Privacy Policy

NO'TA Privacy Policy

This Privacy Policy explains how NOTA SOCIAL NETWORK PTY LTD, trading as NO'TA ("NO'TA", "we", "us", or "our"), collects, uses, discloses, stores, and otherwise processes personal information when you use the NO'TA mobile apps, app extensions, home-screen widgets, web surfaces, public pages, waitlist forms, support channels, age-assurance checks, opt-in AI feedback features, and related moderation or safety workflows (collectively, the "Services").

Last updated: 6 August 2026 Help Center privacy@no-ta.app
Key points.
  • NO'TA is a social platform. Some features are intentionally public, including public posts, comments, public-context conversations, place reviews, and any reflections or journeys you choose to make public.
  • NO'TA does not require a phone number for standard sign-up, but it does process account, profile, content, security, device, age-gate, and usage data to run the Services.
  • Where an age check is required, Didit provides the standard ID and liveness verification flow. A reasonable non-government-ID review can be requested. NO'TA retains only the minimum outcome and audit timestamps, does not publish the result, and schedules terminal vendor sessions for deletion.
  • If you enable real-name visibility or post with your real name, that information can become visible to other users on the relevant surfaces.
  • Private profiles, private reflections, and private journeys reduce visibility, but they do not mean NO'TA operators can never access information. Authorized moderators, support staff, and operators may access relevant data for safety, security, legal compliance, platform integrity, and operational support.
  • If you opt in to Monthly Insight or a similar AI feedback feature, NO'TA may analyze excerpts from your own No'tas, replies, and public-context messages, plus limited non-body context such as a parent title or topic, to generate a private summary for you. Other users' reply or message bodies are not sent to the AI provider for this feature. The summary is not shown on your profile and is not used for reputation or enforcement decisions.
  • If you delete your account, NO'TA uses a 30-day recovery window. Shared contributions may remain visible during and after that period. NO'TA hides the profile and immediately displays retained contributions under "User not available"; recovery restores current public snapshots, while permanent purge removes the original identity. Content you wrote or uploaded may still identify you from its substance.
  • NO'TA is still in a pre-launch or limited-release phase. Some features described here may be invite-gated, disabled, or available only in certain builds, regions, or test groups.
موجز عربي للتحديث.
  • تم تحديث هذه السياسة في 6 أغسطس 2026 لتوضيح التحقق من العمر عبر Didit، تقليل البيانات، حذف جلسات المزود النهائية، ومسار المراجعة الذي لا يتطلب هوية حكومية، إضافة إلى الميزات الموضحة سابقاً.
  • قد تخزن إضافة المشاركة وودجت الشاشة الرئيسية بيانات محدودة على جهازك، مثل جلسة لازمة للحفظ أو النشر من إضافة المشاركة، واسم المستخدم أو آخر موضوع لاختصارات الودجت.
  • بيانات الوصفات، المكونات، خطوات التحضير، واختيارات الصور الرمزية تعامل كجزء من بيانات المحتوى أو الملف الشخصي حسب السياق.
  • إذا اخترت تشغيل الملخص الشهري، قد تحلل NO'TA نقاطك وردودك ورسائلك في المحادثات ذات السياق العام، مع سياق محدود للردود، لإعداد ملاحظة خاصة لك فقط.
  • بعد حذف الحساب نهائياً، قد تبقى المساهمات المشتركة ظاهرة، لكن يُزال اسم المستخدم والاسم والصورة ورابط الملف الشخصي، ويظهر المؤلف باسم «المستخدم غير متاح». وقد يكشف نص المحتوى نفسه عن هويتك إذا ضمّنت فيه معلومات تعريفية.
  • هذا موجز عربي للتحديث وليس ترجمة قانونية كاملة. عند التعارض، يعتمد النص الإنجليزي ما لم يفرض القانون المحلي خلاف ذلك.

