Privacy policy
Last updated 24 August 2026
Ambient Notes is a personal note surface. This policy explains exactly what leaves your device, what the service can and cannot read, and how to remove everything.
The short version
- Notes are encrypted on your device before they are sent anywhere.
- The service stores ciphertext. It has no key and cannot read a note.
- An account is optional, has no password, and cannot open a space or read a note.
- Nothing is sold or used for advertising or model training. Data is shared only for the features and service providers described below.
- You can delete the entire synced copy from inside the app at any time.
What Ambient Notes collects
Note content. Your notes stay on your device. If sync is used, each note is encrypted with a key generated on your device using AES-256-GCM, and only the resulting ciphertext, a random nonce, and a keyed content fingerprint are sent to the service. The fingerprint lets the service notice that two devices changed the same note differently, so an edit is preserved as a conflict copy rather than silently lost. It cannot be reversed to recover the text. A place's name is encrypted the same way, so the service can file a note into a place without knowing what that place is called.
Note metadata. Colour, paper style, pinned state, archived state, board position, which place a note is filed in, reminder times, timestamps, and version numbers are stored unencrypted so the service can order and reconcile changes across devices. Treat these as visible to the service. Note text, which is the sensitive part, is not.
Sync space identifiers. A private sync space is an anonymous identifier with no personal information attached. Access uses a bearer capability generated on your device; the service stores only a SHA-256 hash of it. Each device also sends a random identifier of its own so the service can tell which device last changed a note; it is generated locally and says nothing about the hardware.
Accounts. Signing in with Apple is optional and offered on Apple devices and the web. It gives a space an owner, so there is somebody to bill, to warn before anything is deleted, and to help when they write in. The service stores Apple's per-app identifier for you and, when Apple provides them, your Apple account name and email address. The web flow asks Apple for neither name nor email. The email is often a private relay and is used only for writing to you. The service does not retain Apple access, identity, or refresh tokens. Apple may send the service a signed notice when you disable or enable private email forwarding, revoke consent, or delete your Apple Account. Those notices are used to update forwarding state or process the account-status change. The name is used only to label your account in the app. Apple does not provide a profile photo, and Ambient Notes does not ask Apple for one. Signing in hands back no capability and no key, so an account cannot open a space or read a note.
Push notifications. On an Apple device, if you allow notifications after signing in, the app sends its Apple Push Notification service token and a random device identifier to the service. The token is stored with the account so the service can ask Apple to deliver a short alert when a browser requests access. It is replaced when that device registers a new token, removed if Apple reports it as invalid, and removed with normal in-app account deletion. The alert does not contain note content.
Guest accounts and shared-note names. Opening a shared-note invitation without an Apple account creates a guest account. It stores the display name you type, with no email address, Apple identifier, or password. The service can read that name and makes it available with shared-note membership information so other participants know who is editing. Leaving a note, being removed, or letting the browser session expire does not by itself delete the guest account or name. The current browser app does not provide a guest-account deletion button; contact support if you need a browser-created guest account removed.
Shared notes. Sharing a note creates a shared document the service relays between its participants. Text, drawings, and live presence travel as sealed frames encrypted on the device with a key the service never holds. The service can read who is in a note, each person's role and display name, when they joined, the public half of participating device keys, hashed invitation codes, and the sender, order, and arrival time of each encrypted frame. Frames are retained as a bounded recent tail so someone who was away can catch up.
Problem reports. Choosing Report a problem sends the text you enter and a limited diagnostics record. That record contains a timestamp, device and app version information, the current board or list surface, counts of notes and places, recent card and scroll measurements, and up to 24 named gesture events with numeric movement and timing values. Automatically gathered diagnostics do not include note text, drawings, images, place names, note or space identifiers, account details, sessions, or sync credentials. The description is free text, so do not include sensitive note content unless you intend to send it.
Reports pass through the Ambient Notes API and become issues in the project's private GitHub repository, where GitHub processes them. Their bodies are not stored in the Ambient Notes database or application logs. There is currently no automatic expiration or in-app deletion mechanism for those GitHub issues.
Diagnostics. The service records ordinary operational logs (timestamps, request paths, status codes, a release identifier, and account identifiers for account operations) to keep the service running and answer support requests. Note content never appears in logs or telemetry. Automatically gathered problem report diagnostics exclude note content as described above.
