, investigating attacks, letting you review and end device sessions
- Quality — diagnosing input lag and app errors (never for advertising or behavioural profiling)
2. Data we process
| Category | Data | How collected |
|---|---|---|
| Sign-up (required) | Username, password (stored only as a scrypt hash), email, accepted terms version and time | Sign-up form |
| Sign-up (optional) | Display name, sign-up note, language | Sign-up form, settings |
| Use of the Service | Note content, attachments (including photos, video and audio in video), messages and comments, edit history | Entered by you |
| Generated automatically | Session data (IP, browser/device, time), security history (sign-in attempts, password changes, IP, device), diagnostics (account ID, input-lag statistics, screen size, error type and code location) | While you use the Service |
| Notifications (optional) | Device push tokens, browser push subscriptions | When you enable notifications |
| Payments | Plan, payment provider, transaction/subscription IDs, status and renewal date, and the transaction record the provider sends (amounts, tax, currency, payment status, customer and address IDs) — we never receive card numbers or security codes, and we strip the card's last four digits, holder name and expiry the provider sends before storing | From the payment provider |
| Record sealing (optional) | Hash of a sealed record's content | When you seal a record |
The app never opens your contacts, microphone or camera on its own; it only touches the photos or video you pick. Location is used only if you turn on calendar weather (off by default). Your current location is rounded to two decimals, used only for the lookup, and not stored. If location permission is unavailable and you type a city instead, that city's name and coordinates are stored only in this browser for later lookups and are never sent to the CommonNote server; clearing the browser's site data deletes them.
3. Retention
- Account data — until you delete your account. Deletion immediately erases email, display name, passkeys, sessions, security history, notification settings and API tokens, and replaces the username with an unidentifiable value.
- Notes and attachments — until you delete them. Deleted notes stay in the trash for 30 days, then are permanently removed automatically. However, locked notes and notes whose attachments are still used by other notes or by retained version history are held back from automatic deletion in full, including their text and attachments, and stay in the trash. They are removed at the next cleanup once the references are gone; a locked note can be unlocked and removed with Delete forever or Empty trash. To have a held-back note removed, ask the privacy officer below.
- Sessions — removed on sign-out or when ended; otherwise they expire after 14 days unused or 30 days after creation and are cleaned daily.
- One-time tokens and failed sign-ins — deleted within 7 days and 24 hours of expiry respectively.
- Security history, notifications, and IP/device data on restore events — cleaned after 180 days.
- Diagnostics — kept in server logs for at most 90 days, then deleted automatically.
- Backups — database snapshots are kept all for 7 days, one per day to 30 days, then one per month, and snapshots older than 6 months are deleted. However, backup copies of attachments and some archives made with an earlier method are not yet deleted automatically, so data removed from the live database can stay longer in encrypted backups. To have attachments removed from backups too, ask the privacy officer below and we will delete those files from the backup copies.
- Transaction records — kept as required by Korean consumer-protection law (contract, withdrawal and payment records 5 years; complaint and dispute records 3 years), together with Paddle's and Apple's retention policies.
- Push tokens and subscriptions — removed when you turn off notifications, sign out, delete the account, or the provider reports them expired.
Records in a team workspace with other members belong to the organisation, so they remain with the team after you delete your account. Your account details such as email and display name are erased, but author, assignee and handoff marks stored inside the retained notes may still show your original username. The deletion screen shows what will be removed and what stays. To have your username or the records themselves removed from the team, contact the privacy officer below.
4. How we delete
When retention ends or the purpose is achieved, data is deleted without delay: records are deleted from the live database and attachment files from storage (remnants left inside the database file are overwritten by later writes), database backups are deleted snapshot by snapshot on the schedule above, and attachment backup copies are deleted on request (automatic cleanup is in preparation). We keep no paper copies. Data that law requires us to keep is stored separately for that period only.
5. Disclosure to third parties
We do not provide personal data to third parties except with your consent or where the law requires. When you start a paid subscription, the following is provided to the party that sells and processes it:
| Recipient | Purpose | Data | Retention |
|---|---|---|---|
| Paddle (depending on your location: Paddle.com Inc. in the US, Paddle.com (Canada) Ltd. in Canada, Paddle.com Market Ltd elsewhere) — merchant of record for web payments | Payment, tax invoices, refunds and disputes | Email, plan, transaction/subscription IDs, payment status | Per Paddle's privacy policy and law |
| Apple Inc. (US) — App Store payments | In-app subscriptions and restoring purchases | A random account token linking the purchase to your account | Per Apple's privacy policy |
You enter card details directly in Paddle's or Apple's checkout; CommonNote never receives them.