1. Scope and Applicability

This Privacy Policy applies to personal information processed through:

  • the NO'TA mobile applications, app extensions, widgets, and Flutter web surface;
  • the separate NO'TA web app and public pages under the NO'TA domain;
  • waitlist, invite, help, support, and account management flows;
  • notifications, moderation, safety, advertising, anti-abuse, and reputation systems; and
  • operator, support, and trust-and-safety workflows that relate to user accounts, reports, devices, or content.

This Policy does not apply to third-party websites, apps, communities, ad networks, app stores, or services that have their own privacy policies, even if they are linked from NO'TA or integrated into NO'TA.

2. Information We Collect

We collect information you provide directly, information collected automatically when you use the Services, information generated through social and moderation activity, and information received from service providers or third-party integrations.

Category Examples Relevant to NO'TA
Account and identifier data Email address, username, user ID, login credentials handled by Supabase Auth, Apple Sign-In or Google Sign-In identifiers, passkey credential metadata, two-factor authentication factor metadata, invite codes, waitlist email, support contact details, device ID, session identifiers, app-extension session metadata, push subscription identifiers, CAPTCHA verification signals, and app instance identifiers.
Profile and preference data Avatar, banner, bio, website, first and last name if you provide them, privacy settings, real-name visibility settings, preset-avatar selections, language preferences, nationality, residence, education, occupation, Arabic level, spoken languages, commercial or platform status, and date-of-birth components.
User-generated content Posts, comments, polls, fill-in-the-blank answers, community rules or edits, public-context conversations and conversation messages, quoted passages or media regions, reflections, journals, journeys, journey entries, library notes, place submissions, place reviews, offers, recipes, ingredients, recipe steps, food-item selections, shared links, uploaded images, uploaded videos, and support or safety messages you send to us.
Social graph and participation data Follows, blocks, bookmarks, library saves, votes, community memberships, report submissions, report outcomes, reputation score inputs, warnings, bans, shadowbans, conversation mute/archive states, moderation notes, and notification history.
Location and place data Precise device location if you grant permission and use a location feature, place names, Google Places IDs, addresses, latitude/longitude, approximate location inferred from login IP or request headers, and optional location/weather metadata added to reflections.
Device, log, and security data IP address, user-agent, platform, operating system, app version, crash reports, login event records, notification delivery and token data, connectivity state, underage signup attempt records, device blocklist signals, rate-limit counters, upload metadata, moderation quota signals, and security or abuse signals.
Usage and product telemetry App opens, session duration, views, searches, recipe and food-item searches, shares, widget actions, feature usage, onboarding progress, permissions granted, load time, profile views, announcement views, ad-consent or privacy-options status, and smart metrics used for reputation and product health.
AI feedback data If you opt in to Monthly Insight or a similar AI feedback feature, we process the relevant source items, source counts, opt-in state, summary status, generated private summary, model and prompt version, deletion state, and administrator preview audit metadata where a real-user preview is lawfully run for an opted-in account.
Local device storage Search history stored locally on your device, cached content, offline reflection and shared-link queues, language settings on web pages, theme and display preferences, iOS share extension session data stored in an operating-system app group, and lightweight share or home-screen widget context such as username, topic labels, or pending widget actions.
Advertising and commercial data Sponsored post interactions, ad request and response data, ad frequency state, offer interactions, consent status, and mobile advertising identifiers if advertising is enabled in your build or region.

2.1 Information you provide directly

  • Registration and account setup. When you create an account, we collect your email address, password, username, date of birth, invite metadata, and any optional first/last name or profile details you provide. If you use passkeys, two-factor authentication, Apple Sign-In, Google Sign-In, or similar sign-in options, we also process the authentication metadata needed to run those features.
  • Profile and identity choices. NO'TA lets you choose between username-based identity and, in some cases, real-name display. If you provide real-name data and enable those settings, we process those choices and display the information accordingly.
  • Content and communications. We collect the content, metadata, attachments, and context you choose to submit, including recipes, ingredient lists, preparation steps, drafts, or pending offline content saved locally until sync.
  • Waitlist, invite, and support flows. We collect the email address and any message or metadata you submit through waitlist forms, invite issuance flows, bug reports, safety reports, or support requests.

