Transparency & Data Protection

GeniaNotes Privacy Policy

Last updated: September 20, 2026 | Official domain: https://www.genianotes.com

1. Introduction & Data Controller

GeniaNotes ("we", "our", or "the Application", accessible at https://www.genianotes.com and https://dev.genianotes.com) is an AI-powered personal knowledge management (PKM) system.

This Privacy Policy comprehensively and transparently explains how we collect, access, use, store, protect, and share user data, with explicit disclosure regarding information received from Google APIs (Google Drive API and Google Identity Services).

2. Google User Data Disclosure (Google API Services Compliance)

A. What Google data do we access or collect?

When you connect Google Drive to GeniaNotes, you authorize access via the official Google Picker dialog. We only access:

  • File Metadata: Google Drive File ID (fileId), document title, MIME type, and web view link of the specific file you choose in the Google Picker.
  • File Binary Stream: The binary content of the specific PDF document you choose to view or summarize.
  • Basic Account Information: Your Google email address and user identifier to associate your notes with your GeniaNotes account.

B. How do we use Google user data?

Google user data is used strictly and exclusively to provide and improve user-facing features of GeniaNotes:

  • Real-time Streaming Viewer: Streaming the PDF directly to your browser's interactive reader in GeniaNotes without requiring you to manually upload the file.
  • On-Demand AI Analysis: When you click "Genia!", document text is streamed in-memory to generate structured summaries, P.A.R.A. classifications, and flashcards.
  • No Advertising Use: We do NOT use your Google data for serving ads, building consumer profiles, or commercial marketing.
  • No Generalized AI Model Training: Your Google Drive documents and personal notes are NEVER used to train, retrain, or improve generalized or public AI/LLM models.

C. How do we store and retain Google data?

  • Zero Persistent Storage of Source Files: GeniaNotes DOES NOT store duplicate copies of your Google Drive files in our database or in Firebase Storage. The original file remains 100% in your Google Drive.
  • Metadata Retention: We only store the driveFileId and note title in Firestore so the note card can render in your Inbox.
  • Ephemeral OAuth Tokens: Access tokens are held only in volatile client-side browser session storage (sessionStorage) and expire automatically.

D. With whom do we share or transfer Google user data?

GeniaNotes does NOT sell, rent, trade, or transfer Google user data to any third party. Data is only processed through essential infrastructure sub-processors:

  • Google Cloud Platform & Firebase: Encrypted hosting, database, and authentication backend.
  • Google Gemini API: In-memory processing under Google Cloud enterprise terms (customer data is not logged or retained for model training).

Google API Services User Data Policy - Limited Use Disclosure

"GeniaNotes' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

3. Other Data Collected on the Platform

  • Notes & User Content: Text notes, highlights, custom tags, and P.A.R.A. categorizations created inside the app.
  • Web & Social Media Ingestion: Public URLs from articles, X (Twitter) threads, LinkedIn posts, YouTube videos, or GitHub repositories that you choose to save.
  • WhatsApp Integration: Sender phone identifier and message content sent to the official GeniaNotes bot solely to ingest your links.

4. Data Security & Protection Mechanisms

We implement robust technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction:

  • Encryption in Transit: All communications use HTTPS with modern TLS 1.3 encryption protocols.
  • Encryption at Rest: Database records in Cloud Firestore are encrypted with industry-standard AES-256.
  • User Isolation: Strict Firestore Security Rules ensure each user can strictly access only their own data.

5. User Control, Retention, and Deletion

You maintain full ownership and control of your data at all times:

  • Deleting Notes: You can delete any note, link, or linked Google Drive item directly from the Inbox. Deleting an item permanently purges its metadata and summaries from Firestore.
  • Revoking Google Access: You can revoke GeniaNotes's access to your Google account at any time via your Google Account Security settings: https://myaccount.google.com/permissions.
  • Account Deletion: You can request full deletion of your account and all associated records by contacting soporte@genianotes.com.

6. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify users of any material changes by updating the "Last updated" date at the top of this page and, for significant changes, by placing a prominent notice in the application.

7. Contact Information

If you have questions, inquiries, or requests regarding this Privacy Policy or your personal data, please contact:

GeniaNotes Support Team

Email: soporte@genianotes.com

Website: https://www.genianotes.com