Notiverse العربية

Notiverse Privacy Policy

Last updated:

Notiverse (“the app”, “we”) is a notes, tasks and files workspace published by Yasir Hamdan Alghamdi, trading as Yasir Dev Studio, Riyadh, Saudi Arabia. Yasir Dev Studio is the data controller. This policy explains exactly what the app collects, where it is stored, who it is shared with, and how to delete it.

The short version. Your notes belong to you. They are stored on your device, and — only if you turn on cloud sync — on cloud infrastructure located in Saudi Arabia and in other countries, including in Europe. Your account record is always in the cloud, because an account is what signs you in. If you use live collaboration, that session — the people present, their cursors, and the text of the note being edited together — is carried outside the region for as long as it lasts. We do not sell your data, we do not use it for advertising, and we do not show ads. AI features send only the text or media you explicitly submit, and only when you use them.

1. Data we collect

CategoryWhat it isWhy
AccountEmail address, display name, profile photo, and the sign-in provider you chose (email/password, Google, or Apple). Held by our authentication provider.To create your account and sync it across devices.
Your contentNotes, tasks, reminders, tags, folders, drawings, PDFs and their annotations, images, video and audio recordings you add. This is the product. Stored locally always; in the cloud only with sync on.
Registered devicesA standing list of the devices signed in to your account — a per-install identifier, device name and model, operating system and app version, when the device claimed a sync slot, and when it was last active. To enforce the device limit on your plan, and to let you see and remove your own devices in Settings → Devices. A device you stop using releases its slot after 30 days.
Push notification tokenA push messaging token issued per device by the platform's notification service. To deliver reminders, and to tell your other devices that something changed so they can sync. It is deleted when you sign out on that device.
PurchasesSubscription status (Free / Pro / Ultra), AI credit balance and purchase history. Handled by the app store you bought from and by our subscription management provider. To unlock what you paid for. We never see your card details.
DiagnosticsCrash reports and stack traces; basic usage events and your plan tier. To find and fix crashes and understand which features are used.
Device & technicalDevice model, OS version, app version, language, an app-instance identifier, and IP address as seen by our servers. Compatibility, abuse prevention and app integrity attestation.
Support correspondenceThe emails you send us, your address, and our replies.To answer you, and to keep a record of what was asked and decided. Kept for 24 months, then deleted.

We do not collect an advertising identifier. The app ships no ad SDK, serves no ads, and the Advertising ID permission is explicitly removed from the Android build.

2. Device permissions

Each is requested only when you first use the feature that needs it, and each can be refused — the app stays usable without any of them.

3. Where your data is stored

Your data is processed and stored on infrastructure located in Saudi Arabia and in other countries, including in Europe. We select regions for reliability and performance and may change them; the safeguards described in section 4, Crossing a border, apply wherever your data is processed.

Broadly: your notes, tasks and their metadata, the files you upload, and the backend processing that serves them are hosted in the Gulf region. Live collaboration — presence, cursors, and the note content being edited during a session — is carried on infrastructure in Europe for the life of the session. Section 4 sets out every case in which data leaves the region, and the legal basis for it.

An account is required on every plan, including Free — so your account record (section 1, first row) always exists in the cloud. Your content is a separate matter: notes, files and everything else you create stay on your device and are never uploaded unless you turn cloud sync on.

4. Crossing a border

Four things leave the Gulf region, and only these four:

How these transfers are lawful.
  • Saudi Arabia. Transfers outside the Kingdom are made under Article 29 of the Personal Data Protection Law, which permits a transfer that is necessary to perform a contract to which you are a party, or to which you have consented, provided it does not prejudice national security or Saudi Arabia's vital interests, and provided the level of protection is adequate. We limit each transfer to what the feature actually needs.
  • EU and UK. Transfers rely on the Standard Contractual Clauses incorporated into the data processing terms we accept from each provider we use, together with the safeguards those terms require.
You can ask us for more detail about any specific transfer at privacy@notiverse.net.

5. Why we are allowed to use your data

Under the GDPR every use of personal data needs a legal basis. Under the Saudi PDPL the equivalent grounds apply. Here is ours, feature by feature:

BasisWhat it covers
Contract
GDPR Art. 6(1)(b)
Creating and running your account · cloud sync of your notes and files · sharing a note with people you invite · subscriptions, AI credit balances and purchase restoration · sending you service messages.
Consent
GDPR Art. 6(1)(a)
Reading your location for a location block · sending your text, images or audio to an AI provider · camera, microphone and notification permissions. Each is off until you turn it on, and each can be turned back off. Live collaboration is not listed here: it is part of sharing a note, which runs on the contract basis above, and the transfer it involves is described in section 4.
Legitimate interests
GDPR Art. 6(1)(f)
Preventing abuse, fraud and quota circumvention · app integrity attestation · crash diagnostics · keeping the service secure and working. We have weighed these against your interests and use the least data that does the job.
Legal obligation
GDPR Art. 6(1)(c)
Keeping purchase and tax records, and responding to lawful requests.

You can withdraw consent at any time — turn the feature off in the app, or revoke the permission in your device settings. Withdrawing consent stops the processing from that point on; it does not undo what was lawfully done before, and it does not affect anything resting on a different basis. Nothing you refuse locks you out of the app.

6. AI features

AI features are optional and run only when you invoke them. When you do, the specific text, image or audio for that request is sent to the relevant provider through our servers. The features that do this are summaries, grammar and structure help, Ask Notiverse, text extraction from images, text-to-speech, audio transcription and dictation.