2.2 Information collected automatically

  • Security and login telemetry. When you log in, sign up, fail an age gate, pass a CAPTCHA, or trigger a rate limit, we may record your IP address, user-agent, app source, device and abuse signals, and approximate location derived from request headers or a geo-IP service.
  • App and product telemetry. NO'TA records app opens, session duration, search counts, view counts, shares, permissions granted, and other feature-use metrics.
  • Notifications. If you enable push notifications, we collect device token or push subscription data and delivery events.
  • Diagnostics. We use crash and diagnostics tooling to help us detect, investigate, and fix technical issues.
  • Media and upload metadata. When you upload images, videos, avatars, banners, or journey media, we process file metadata and delivery records needed to store, serve, moderate, and secure that media.
  • Browser and local storage. Our web surfaces may use cookies, local storage, session storage, or equivalent technologies for language preferences, session persistence, security, and similar purposes.

2.3 Information from third parties and other users

  • Authentication partners. If you sign in with Apple or Google, we receive the profile and authentication information made available by that provider.
  • Maps and place providers. If you use maps, nearby places, or place search features, we receive location and place data from Google Maps or Google Places services.
  • Translation providers. If you ask NO'TA to translate text, the text you selected for translation may be sent to DeepL or a replacement translation provider.
  • Safety, infrastructure, and CAPTCHA providers. We may receive or create security, moderation, media-delivery, CAPTCHA, and hosting signals through providers such as Cloudflare, OpenAI or other moderation providers, Supabase, and similar service providers.
  • Age-assurance provider. If an age check is required, Didit receives the information needed to run the configured check and returns a verification outcome to NO'TA.
  • Reports and moderation signals. Other users may report your content or account. Admins and moderators may create warnings, review notes, or enforcement records tied to your account.

2.4 Age assurance and Didit

NO'TA may apply age assurance when required by law, a country policy, a declared-age band, or a documented suspected-minor review. The decision to require a check is made by NO'TA's server-side policy. It is not based on an editable nationality or residence profile field.

The standard check is provided by Didit. NO'TA sends Didit an internal account identifier, workflow identifier, language, and technical request information. Depending on the configured method, Didit may collect and process a government-issued identity-document image, extracted document information including date of birth, a selfie or liveness capture, biometric-derived information, device and network data, fraud signals, and review information. Didit may use automated systems and authorized human review to produce the result.

NO'TA uses the result only to determine whether the applicable minimum-age requirement is met, administer a correction or review, prevent circumvention, and demonstrate compliance. NO'TA does not use age-assurance inputs or results for advertising, feed recommendations, reputation scoring, or unrelated profiling. Verification results are not public.

NO'TA stores only a minimal session status, threshold outcome, and audit timestamps. Detailed Didit decision payloads, identity-document details, exact DOB extracted by Didit, and biometric scores are not intentionally retained by NO'TA. After a terminal result, NO'TA instructs Didit to delete the vendor session and replaces the raw vendor session identifier with a one-way hash. A failed deletion is retried and recorded for operator action.

You do not have to use government-issued identification as your only option. You may request a reasonable non-ID review in the app. Access may remain limited while that request is assessed, and support may ask for a proportionate alternative age signal. You may use the same process to challenge an inaccurate outcome. Requests are decided by an authorized operator and recorded in an audit trail.

Didit acts as NO'TA's processor or service provider for the configured verification, but may act independently for limited security, legal, or service-integrity processing described in its notices. Review Didit's verification privacy notice and terms before starting. Contact privacy@no-ta.app for access, correction, deletion, objection, or complaint requests concerning a NO'TA age check.

Sensitive content warning. If you include sensitive personal data in content you publish or send through NO'TA, you direct us to process it. Public features are not suitable for confidential, regulated, or highly sensitive information.

3. How We Use Information

We use personal information to operate, secure, and improve NO'TA.