6. Processors
| Processor | Task |
|---|---|
| Oracle Corporation (Oracle Cloud Infrastructure) | Hosting the servers, database and attachment storage |
| Resend, Inc. | Sending confirmation, approval, recovery and security emails |
| Google LLC (Google Drive) | Storing encrypted disaster-recovery backups — encrypted on our server first, so Google cannot read them |
| Apple Inc. (Apple Push Notification service) | Delivering iPhone and Mac app notifications |
| Browser Web Push providers (Google, Mozilla, Apple, chosen by your browser) | Delivering encrypted web notifications |
7. International transfers
Our server is in Japan and some processors are foreign companies, so personal data is transferred abroad as follows (Article 28-8 of the Personal Information Protection Act). All transfers use encrypted HTTPS connections.
| Recipient (contact) | Country | Data | When / how | Purpose | Retention |
|---|---|---|---|---|---|
| Oracle Corporation (oracle.com/legal/privacy) | Japan (Osaka region) | Everything in section 2 | Continuously while you use the Service | Running the Service | Section 3 |
| Resend, Inc. (resend.com/legal/privacy-policy) | US (delivered via Tokyo, Japan) | Email address, message body | Each email sent | Email delivery | Per Resend's policy |
| Google LLC (policies.google.com/privacy) | US and others | Encrypted copy of database and attachments | Automatically every 6 hours | Disaster-recovery backup | Backup retention in section 3 |
| Paddle — contracting entity by buyer location (paddle.com/legal/privacy) | US, Canada, UK | Email, plan, transaction/subscription IDs | At checkout and billing management | Payments | Per Paddle's policy and law |
| Apple Inc. (apple.com/legal/privacy) | US | Push token and notification text, purchase link token | When sending notifications or purchasing | Notifications, App Store payments | Per Apple's policy |
| Web Push providers | US and others | Push endpoint, encrypted notification | When sending web notifications | Web notifications | Per the provider's policy |
How to refuse, and the consequence — hosting in Japan is essential to the Service, so refusing means not signing up or deleting your account. Turn off notifications to avoid Apple/Web Push transfers; without a paid plan nothing goes to Paddle or Apple payments; without a recovery email you cannot receive recovery emails.
8. Feature services
These receive only the values a feature needs, without account details, and only when you use the feature.
- PubChem (US NIH) — a reagent name or CAS number when you look up a reagent. Results are cached on our server.
- Open-Meteo — latitude and longitude when calendar weather is on (and the city name, if you typed one). Your browser calls Open-Meteo directly, so Open-Meteo receives your device's IP address; no username or account is sent.
- ntfy.sh — notification text, only if you entered an ntfy topic in settings. Anyone who knows a topic name can subscribe, so use a long random one.
9. Your rights
You may at any time request access to, correction or deletion of, suspension of processing of, or withdrawal of consent for your personal data.
- In the app — change display name and email (Account), review and end devices (Security), export notes or everything, turn off notifications, delete the account (bottom of Account).
- By email — k2dydwl@gmail.com. After verifying your identity we act within 10 days and tell you the result.
- Representatives — a legal representative or someone you authorise may request on your behalf with a power of attorney.
Data other laws require us to keep may be held separately for that period, and suspension requests may be refused where needed to meet legal obligations; we will tell you why.
10. Security measures
- Administrative — access to personal data is limited to the operator; server access requires a private key.
- Technical — scrypt password hashing, hashed sessions and tokens, HTTPS with HSTS, Content Security Policy and cross-site request blocking, sign-in rate limits, backups encrypted before transfer, security history (access logs) kept 180 days.
- Physical — servers and storage are in Oracle Cloud data centres, whose physical access Oracle controls.
11. Cookies and browser storage
We use only the cookies needed to keep you signed in. There are no advertising or analytics cookies.
| Name / type | Purpose | Lifetime |
|---|---|---|
cn_session (HttpOnly, Secure cookie) | Keeps you signed in | Up to 30 days or until sign-out |
cn_unlock_session (Secure, SameSite=Lax cookie read by page scripts) | A random per-window value used to load attachments of a note unlocked in that window; contains no sign-in credentials | Deleted when the browser closes (session cookie) |
| Browser storage — IndexedDB and caches | Offline copies of opened notes, response cache | Cleared on sign-out |
| Browser storage — localStorage | Display and view settings, weather location and other settings for this device | Stays in this browser after sign-out — remove it by clearing site data in the browser |
You can block cookies in your browser settings, but you will not be able to sign in.
12. Children
The Service is for research and work, is not directed to children under 14, and does not knowingly collect their data.
13. Privacy officer
- Name
- Jae Yoon Sung
- Role
- Operator (privacy officer and complaints)
- Contact
- k2dydwl@gmail.com
14. Remedies
For dispute resolution or advice about a privacy infringement you may contact the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the KISA Privacy Infringement Report Center (118, privacy.kisa.or.kr), the Supreme Prosecutors' Office (1301) or the Korean National Police Agency cyber bureau (182). Residents elsewhere may also contact their local data protection authority.
15. Changes
We announce changes on this page and in News 7 days before they take effect (30 days for changes that materially affect your rights), and by email where needed.
- Effective September 27, 2026 — added international transfers, processors, disclosures, privacy officer, rights, security measures, cookies and remedies; set a 90-day limit for diagnostic logs
- September 16, 2026 — previous version