VelNotes Privacy Policy
Last updated: July 24, 2026
This Privacy Policy explains which categories of personal data are processed through the VelNotes mobile app and velnotes.com, why that data is used, where it may be stored or transferred, and which rights you may exercise. It covers the data-protection framework for core product flows, including note creation, audio/video transcription, local-first storage, iCloud safety backup, and data export.
1. Data Controller and Scope
VelNotes is the data controller for the processing activities described in this policy. Scope includes the mobile app, marketing and support pages on the website, the iCloud backup / restore-check flow, data export, direct email communication, and Apple StoreKit subscription verification.
2. Categories of Data Processed
2.1 App, support, and contact data
The VelNotes mobile app is designed to work without a VelNotes account. It does not keep an in-app email/password account, Google sign-in session, or notebook-linked VelNotes profile. The app and website do not offer a support form that asks for a name, email address, or phone number. If a user chooses to email us from their own email app, the sender address and message content are processed as part of ordinary email delivery.
2.2 Device, website, and security data
The mobile app does not send a persistent remote user ID, device list, or notification/sync verification token for automatic notebook-content transfer. The website may process request timestamps, IP address, user-agent, and limited technical logs needed for abuse prevention. For website analytics, a country code inferred from request headers (and when needed Accept-Language fallback) may be processed for country/region distribution reporting. To preserve the selected website language (Turkish or English), the page may read a language value from the URL and, where preference cookies are allowed, a local on-device preference record; this does not create a separate server-side language profile. Website admin access may use Google/Firebase authentication only for authorized administrators; that administrator session is not a mobile-app user account. Device-local biometric lock checks using Face ID / Touch ID or device passcode fallback are handled by the operating system on the device; VelNotes does not access, store, or transmit biometric template data to its servers.
2.3 Notebook and content data
Notebook/page titles, text, drawing payloads, shapes, stickers, sticky notes, text boxes, imported PDF-page backgrounds, cover/theme metadata, and deletion timestamps may be processed. This content is stored local-first in the app data area by default. When the user starts backup or export, a backup archive or export file may be created according to the selected destination. VelNotes does not edit text or objects inside a source PDF. An imported PDF page remains an immutable background; the app processes only the drawings, text, images, stickers, and shapes the user adds on top. Input preferences such as Finger Writing Mode are stored in on-device settings by default. Where voice and Video to Text features are used, user-approved transcription text may be added to notebook content. During local video import, the audio track of the supported media file the user chose may be extracted on device; VelNotes does not download videos from YouTube or third-party links. Pages captured through camera/document-scanner flows, images imported from the photo library, and image/video exports saved to the photo library at the user's request may also be processed as content data.
2.4 Feature usage and limit data
On-device usage counters, operation timestamps, and technical status records may be processed for notebook creation/editing, export, backup/restore, and plan-limit enforcement. These records are used for service continuity, anti-abuse controls, and limit management. To protect the Free plan notebook creation allowance and prevent limit bypass through repeated reinstall/reset behavior, VelNotes may keep a device-local lifetime free-notebook creation counter in secure on-device storage (Keychain). This counter is not used for cross-app or cross-site tracking.
2.5 Subscription and payment verification data
The current app reads product identifiers and verified subscription entitlements on device through Apple StoreKit 2. Apple performs the transaction; the app does not send StoreKit transaction IDs, receipts, or a subscription profile to a VelNotes/Firebase server and does not create a separate payment account.
2.6 iCloud backup and data export data
When iCloud Backup is enabled, the app may write a notebook backup archive to the user's iCloud Drive area automatically after local changes or when the user requests a manual backup. A restore check is enabled by default so the latest iCloud backup can be used when no active local notebook exists; it can be turned off in Settings. When the user starts data export, a portable archive may be created with notebook/page data and limited technical metadata needed for restore safety. VelNotes does not send the backup archive to its own server. Apple protects the archive in transit and on its iCloud servers under the user's Apple Account and iCloud Drive security settings; end-to-end encryption depends on whether the user enables iCloud Advanced Data Protection.
2.7 Support and contact data
Contact Us / Report Issue in the app and the website contact link open support@velnotes.com in the device's default email app. VelNotes does not show name, email, or phone fields on these screens, submit an HTTPS support form, or create a Firebase/Firestore contact_messages record. If the user chooses to send the email, its sender address, subject, and message content reach us through the user's email provider and may remain in the support mailbox for the time needed to answer the request. The app creates a random Support ID and stores it in the device Keychain. It contains no name or email address, is not automatically sent to a server, and is included only if the user sends the prepared email; it can then be associated with that support correspondence.
2.8 Voice recording and transcription data
When voice recording starts, an audio file may be created in app-local recording storage (VoiceRecordings folder, e.g. velnotes_recording_*.m4a). These files may remain in the in-app recording library until deleted by the user; cleanup flows or technical maintenance can remove them when needed. Recording-library limits and some import options may vary by plan. If the user exports the file to Files, retention is governed by the selected destination. Audio/video transcription uses on-device speech recognition provided by the operating system when supported; on unsupported devices this feature cannot be used. Video to Text works only with supported local media files the user chooses and within the in-app duration limit. Transcription output is generated automatically and may contain mistakes; users should review results before use. In the default flow, raw audio/video files are not uploaded to VelNotes servers as notebook content, while generated transcript text may be stored on device like other notebook content and included when the user starts backup/export.