  • Create and manage accounts, authenticate users, recover accounts, and support sign-in, sign-out, and account deletion.
  • Display profiles, identity settings, public content, community participation, public-context conversations, reflections, journeys, reviews, and other user-selected surfaces.
  • Run core social features such as feeds, follows, blocks, bookmarks, voting, community membership, search, profile tabs, messaging, and directory experiences.
  • Calculate and display reputation signals using data such as posts, comments, votes received, blocks, reports, reviews, account age, and smart metrics.
  • Provide opt-in Monthly Insight or similar AI feedback features that generate private coaching-style summaries from your eligible NO'TA activity after a completed calendar month.
  • Detect spam, doxxing, contact-info sharing, abuse, fraud, ban evasion, underage signup attempts, device abuse, and other policy or security risks.
  • Apply proportionate age assurance, receive a minimum-age outcome, administer non-ID alternatives and reviews, prevent circumvention, and meet applicable online-safety obligations.
  • Review reports, run keyword and AI-assisted pre-publish moderation, investigate safety concerns, enforce platform rules, restore content when appropriate, and operate moderation, support, and trust-and-safety workflows.
  • Send in-app messages, public conversation notifications, follow alerts, push notifications, emails, reset flows, operational notices, and invite or waitlist communications.
  • Support translation, maps, place search, recipe and food catalogue features, media hosting, sharing flows, app extensions, widgets, offer features, crash recovery, analytics, and service performance.
  • Deliver sponsored content, advertising, or measurement features if enabled.
  • Comply with law, exercise legal rights, protect users, protect the Services, and respond to valid legal requests.
NO'TA uses automated and rule-based systems for things like feed ordering, reputation calculation, keyword and AI-assisted moderation filtering, contact-info blocking, spam protection, age-gate enforcement and age-assurance triage, CAPTCHA checks, rate limits, and abuse detection. These systems can affect visibility, ranking, warning, or access outcomes. Human review may also occur.

3.1 Opt-in Monthly Insight and AI feedback

Monthly Insight, also called Your Month in NOTA, is a private opt-in feedback feature. If you enable it, NO'TA may analyze your own No'tas, replies, and public-context messages for a completed calendar month and compare them with the previous month. For replies, limited non-body context such as a parent No'ta title or topic may be used so the system can understand what you replied to. The AI-provider payload excludes another person's reply or message body, including reply context excerpts. For public-context messages, the feature uses only messages you authored and coarse conversation metadata, not the other participant's messages.

The client app and admin web do not receive our AI provider keys. Generation happens in server-side infrastructure. To generate or preview a summary, selected excerpts from your own eligible activity, aggregate counts, and coarse metadata may be sent to OpenAI or a successor AI provider. Requests to OpenAI use the Responses API with provider-side application-state storage disabled. OpenAI may still retain limited abuse-monitoring logs for up to 30 days unless a different approved data control applies to NO'TA's project. We do not intentionally store raw prompts, raw source excerpts, or full message bodies in the Monthly Insight feedback tables. We store the generated summary, aggregate counts, status, model and prompt version, consent version, and deletion/audit metadata needed to operate the feature.

Monthly Insight is private coaching, not a score. It is not shown on your public profile, is not used to update reputation, and is not used by itself to make moderation, access, or enforcement decisions. You can opt out to stop future generation and can delete a visible monthly summary from Growth. Administrators can run a real-user preview only for an opted-in account, with a recorded reason, and the admin web receives only the generated summary and aggregate counts, not raw evidence.

4. When Information Becomes Public on NO'TA

Because NO'TA is a social product, some information is intended to be visible to other users or to the public internet. Please read this section carefully.

4.1 Public posts, comments, and community activity

Posts, comments, votes, profile activity, community participation, place reviews, and other public interactions may be visible to other users and, where public web surfaces exist, to search engines and people or automated systems that access those pages.

4.2 Public conversations are not private DMs

NO'TA's messaging feature is structured around public-context conversations. Public conversations and conversation messages are not end-to-end encrypted private messaging. Do not use them for confidential or high-risk communications.

4.3 Reflections and journeys

Reflections and journeys are private by default. If you change a reflection or journey to public visibility, or choose to show a public journey on your profile, it may become visible to other users on the relevant NO'TA surfaces. Public reflections are intended for profile display; private reflections and journals are treated as more sensitive.