What Ambient Notes does not collect
No password or phone number is ever requested. There is no advertising identifier, no analytics SDK, no location data, no contacts access, and no cross-app tracking. Your notes are never used to train machine learning models.
Encryption and its consequences
The encryption key never reaches the service. On Apple devices it is stored in the Keychain as a synchronizable item, so iCloud Keychain may carry it to a replacement device, end to end encrypted in a way Apple cannot read either. On the web, the browser normally stores it as a non-extractable cryptographic key. If that browser cannot store the key that way, it keeps the key in the app's local browser storage instead. The key is not sent to the service. Anywhere iCloud Keychain does not reach, it travels through the device-link flow or a recovery phrase, both of which wrap it so the service only ever sees an opaque blob.
This has an important consequence you should understand: if you lose every device, do not have iCloud Keychain switched on, and have not saved a recovery phrase, your notes cannot be recovered by anyone, including us. That is the cost of the service being unable to read them. The app cannot verify that iCloud Keychain synchronized the key. A recovery phrase saved beforehand is the only recovery method independent of iCloud Keychain and any surviving device.
Photos
Two different things use the photo picker, and they are treated differently.
A custom background is processed and stored on that device only. It is never uploaded and is not part of sync.
An image attached to a note is part of that note. It is encrypted on your device with the same key as the note's text, before it leaves, and syncs so your other devices can see it. The service stores it as ciphertext it cannot read, exactly like note text and doodles. Attached images are resized and compressed first, both to keep them small and because a note shows an illustration rather than an archive of the original photo.
Handwriting
Handwriting is ink, and it stays ink. Nothing reads it and nothing turns it into characters: the canvas keeps the strokes you drew, and they are encrypted before sync like the rest of a note. What you write is never sent to Google or to anyone else.
Earlier builds tidied handwriting into neat script using a recognition model downloaded from Google and run on the device. That feature has been removed, so there is no model to download and nothing about handwriting touches the network at all.
Deleting your data
Deleting the native app removes every local note from that device. Removing an installed web app may leave its browser data behind; clear the site data for app.ambientnotes.app in the browser to remove that local copy.
To remove the server data used for sync and recovery, open Private space and choose Delete synced copy. This erases the sync space and everything attached to it, including encrypted note records and deletion markers, every access capability, and any pending device-link codes. Notes already on the device you are holding are kept so you do not lose your work. Your Apple account is not deleted. The deletion is immediate and cannot be undone.
If you signed in, Delete Ambient Notes account in the Apple account screen removes the account and every synced copy it owns. It refuses the first time and says how many synced copies that is, so the cost is named before anything is erased rather than after. Notes already on your devices are kept here too. You confirm the action with Apple, and Ambient Notes revokes its Sign in with Apple authorization before deleting the account. Account deletion currently requires Ambient Notes on an iPhone or iPad; the web app explains this rather than showing a deletion button it cannot complete.
Data retention
Current encrypted note records are retained until you delete the sync space. Deleting a note drops its encrypted pictures and doodle from the service straight away; the encrypted text and metadata stay behind as a deletion marker, which is how a second device learns the note is gone rather than putting it back. Expired device-link codes are purged after they expire, and operation receipts used to make retries safe are retained for thirty days.
A sync space that has never held a note or a place is reclaimed thirty days after it was created, provided nothing has ever contacted it and it carries no recovery phrase, no linked device, and no account. A space that holds notes is never reclaimed, however long it has been quiet.
Service providers
The service runs on Microsoft Azure (App Service and Azure Database for PostgreSQL) in the United States, and the web client and this website are served by Vercel. These providers process data on our behalf as infrastructure. Note content sent for sync remains encrypted; optional problem-report text passes through the API as described above. GitHub processes those problem reports, and Apple processes Sign in with Apple and any push notification you enable. Traffic uses HTTPS, and the database is not reachable from the public internet.
Children
Ambient Notes is not directed at children under 13 and does not knowingly collect information from them.
Changes
Material changes to this policy will be reflected here with an updated date, and significant changes will be surfaced in the app.
Contact
Questions about privacy or a data request can be sent to support@ambientnotes.app.