Legal
Privacy Policy
- Effective
- Last updated
1. Overview
Jottoo ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. Jottoo is a local-first application providing notes, meeting capture, audio transcription, task management, and AI-assisted summaries across iOS and Web platforms.
Our service is built around a local-first architecture:
- Notes and tasks are created and stored locally on your device for fast offline access.
- When you are signed in, notes sync to Firebase Firestore as AES-GCM ciphertext produced on your device (end-to-end encryption for note content).
- A password-wrapped encryption key and recovery key to unlock your notes.
- Local app lock settings (such as Face ID or Touch ID on native apps) never leave your device. Biometric data is not sent to Jottoo.
This Privacy Policy explains what information we collect, how it is used, how sensitive data is handled, and the legal limits of our liability regarding your data.
2. Information We Collect
A. Account & Authentication Information
- Credentials: Email address, user identification numbers (
uid), and login states managed securely via Firebase Authentication. - Recovery keys: When you enroll or re-email a recovery key, Jottoo securely stores a protected recovery copy in a private collection. It cannot be accessed through the Jottoo app, by other users, or through public APIs. If you lose all of your personal copies, a recovery copy can be sent to your registered account email. Your unwrapped note encryption key is never stored.
- Biometric Settings: Local app toggles indicating whether Face ID or Touch ID is enabled. Note: Jottoo never receives, collects, or stores your actual fingerprints or facial recognition geometry.
B. User Content & Note Data
- Text Content: Note titles, body text (plain text and formatted HTML), manual meeting notes, tasks, calendar entries, tags, and workspace structures.
- Audio & Transcripts: Recorded AAC/M4A audio files captured during voice recording sessions, machine-generated plain text transcripts, and AI-generated meeting summaries.
C. Support & Feedback Data
- Support Tickets: Information you voluntarily submit through our in-app feedback or bug report system, including problem descriptions, category mode (Business or Personal), app version, and platform (iOS or Web).
D. Technical & Diagnostic Information
- Metadata: Device model, operating system version, sync status (pending, completed, failed), and system crash logs necessary to maintain security and operating performance.
E. Advertising measurement
When you create an account on the web, we may send a Sign Up conversion to Reddit Ads (Conversions API) so we can measure whether ads led to sign-up. That event can include a hashed copy of your email, your IP address, browser user agent, and a Reddit click identifier if you arrived from a Reddit ad. Reddit does not receive your password, notes, or encryption keys.
3. How We Use Information
We use collected information strictly to operate, maintain, and safeguard the Jottoo service:
- Local Synchronization: Syncing notes between your authorized devices (iOS and Web) using Firebase Firestore.
- Audio Processing & AI Summarization: Transcribing uploaded audio files and generating concise or detailed meeting summaries using automated AI pipelines.
- Automated Support Triage: Categorizing and prioritizing support tickets using AI-assisted clustering models to fix bugs and plan product updates.
- Access Control: Verifying your identity and enforcing biometric locking when opening the application.
- Advertising measurement: Measuring whether Reddit ads led to a web sign-up, as described in Section 2(E).
Data Protection Guarantee: We do not sell your personal information or note content. We do not use your private notes, audio recordings, or meeting transcripts to train public machine learning or AI models.
4. How Data Is Shared, Transferred & Processed
We share data only with third-party service providers essential to delivering Jottoo’s core capabilities, bound by privacy and confidentiality agreements:
- Cloud Infrastructure & Storage (Google Cloud / Firebase): For user authentication, cloud database syncing (Firestore), and serverless backend workflows (Cloud Functions). Account data, database records, and user content are hosted on servers located in the United States. Note titles and bodies stored in Firestore are encrypted client-side (AES-GCM); privileged administrators cannot read ciphertext without your password or recovery key. Metadata used for sync and routing may remain unencrypted.
- AI & Machine Learning Services: Audio recordings and plain-text transcripts are transmitted via secure, encrypted server-side APIs solely to generate your requested summaries and process support submissions. Please note: While primary database storage is US-based, third-party AI processing servers and model inference infrastructure may be located outside of the United States depending on regional routing, server load, and vendor availability.
- App Distribution Platforms (Apple App Store & TestFlight): For software distribution, build installation, and diagnostic feedback.
