Chatlo Notes

Privacy Policy

Last updated: March 3, 2026

1. Introduction

Welcome to Chatlo Notes ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered note-taking application.

2. Information We Collect

2.1 Personal Information

  • Account information (name, email address, profile picture)
  • Authentication data through Google Sign-In

2.2 Content Data

  • Voice recordings and transcriptions
  • Text notes and documents
  • Uploaded files (PDFs, images)
  • AI-generated summaries and flashcards
  • Meeting recordings and transcripts

2.3 Usage Data

  • Device information and browser type
  • Usage patterns and feature interactions
  • Error logs and performance data
  • Analytics cookies (PostHog) — with your consent

3. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal bases:

  • Consent — For analytics cookies and marketing communications. You can withdraw consent at any time.
  • Performance of a Contract — To provide, maintain, and improve the Chatlo Notes service as agreed in our Terms of Service.
  • Legitimate Interest — For security, fraud prevention, product improvement, and customer support.
  • Legal Obligation — To comply with applicable laws and regulations.

4. How We Use Your Information

  • To provide and maintain our services
  • To process your voice recordings and generate transcriptions
  • To create AI-powered summaries, flashcards, and quizzes
  • To improve and personalize your experience
  • To communicate with you about updates and features
  • To ensure security and prevent fraud

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Account data — Retained for the duration of your account. Deleted within 30 days of account deletion.
  • Notes and content — Retained until you delete them or delete your account.
  • Analytics data — Anonymized and aggregated data may be retained indefinitely. Identifiable analytics data is retained for up to 12 months.
  • Server logs — Retained for up to 90 days for security and debugging purposes.

6. Data Storage and Security

Your data is stored securely using Firebase services and Google Cloud. We implement industry-standard security measures including encryption in transit (TLS) and at rest (AES-256), secure authentication via OAuth 2.0, and access controls. While no system is 100% secure, we continuously review and improve our security practices.

7. Data Sharing and Google API Services

We use the following third-party services to provide our core features:

  • Google Firebase (authentication and storage)
  • Google Gemini AI (for AI-powered features)
  • PostHog (analytics — with your consent)

Google User Data Disclosure

We do not share, transfer, or disclose Google user data with any third parties for purposes other than providing the core functionality of our application as described above. We strictly do not sell your personal data or use information received from Google APIs for advertising purposes.

Chatlo Notes's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your Rights

8.1 GDPR Rights (EU/EEA Users)

If you are in the EU/EEA, you have the following rights:

  • Right of access — Request a copy of your personal data.
  • Right to rectification — Correct inaccurate personal data.
  • Right to erasure — Delete your account and data via Settings → Delete Account.
  • Right to data portability — Export your notes in standard formats.
  • Right to restrict processing — Request limits on how we use your data.
  • Right to withdraw consent — Withdraw cookie/analytics consent at any time.
  • Right to lodge a complaint — With your local data protection authority.

8.2 CCPA Rights (California Users)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used.
  • Request deletion of your personal information.
  • Opt out of the sale of personal information.
  • Non-discrimination for exercising your privacy rights.

We do not sell, rent, or trade your personal information to third parties. We never have and never will.

8.3 DPDPA Rights (India Users)

Under India's Digital Personal Data Protection Act, 2023:

  • You have the right to access and correct your personal data.
  • You have the right to nominate another person for your data rights.
  • You can withdraw consent at any time for data processing based on consent.
  • You can file a grievance with our Grievance Officer (see contact details below).

9. Cookies and Tracking

We use the following types of cookies:

  • Essential cookies — Required for authentication and basic function. Cannot be opted out.
  • Analytics cookies — PostHog analytics to improve our product. Requires your consent. You can opt out via the cookie consent banner or by contacting us.

10. Contact Us & Grievance Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Email: support@chatlo.io

Grievance Officer / DPO: privacy@chatlo.io

We aim to respond to all data-related requests within 30 days.