4.4 Real-name settings and private-profile settings

If your profile is public and you choose to show your real name or post with your real name, your first and/or last name can become visible on your profile and public content. If your profile is private, NO'TA limits follow and messaging behavior and uses your username instead of your real name for relevant public surfaces. Switching to a private profile does not necessarily erase content you already shared publicly.

4.5 Public indexing, copying, and re-sharing

Content made public on NO'TA may be copied, screenshot, quoted, indexed, cached, scraped, translated, or re-shared by other users, search engines, and third parties. Even if you later edit or remove public content, copies may remain elsewhere.

5. How We Disclose Information

We may disclose personal information in the following ways:

  • To other users and the public when you choose to publish content, participate publicly, enable public profile features, or interact with public-context conversations, communities, or reviews.
  • To authorized moderators, support staff, and trust-and-safety operators for report review, enforcement, security, abuse prevention, incident response, operational support, and auditability.
  • To service providers and infrastructure partners that host, secure, analyze, translate, map, notify, moderate, scan, generate opt-in feedback, or otherwise support the Services, including providers such as Supabase, Cloudflare, Google, Apple, Firebase, OneSignal, DeepL, OpenAI or successor AI providers, Didit, AdMob/Google Mobile Ads, CAPTCHA providers, and hosting or CDN providers.
  • To advertisers and measurement partners if advertising, sponsored content, or measurement features are enabled for your experience and applicable law allows the disclosure.
  • For legal and safety reasons when required by law, subpoena, court order, or other valid process, or when we believe disclosure is necessary to protect users, the public, our rights, or the integrity of the Services.
  • In a business transaction such as a merger, financing, acquisition, reorganization, insolvency, or sale of some or all assets.
  • At your direction when you choose to use external integrations, share content, export data, or connect third-party services.

We do not sell personal information to data brokers for money. If NO'TA enables third-party advertising or cross-context advertising technologies in ways that are treated as a "sale", "sharing", or targeted advertising under certain laws, we will provide the notices and controls required by those laws.

6. Advertising, Analytics, Safety, and Measurement

  • Analytics and diagnostics. NO'TA uses analytics and diagnostics tools, including Firebase analytics/crash tooling and internal metrics, to understand usage, investigate issues, and improve stability and product quality.
  • Push notifications. NO'TA uses OneSignal and related notification tooling to deliver push notifications and record notification delivery events.
  • Maps and places. If you use place or map features, Google Maps or Google Places services may receive location, IP, or request information needed to fulfill your request.
  • Translation. If you request translation, the text being translated may be sent to DeepL or a successor provider.
  • Safety automation. NO'TA may use CAPTCHA, keyword filtering, AI-assisted moderation, media-delivery security, and abuse detection services to protect users and the platform.
  • Opt-in AI feedback. If you enable Monthly Insight or a similar feature, selected source excerpts, source counts, and metadata may be sent to OpenAI or a successor AI provider to generate a private summary and to run safety validation. Another user's reply or message body is not included in that provider payload. OpenAI Responses application-state storage is disabled for these requests, but limited abuse-monitoring logs may still be retained for up to 30 days unless a different approved provider control applies.
  • Advertising. If ads or sponsored content are enabled, NO'TA and its advertising partners, including Google Mobile Ads or a successor provider, may process device, app, approximate location, consent, and ad-interaction data to deliver, measure, and limit ads. On supported mobile platforms, advertising identifiers may be subject to operating-system permissions and settings, including App Tracking Transparency where required.

Where applicable law requires consent before non-essential cookies, mobile tracking, or advertising measurement, we will seek that consent or provide a legally required alternative control before carrying out the relevant processing. The in-app Data & Ad Privacy screen may also expose available mobile ads privacy options where the relevant SDK reports that those controls are required or available.

7. Cookies, Local Storage, and Device Storage

NO'TA's web and app surfaces use cookies, local storage, session storage, shared preferences, secure app storage, and similar technologies for authentication, language selection, settings, security, caching, offline support, and performance.

