← Back to GNOTO

Privacy Policy

Last updated: August 23, 2026

GNOTO (the “Service”) respects your privacy and handles your personal information responsibly. This policy describes what we collect, how we use it, sharing with third parties, storage, and your rights.

1. Operator

  • Service: GNOTO
  • Operator: Takashita Yoshiaki
  • Contact: Gnoto.official@outlook.com
  • Address / phone: disclosed without delay upon request.

2. Information we collect

  • Account info: display name, email address, account code, authentication data.
  • Your content: note contents, images, and chat messages/images.
  • Usage data: time used, characters typed, token balance, plan status.
  • Payment data: transaction details when purchasing a plan. We do not store card numbers; payments are processed by payment providers (e.g. Stripe).
  • Technical data: IP address, browser/device info, settings stored in cookies/local storage.
  • Credentials you supply to connect external services: AI provider API keys and GitHub access tokens. These are stored on your device only. They are never sent to our servers and are excluded from cloud sync.

2-2. What the AI features send (important)

The AI features are bring-your-own-key. You connect an account you already hold with an AI provider by entering your own API key, and that provider bills you directly. We do not resell AI.

  • Where it goes: the single provider you connected (Anthropic, OpenAI, or Google). It does not pass through our servers — it is sent from your device straight to that provider's API.
  • What is sent: the prompt you write, the contents of notes in folders you have allowed the AI to read, and any image, PDF, or audio file you explicitly attach.
  • Controlling the scope: by default the AI can read nothing. Only folders you explicitly allow are included, and you can revoke that at any time. The interface always shows the current reach and the exact notes that were read.
  • Opting out: unless you connect an API key, no AI feature appears and no traffic to any AI provider occurs at all.
  • Data you send is then handled under the privacy policy and API terms of the provider you connected. Please review them before use.

The Service includes features where an AI generates text, slides, and similar content in response to your input. If generated content is inappropriate, you can report it to the developer from "Report AI content" inside the app.

2-3. What the GitHub integration sends and receives

Active only when you supply a GitHub access token.

  • Reading: fetches README files and issues from repositories you choose, as notes.
  • Writing: opening pull requests, filing issues, and merging pull requests. Writing is off by default and is enabled only when you explicitly opt in. Every write is initiated by you; the AI never writes on its own.
  • Every write is recorded in an in-app log you can inspect at any time.

3. How we use information

  • To provide the Service, authenticate you, and store/sync your data.
  • To provide communication features such as chat.
  • To manage plans, billing, and tokens.
  • To prevent abuse, improve quality, and respond to inquiries.

4. Third parties

We use the following providers, which process data only as needed:

  • Supabase (database, authentication, storage)
  • Stripe / PayPal / PayPay and other payment providers (billing; their privacy policies apply)
  • Google Fonts (your IP may be sent when fonts are delivered)
  • Translation API when you use the translation feature (selected text is sent for translation)
  • Anthropic / OpenAI / Google (AI): only the one provider you connected receives what is described in 2-2, sent directly from your device (only if you connect one)
  • GitHub: only if you supply a token, for the reads and writes described in 2-3
  • Google / Apple: if you sign in with them, we communicate with them via Supabase to authenticate you
  • Wikimedia (dictionary and image lookups)

We do not share personal information with third parties beyond these purposes without your consent, except as required by law.

5. User communication and safety features (chat)

The Service includes chat, where you can exchange messages and images with friends (mutually added users). For safety we provide the following:

  • Interaction is limited to friends you add. You can disable automatic friend-adding by account code in settings.
  • You can block and report users or content in the app.
  • Reported content may be reviewed by us to ensure safety and check for policy violations.
  • Posting or sharing nudity, graphic violence, harassment, impersonation, or other objectionable content is prohibited.

6. Storage

Information is stored in the cloud (Supabase) and on your device (local storage / IndexedDB). Data may be processed and stored on servers outside your country.

7. Security

We apply reasonable safeguards including HTTPS encryption, row-level security (RLS) limiting access to your own data, and output escaping.

8. Your rights

You may request access, correction, deletion, or restriction of your personal information. You can delete your account and notes in the app, or contact us at the address above.

9. Children

We do not knowingly collect personal information from children under 13 without parental consent.

10. Changes

We may update this policy as needed. Material changes will be announced on this page.

11. Contact

Questions about this policy: Gnoto.official@outlook.com.