2.9 Legacy-account transition
Earlier VelNotes versions may have created a legacy Firebase Authentication record containing an email address, display name, provider identifier, and account status. The accountless release does not use that record to open notebooks, determine Pro access, or submit support requests, and it does not create new app accounts. Publishing the new release does not automatically delete legacy account records or notebooks stored on the device. During the staged migration, legacy account records may be retained for a limited period for transition safety and legal or operational obligations; they are deleted or anonymized when no longer needed. The current app does not upload notebook content to those records or to Firebase.
3. Purposes of Processing
Data is processed to provide subscription checks, notebook creation/editing and recovery flows, plan-limit enforcement, iCloud backup and data export operations, subscription verification, device-permission-based local notifications, anti-abuse and security controls, support handling, and service-quality monitoring.
4. Local-first Processing and Backup Scope
Notebook content you own is local-first by default. When iCloud Backup is enabled, a safety copy may be refreshed automatically after local changes or manually by the user; the restore check for the latest iCloud backup can be managed in Settings. Data export is user-initiated and governed by the destination the user selects.
5. Legal Bases
Processing may rely on contractual necessity, legal compliance, legitimate interests in security/fraud prevention, and consent where required (for example, optional cookie categories on the website).
6. Third-Party Services, Sub-processors, and International Transfers
VelNotes uses Apple services (StoreKit, iCloud Drive, and operating-system speech recognition) and website/admin infrastructure services. The website, administrator-only admin panel, live site configuration, and consented web analytics may use Firebase/Google infrastructure. Support and issue-report messages are not sent to Firebase; emails the user sends reach us through the user's email provider. This Firebase use does not create an iOS app account or automatic notebook-content transfer. Audio/video transcription does not require transfer to a separate third-party speech provider; it relies on supported on-device capabilities. Cross-border data transfer may occur through these infrastructure providers.
6.1 Sub-processor List
The following service providers may process personal data on behalf of VelNotes:
Apple Inc. — Subscription verification (StoreKit 2), iCloud Drive backup area, and on-device speech recognition (Speech.framework). Location: USA. Processed under the Apple Developer Program License Agreement.
Google/Firebase — May be used for authorized administrator Google sign-in, the website admin panel, site configuration, admin media management, temporary transition storage for legacy app-account records, and consented web analytics. It is not used by the current iOS app for notebook-content synchronization.
6.2 International Data Transfers
The infrastructure of the above service providers may be located in the USA and other countries. Accordingly, your personal data may be transferred internationally for service delivery purposes. These transfers are safeguarded under GDPR Article 46 through Standard Contractual Clauses (SCCs) and under KVKK Article 9 through explicit consent or transfers to countries providing adequate protection. Apple and Google/Firebase implement EU Standard Contractual Clauses (SCCs), where applicable, and operate under their own Data Processing Addenda (DPA).
7. Retention and Deletion
Data is retained only for as long as needed to provide the service safely and to satisfy applicable legal obligations. When retention is no longer necessary, technical deletion, anonymization, or access-removal processes are applied. After a data deletion request, relevant support/operational records enter cleanup flows. Each time an item is moved to Trash, a new deletion timestamp is written. Restoring the item clears that timestamp; if it is deleted again, the 30-day period restarts from the latest deletion. Unless permanently deleted earlier, an item may remain in the local database and, when enabled, the iCloud safety copy until the 30-day boundary. On the first eligible app maintenance run at or after expiry, it is removed locally, excluded from new backups, and removed from the iCloud archive when that archive is read or refreshed. If the device is off, the app is not running, or iCloud is unavailable, the operation completes on the next eligible run. Security and anti-abuse logs (including IP address and user-agent) may be kept for limited periods under legitimate-interest and legal-obligation grounds. Sent support emails may remain in the VelNotes mailbox and the ordinary retention or backup systems of the email providers for the period needed to answer the request and meet legal obligations; they enter deletion flows when no longer needed. Voice recordings are stored in app-local recording-library storage by default; users can delete them, and cleanup actions may remove them where applicable. If a file is exported by the user, retention depends on the selected destination. Free-tier local notebook data may be lost on uninstall or device loss unless a backup exists. Exported archives remain under the selected destination's control and can be manually removed by the user.
8. Cookies and Similar Technologies
velnotes.com uses strictly necessary technical storage and preference mechanisms. Website analytics may include visited-page and country/region distribution measurements; country/region is evaluated via country code inferred from request headers without requesting client geolocation access. Optional categories (preferences/analytics/marketing) are consent-based. See Cookie Policy for details.
9. Security Measures
Security controls include the app sandbox and file protection, on-device Keychain use, StoreKit verification, website rate limiting and abuse monitoring, and authorized-account/role checks for the admin panel. Absolute security over internet transmission cannot be guaranteed.
10. User Rights and Requests
You may request access to your personal data, correction of inaccurate records, deletion, objection to processing, and permission-management actions, including managing local/iCloud backups, and managing notification permissions through operating-system settings. Contact: support@velnotes.com.
11. Data Breach Notification Procedure
In the event of a personal data breach, VelNotes follows the procedure below:
72-hour rule: In accordance with GDPR Article 33 and KVKK Article 12/5, if unauthorized access to or processing of personal data is detected, notification will be made to the relevant Data Protection Authority (and where applicable, the relevant EU Supervisory Authority) within 72 hours at most.
User notification: If the breach poses a high risk to users' rights and freedoms, affected people whose contact details are available will be contacted directly; where they are not available, notice will be provided through an appropriate method such as the website or an in-app notice, as soon as reasonably possible. The notification will include the nature of the breach, affected data categories, potential consequences, and measures taken or planned.
Contact: If you suspect a data breach, please contact support@velnotes.com.
12. Policy Updates
VelNotes may update this policy when product features, infrastructure providers, or legal requirements change. The updated text becomes effective on the publication date and remains available on the website.