Privacy Policy
Typednotes (“Typednotes”, “we”, “us”) operates the website www.typednotes.com and the Typednotes application at app.typednotes.com (together, the “Service”). Typednotes is a server-side agent that acts on resources on behalf of its users, with bounded, auditable authority.
This policy explains what information we collect, how we use and share it, how long we keep it, and the choices you have. It also describes how we handle data received from Google APIs.
1. Information we collect
Account information
You sign in with GitHub or Google. From the identity provider we receive your provider account identifier, your name, your verified email address and your profile picture URL. We never receive your password.
Organizations and projects
The organizations, memberships, roles, projects, primary repositories, messaging interfaces and settings you create or join in the Service.
Connection credentials
When you connect a third-party service to an organization — for example GitHub, GitLab, an S3-compatible bucket, Azure Blob Storage, Dropbox, Google Drive, an AI provider (Anthropic, Mistral, OpenAI or an OpenAI-compatible endpoint) or a messaging platform (Slack, WhatsApp, Signal) — we store the OAuth tokens, API keys or other credentials required to act on your behalf. Credentials are stored encrypted in a dedicated secrets vault and are never displayed back.
Content from connected services
When you, or an agent running in one of your projects, perform an action, the Service accesses the content needed to perform it: repository contents, files in connected storage, and messages received by your project’s messaging interfaces (which land in the project’s inbox).
Usage and billing
Usage events, credit balances and holds used to meter the Service.
Technical data
Server logs containing IP addresses, user agents, timestamps and request paths, used for security, abuse prevention and debugging.
Cookies
The application uses a strictly necessary session cookie, plus short-lived cookies that protect the sign-in flow. We use no advertising or analytics cookies. This website (www.typednotes.com) sets no cookies and loads no third-party resources.
2. How we use information
- To provide and operate the Service: create your account, sign you in, and run your organizations and projects.
- To perform the actions you, or members of your organization, request through the Service.
- To meter usage and manage credits.
- To secure the Service, prevent fraud and abuse, and debug problems.
- To send you service-related messages (for example security or policy notices).
- To comply with legal obligations.
We do not sell personal data, we do not use it for advertising, and we do not build marketing profiles.
3. Google user data
The Service uses Google APIs in two cases:
- Sign in with Google (scopes
openid,email,profile): we receive your Google account identifier, name, verified email address and profile picture URL, used only to create your account and sign you in. - Google Drive connection (only if you connect Google Drive to an organization): we access the Drive files needed to perform the actions you or your project members request, such as reading or writing documents for a project.
How we handle Google user data:
- We use it only to provide and improve the user-facing features of the Service that you request.
- We do not transfer it to third parties, except as necessary to provide the features you request (for example, sending a file’s content to the AI provider account you connected to your project, at your direction), to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.
- We do not use it for advertising, including personalized, retargeted or interest-based advertising, and we do not sell it.
- We do not use it to determine credit-worthiness or for lending purposes.
- No human at Typednotes reads it unless you give explicit consent for specific data, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or it is aggregated and anonymized for internal operations.
- We do not use it to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
Typednotes’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Drive from your organization in the Service at any time, and revoke Typednotes’ access to your Google account at myaccount.google.com/permissions.
4. How we share information
- Members of your organizations can see organization data, projects and inboxes according to their roles.
- Third-party services you connect. When the Service acts on your behalf, it sends the data needed for that action to the service concerned (for example, a prompt and relevant file content to the AI provider account you connected, or a reply to a Slack channel). Those services process the data under their own terms and privacy policies, under your account with them.
- Infrastructure providers who host and operate the Service for us, under contractual confidentiality and security obligations, and only to provide the Service.
- Legal reasons, when required by law or to protect the rights, safety and security of our users, the public or Typednotes.
- Business transfers, in connection with a merger, acquisition or sale of assets, with notice to you.
- With your consent, in any other case.
5. Retention and deletion
- Account, organization and project data are kept while your account is active.
- Connection credentials are deleted from the vault when you disconnect the service.
- Server logs are kept for a limited period for security and debugging, then deleted.
- When you delete your account, or ask us to, we delete or anonymize your personal data within 30 days, except where we must keep some of it to meet legal obligations.
6. Security
Data is encrypted in transit (TLS). Connection credentials are encrypted in a dedicated secrets vault. Calls to third-party providers go through a single broker service that enforces scoped, auditable authority, and our services run with least-privilege access. No method of transmission or storage is completely secure, but we work to protect your data and will notify you of breaches as required by law.
7. Your rights
Depending on where you live (for example under the GDPR, the UK GDPR or US state privacy laws), you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent at any time. To exercise these rights, contact us at the address below; we respond within 30 days. You may also lodge a complaint with your local data protection authority.
We process personal data to perform our contract with you (providing the Service), for our legitimate interests (security, abuse prevention and improving the Service), to comply with legal obligations, and, where required, with your consent.
8. International transfers
Your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy. We will change the “Last updated” date above and, for material changes, notify you through the Service or by email before they take effect.
11. Contact
Questions or requests about this policy or your data: privacy@typednotes.com.
See also our Terms of Service.