- Payments (Stripe & Apple): Web subscriptions are $13.99 USD per month, excluding applicable taxes, processed by Stripe, Inc. iOS subscriptions are billed through Apple at the same list price (Apple may show a localized equivalent). We receive limited billing metadata (subscription status, customer ID, and payment outcome). We do not store your full payment card number. Billing terms are in our Terms of Service.
Separately, when you create a web account we may send a Sign Up conversion event to Reddit Ads (Conversions API) to measure advertising performance. Identifiers are hashed where Reddit supports hashing.
We may also disclose information if required to do so by applicable law, court order, or governmental regulation, or to protect the safety, rights, and security of Jottoo and its users.
5. Critical Technical Disclaimers & Limitation of Liability
A. Account Authentication & End-to-End Encryption
Jottoo protects notes with Firebase Authentication (email and password), Firestore security rules, and client-side AES-GCM encryption.
Sensitive note fields are encrypted on your device before sync. Changing your password re-wraps the same encryption key so you can still decrypt existing notes. If you reset a forgotten password, you may need your recovery key (saved in Settings) when this device no longer has your encryption key.
Jottoo securely stores a protected recovery copy of each recovery key in a private collection. It cannot be accessed through the Jottoo app, by other users, or through public APIs. If you lose all of your personal copies, a recovery copy can be sent to your registered account email. Your unwrapped note encryption key is never stored.
Authorized backend administrators cannot read encrypted note bodies without your password or recovery key. Brief plaintext may exist during server-side AI transcription until your device re-encrypts those fields.
Jottoo is not liable for data loss resulting from lost credentials, lost recovery keys, account lockouts, or failure to keep your password secure.
B. Accuracy of AI-Generated Content
Transcriptions, meeting summaries, action items, and automated triage classifications are produced using automated machine learning and third-party AI models.
- No Guarantee of Accuracy: Machine-generated outputs may contain errors, omissions, inaccuracies, or false information ("hallucinations").
- Not Professional Advice: AI-generated content is provided strictly for organizational convenience. It must not be relied upon for legal, medical, compliance, financial, or other high-risk decision-making.
- Exclusion of Liability: Jottoo disclaims all liability for actions taken, decisions made, or commitments missed based on the contents or omissions of AI-generated transcripts or summaries.
C. Local-First Storage & Offline Risks
Jottoo operates on a local-first model. Content that has not yet synced to the cloud resides exclusively within your device’s local application storage.
You are solely responsible for maintaining device backups and maintaining network connectivity to trigger cloud synchronization. Jottoo is not liable for data loss caused by hardware damage, physical loss of your device, operating system crashes, app uninstallation, or local storage corruption.
D. Security Standards & Third-Party Dependencies
We implement industry-standard technical measures, including HTTPS/TLS encryption in transit. However, no electronic transmission or local storage system is 100% secure.
Jottoo relies on third-party cloud infrastructure (such as Google Cloud and Firebase). While we contractually ensure our infrastructure providers adhere to strict security standards, Jottoo cannot guarantee absolute protection against third-party server outages, hardware failures, or unauthorized third-party intrusions. Encrypted note ciphertext remains unreadable without your keys.
6. Retention & Deletion
- Data Retention: We retain account and database records for as long as your account remains active.
- Temporary Audio Queue: Audio files stored in local temporary queues (
pending-audio/) are automatically deleted from your device local storage immediately after successful backend transmission. - Cascading Deletion: When you delete a note, transcript, or recording in Jottoo, a deletion command is dispatched to purge the record across your local cache and our cloud database.
- Account Deletion: You may request full account and data deletion at any time through the app settings or by contacting us. Upon account deletion, all associated user records, cloud documents, and stored support tickets will be permanently removed.
7. Your Rights & Choices
Depending on your local legal jurisdiction, you may have the right to:
- Access & Export: Request a copy of the personal information associated with your account.
- Correction & Erasure: Correct inaccurate profile details or request the permanent erasure of your account data.
- Local Controls: Enable or disable Face ID/Touch ID app locking, or clear local client caches via the app settings menu.
To exercise any of these rights, please submit a request using the contact information below.
8. Children’s Privacy
Jottoo is intended for a general professional audience and is not directed at children under 16 years of age. We do not knowingly collect or solicit personal information from children under 16. If we become aware that personal data from a child under 16 has been collected without verified parental consent, we will take immediate steps to purge that information.
9. Contact Us
For questions, feedback, or legal inquiries regarding this Privacy Policy or Jottoo's data handling practices, please contact:
Data Protection & Legal Inquiries: Email: [email protected]