  • Our landing pages currently store language preferences in browser local storage.
  • The NO'TA web app may store auth/session state using Supabase browser storage behavior.
  • The mobile apps may store settings, cached content, local search history, and pending content on the device.
  • The iOS share extension flow may store auth session data in an app group so shared links can be handed off to the app securely.
  • Native share extensions and home-screen widgets may store lightweight local context, such as your username, last selected topic labels, a pending widget action, or share-intake metadata, so those operating-system surfaces can save, post, or route back into NO'TA.

You can manage or delete some of these technologies through your browser settings, device settings, in-app settings, or by uninstalling the app. Doing so may disable important features.

NO'TA does not currently respond uniformly to every browser "Do Not Track" signal. Where we are legally required to recognize browser-based opt-out preference signals, such as Global Privacy Control, we will do so to the extent the relevant web surface and applicable processing support it.

8. Legal Bases for Processing

If you are in the EEA, UK, Switzerland, or another jurisdiction that requires a legal basis, NO'TA generally relies on the following:

  • Performance of a contract. To provide accounts, communities, public content, moderation, profile settings, search, messaging, authentication, recipes, widgets, app extensions, and requested features.
  • Legitimate interests. To secure the Services, prevent abuse, enforce rules, calculate reputation, apply age-gate and device protections, improve the product, operate moderation, understand usage, and defend legal claims.
  • Age-assurance and online-safety obligations. Where applicable, to take reasonable steps to enforce a legal minimum age, comply with online-safety law, operate a proportionate review process, and protect the rights and safety of users. Consent is used where the applicable law requires it for biometric or other sensitive processing; a mandatory legal check is not described as consent merely because the user acknowledges the notice.
  • Consent. For precise location, push notifications, optional public disclosures you control, some analytics or ad processing where required, and any other processing that law requires us to base on consent.
  • Legal obligations. To comply with legal requests, retain required records, address tax or regulatory issues, and support law-enforcement or court processes where valid.
  • Vital interests or public-interest reasons. In the rare situations where they apply, such as credible threats to safety or serious harm.

9. International Data Transfers

NO'TA is offered globally. Your information may be processed in the country where you live and in other countries where we or our service providers operate. Those countries may have privacy laws that differ from the laws of your jurisdiction.

Where required by law, we use appropriate safeguards for cross-border transfers, such as contractual protections, adequacy mechanisms, or other recognized transfer tools. Public content, by its nature, may be accessed worldwide.

Didit may process verification data in its configured processing region and through approved subprocessors. NO'TA's integration is intended to use a restricted processor configuration and short retention. Specific transfer information can be requested from privacy@no-ta.app.

10. Data Retention

We retain personal information for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Policy, comply with law, and protect users and the platform.