Our AI providers are in the United States and Europe, so using an AI feature transfers that request outside your region. We send only what the request needs — never your whole notebook, and never your account credentials. We use paid API tiers whose terms do not permit the provider to train models on the inputs we send. If you never use an AI feature, nothing is ever sent to them.

No automated decisions are made about you. AI features generate text, audio and suggestions for you to read and act on. They do not make decisions that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 of the GDPR. Nothing in the app profiles you or scores you.

7. Who else receives data

We share data only with processors that run the service. We do not sell data, and we do not share it for advertising.

CategoryWhat they receive
Cloud infrastructure and hostingAccount data, and your content only if you enable cloud backup or sync
Subscription and purchase managementAccount identifier, purchase and entitlement events
Crash and performance diagnosticsDevice and error data
AI processingOnly the specific content you submit to an AI feature, at the moment you use it
App storesPurchase and refund records, under their own privacy policies. If you ask Apple for a refund: how much of that purchase you used, how long you have had your account, and your total purchases and refunds with us, so Apple can decide the request

We use paid API tiers whose terms do not permit the provider to train models on the inputs we send.

For the current list of named providers, email privacy@notiverse.net.

People you invite also see part of your account — see section 8. They are not a processor; they are people you chose.

We may also disclose data where we are legally required to, or to protect the rights and safety of our users.

8. Sharing a note — what the other members see

Inviting someone to a note reveals some of your identity to them. Exactly this much:

Invitations are sent by email address, so inviting someone confirms to the sender whether that address already has a Notiverse account. Nothing else about your account — your other notes, your plan, your devices — is ever visible to a collaborator.

9. This website

notiverse.net is a small static site served by our cloud hosting provider.

10. How long we keep it

Backups. Deletion removes your data from the live service immediately, and that is what you will see. Erasing it everywhere takes longer, because our infrastructure provider keeps internal backup snapshots that expire on their own cycle. There is a recovery window of up to 30 days, removal from active systems takes about two months, and our provider commits to completing deletion — backups included — within a maximum of about six months (180 days). Those copies are encrypted and access-controlled throughout. They are never used for anything: not searchable, not restorable to an individual account, and not looked at.

11. Deleting your account

You can delete your account and all associated data from inside the app (Settings → Account), or from the web at notiverse.net/delete-account. This permanently removes your notes, files, tasks and account record from our systems, subject to the backup window above. It cannot be undone, and it does not cancel a store subscription — cancel that separately in Google Play or the App Store.

12. Security

Traffic is encrypted with TLS in transit and encrypted at rest by our infrastructure provider. Access is enforced server-side by security rules and by verified sign-in — a client cannot grant itself access to another account's data. Encrypted backups use AES-256-GCM with a key derived from your passphrase; we cannot recover that passphrase, so if you lose it the backup cannot be opened. The optional app lock (PIN or biometric) is enforced on your device.

13. If there is a breach

If personal data is exposed, lost or accessed without authorisation, we will investigate immediately and contain it. Where the law requires it we will notify the Saudi Data & AI Authority (SDAIA), and any other competent supervisory authority, within the period that law sets — 72 hours under the GDPR. Where the breach is likely to cause you serious harm, we will tell you directly, and we will say plainly what happened, what was affected, and what you should do.

14. Children

Notiverse is not directed to children under 13 (or the equivalent minimum age where you live), and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

15. Your rights

Depending on where you live — including under Saudi Arabia's PDPL and the EU/UK GDPR — you may have the right to access, correct, export or erase your data, to object to or restrict processing, to withdraw consent, to data portability, and to complain to your data protection authority. In Saudi Arabia that authority is SDAIA; in the EU or UK it is your national one.

The app gives you export and deletion directly, with no need to ask. For anything else, write to privacy@notiverse.net and we will respond within the period the law requires — 30 days under the PDPL, one month under the GDPR. We may need to verify who you are first, and we will not charge you for a reasonable request.

Where a controller outside the EU or UK offers services to people inside it, the GDPR requires a representative there. We have not appointed one. Until we do, write to the address above — it reaches us directly, and we answer within the periods stated.

16. If you are in the United States

This section is for residents of California and of other US states with comparable privacy laws.

We do not sell your personal information, and we have not sold it in the past 12 months. We do not share it for cross-context behavioural advertising. We serve no advertising at all, we collect no advertising identifier, and we run no ad SDK — so there is nothing to sell and no one to share it with. We do not knowingly sell or share the personal information of anyone under 16.

Under the CCPA/CPRA you may request to know what we collect and why, to have it deleted, to correct it, and to receive a portable copy — and you may not be discriminated against for asking. The categories we collect, the purposes and the recipients are set out in sections 1, 5 and 7 above; we do not use or disclose sensitive personal information beyond what is needed to provide the service.

To exercise any of these rights, or to have an authorised agent do it for you, write to privacy@notiverse.net. You can also delete everything yourself, without asking, at notiverse.net/delete-account.

17. Changes

If this policy changes materially we will update the date above and notify you in the app before the change takes effect.

18. Contact

Yasir Hamdan Alghamdi, trading as Yasir Dev Studio, Riyadh, Saudi Arabia
Privacy questions, data rights requests and privacy complaints: privacy@notiverse.net
Everything else: support@notiverse.net