Data type General retention approach
Account and profile data Retained while your account is active and for a reasonable period afterward to support recovery, security, legal obligations, and dispute handling.
Public content and public interactions Otherwise-visible shared contributions may remain once account deletion is requested so discussions, directories, and recipient-visible history continue to make sense. NO'TA immediately hides the profile, detaches its username/name, avatar, and profile link from retained items, and displays "User not available." Recovery restores current public snapshots; permanent purge removes the original account identity. The body or media may still identify you if you included identifying information. Content may also be removed by you before account deletion, by an authorized moderator or operator, through an applicable rights request, or when it is otherwise retired; copies may remain in logs, caches, backups, screenshots, search indexes, or third parties that previously accessed it.
Private reflections, journals, and journeys Retained while your account is active or until you delete them, then removed from active systems subject to backup, security, and legal retention needs.
Waitlist, invite, and support records Retained for launch operations, support, security, recordkeeping, and relationship management unless you ask us to delete them and we no longer need them.
Security, moderation, and audit records Retained as long as reasonably necessary to investigate abuse, maintain platform integrity, comply with law, and preserve audit trails.
Age-gate, device, rate-limit, and CAPTCHA records Retained for as long as reasonably necessary to prevent underage signup, account abuse, automated activity, fraud, or ban evasion, then deleted or de-identified when no longer needed.
Didit age-assurance data NO'TA keeps the minimum status, threshold outcome, review/audit timestamps, and a one-way session hash where needed to explain the check. Detailed decision data is scrubbed. Terminal sessions are deleted from Didit after the result is received; failed deletion attempts are retried and escalated. A minimal review record may be kept only as long as necessary to explain the decision, handle a complaint, prevent immediate circumvention, or meet a specific legal obligation.
Media delivery and safety scan records Retained for operational security, abuse investigation, content moderation, cache delivery, legal compliance, and incident response.
Monthly Insight and AI feedback records Generated summaries, aggregate source counts, run status, model and prompt version, versioned opt-in state, deletion state, and audit metadata are retained for the configured Monthly Insight retention window to provide the feature, honor user choices, investigate safety issues, and maintain auditability. If you delete a monthly summary, it is hidden from your Growth home; limited backend, backup, security, or audit records may remain where permitted or required. Raw source text and raw prompts are not intentionally stored in the Monthly Insight feedback tables. OpenAI Responses storage is disabled for generation requests; separate provider abuse-monitoring logs may be retained for up to 30 days unless a different approved data control applies.
Deleted account data NO'TA uses a 30-day grace period for account recovery. After that period, the original authentication account, profile, username, name, avatar, profile link, and private/account-only state are purged. Shared contributions listed above may remain under "User not available," while limited archival information may be retained for legal compliance, fraud prevention, security, dispute handling, or audit purposes.
Local device storage and caches Retained until cleared by the app, overwritten, removed by your device settings, or deleted when the app is uninstalled.

11. Your Choices and Rights

NO'TA offers privacy choices inside the product, and many users have additional rights under local law.

  • Access and portability. You may request a copy of personal information we hold about you, subject to legal limits. Where available, the in-app Export My Data flow can generate a data export.
  • Correction. You can edit profile information in the app and may ask us to correct inaccurate personal information.
  • Deletion. You can request deletion through Settings > Account > Delete Account. NO'TA currently requires an explicit confirmation step and uses a 30-day recovery window before final purge. The profile and public identity snapshots are hidden immediately, while account recovery restores the current snapshots. Account deletion does not automatically remove shared contributions; remove content before deleting the account or contact us for a content-specific request where applicable.
  • Visibility controls. You can change profile privacy, real-name display settings, reflection visibility, journey visibility, and various notification settings.
  • Monthly Insight controls. You can choose whether to opt in to Monthly Insight. Opting out stops future generation. If a monthly summary has been generated, you can delete the visible summary from Growth.
  • Permissions. You can manage notification, location, photo, camera, and microphone access through your device settings.
  • Public content choices. If you do not want content to be public, do not post it publicly or do not switch private-first content to public visibility.
  • Advertising choices. You can use available ad, browser, and device settings to limit personalized advertising where supported. Where available, the in-app Data & Ad Privacy screen exposes mobile ads privacy options, and you may contact us to request applicable statutory opt-outs.
  • Translate or do not translate. Translation is feature-initiated. If you do not want selected content sent to a translation provider, do not use translation features.
  • Age-assurance choice and review. You may request a non-government-ID review, challenge an incorrect outcome, and ask for access to or deletion of age-assurance information subject to lawful limits. Refusing a required check may mean account access remains limited, but government ID is not the only review route where law requires a reasonable alternative.

To exercise privacy rights, email privacy@no-ta.app. We may need to verify your identity before fulfilling a request. In some cases, we may refuse or limit a request where permitted by law.

12. Regional Privacy Notices

12.1 EEA, UK, and Switzerland

If you are in the EEA, UK, or Switzerland, you may have rights to access, correct, delete, restrict, object to, or port your personal data, and to withdraw consent where consent is the basis for processing. You may also lodge a complaint with your local supervisory authority.

The primary controller for the Services is NOTA SOCIAL NETWORK PTY LTD, unless a product-specific notice says otherwise. For privacy questions or rights requests, contact privacy@no-ta.app.

12.2 United States, including California and other state privacy laws

Depending on your state, you may have rights to know, access, correct, delete, and obtain a portable copy of personal information, to opt out of sales, sharing, targeted advertising, certain profiling, or certain uses of sensitive personal information, and to appeal a denied request.

In the last 12 months, NO'TA has collected the categories of personal information described in Section 2, including identifiers, profile and demographic data, user-generated content, social graph data, geolocation data, device and network data, internet or app activity, commercial or advertising data, and inferences such as reputation or product-use metrics.

We collect this information from you, your device or browser, our service providers, login and notification partners, maps and translation providers, and other users or moderators interacting with your content. We disclose these categories for the business and commercial purposes described in Sections 3 through 6.

We do not knowingly sell personal information for money. If ad tech or similar tools used by NO'TA are treated as "sharing" or targeted advertising under state law, you can request an opt-out by contacting privacy@no-ta.app with the subject line "US Privacy Request". If your request is denied, you may appeal by replying to our decision email or emailing the same address with the subject line "Privacy Appeal".

California residents may also designate an authorized agent to act on their behalf, subject to verification and lawful authorization.

12.3 Brazil

If you are in Brazil, you may have rights under the Lei Geral de Protecao de Dados (LGPD), including rights to confirmation of processing, access, correction, anonymization, deletion, portability, information about sharing, and revocation of consent where consent is used. Contact privacy@no-ta.app to exercise those rights.

12.4 Canada

If you are in Canada, including provinces with substantially similar laws, you may request access to and correction of your personal information and may withdraw consent for certain processing, subject to legal and contractual limits. If you are in Quebec, you may also have additional rights under applicable law, including rights relating to portability and automated processing where required.

12.5 Australia and New Zealand

If you are in Australia or New Zealand, you may request access to or correction of personal information we hold about you, subject to lawful exceptions. We may disclose information to overseas service providers as described in this Policy. You may contact us first with any concern, and if we cannot resolve it, you may have the right to complain to the relevant regulator in your jurisdiction.

12.6 Other regions

If the law where you live gives you additional privacy rights, NO'TA will honor those rights to the extent applicable. Contact privacy@no-ta.app and identify your jurisdiction so we can apply the right framework to your request.

13. Children and Minimum Age

NO'TA is not directed to children under 16. We do not knowingly provide accounts to children below the applicable minimum age, but we may process limited age-gate or age-assurance information from a person whose age is not yet known in order to prevent or remove underage access. If the law where you live sets a higher minimum age for social or consent-based services, that higher age applies. If we learn that a child below the applicable minimum age has provided other personal information, we will take reasonable steps to delete or de-identify it. Age-assurance inputs are ringfenced and destroyed after their purpose is complete, subject only to narrowly applicable legal exceptions.

If you believe a child has used NO'TA in violation of this section, contact support@no-ta.app or privacy@no-ta.app.

14. Security

We use technical, administrative, and organizational measures designed to protect personal information, including access controls, database rules, service-provider protections, passkeys, two-factor authentication, CAPTCHA, rate limits, and moderation or audit workflows. No system is perfectly secure, and we cannot guarantee absolute security.

You are responsible for safeguarding your password, passkeys, authenticator codes, device access, and any information you choose to share publicly. Please avoid posting private contact information or other sensitive personal data in public features.

15. Third-Party Services and External Links

NO'TA may link to or integrate with third-party services, including app stores, social login providers, maps providers, translation providers, cloud hosting and media delivery providers, CAPTCHA providers, AI-assisted moderation and feedback providers, age-assurance providers such as Didit, ad networks, support channels, and external links shared by users. Their own policies may also apply. This does not remove NO'TA's responsibility for choosing, instructing, and monitoring processors that handle information on our behalf.

If you click an external link, share content to another service, or otherwise leave the NO'TA environment, you should review the privacy policy of the destination service.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Services, legal requirements, or our processing practices. If we make material changes, we may provide additional notice through the app, website, email, or other reasonable means. The "Last Updated" date at the top shows when this version was last updated.

17. Contact Us

For privacy questions, rights requests, support issues, or complaints, contact the address that matches your issue:

To help us process your request, please include your username, account email (if applicable), country or region, and a clear description of the request.