Privacy Policy
Effective Date: June 3, 2026
Last Updated: June 3, 2026
This Privacy Policy explains how Conoted ("we", "us", or "the Service"), operated by Streltsov Company D.O.O. (the "Company"), collects, uses, and shares your personal information.
Conoted is a note-taking, knowledge management, and communication service. This policy applies to all users of our websites (conoted.com, conoted.us, conoted.org, conoted.net, conoted.fr), mobile apps (iOS, Android), and desktop experiences.
1. Information We Collect
1.1 Information You Provide
When you register and use Conoted, you provide:
- Account information: name, email address, username, avatar
- Authentication data: Apple ID, Google account, Telegram ID (depending on sign-in method)
- Content: notes, tags, comments, messages, and any other content you create
- Profile information: bio, preferences, settings
1.2 Information Collected Automatically
When you use Conoted, we automatically collect:
- Usage data: features used, pages visited, interactions with content
- Device information: device type, operating system, app version
- Technical data: IP address, time zone, crash reports, performance metrics
1.3 Information from Integrations
If you connect third-party services (Telegram, Slack, Gmail, phone contacts), we collect:
- Telegram: messages from channels/groups you specify, user handles, message timestamps
- Slack: messages from workspaces you authorize, user identifiers, channels
- Gmail: contact names and email addresses (not email content)
- Phone contacts: names, phone numbers, emails from your device contacts (only if you grant permission)
1.4 Information About Other People
Through Telegram/Slack integration, we may store information about users who are not Conoted members. These are called "ghost users" and contain:
- Public username and display name (from the source platform)
- Messages they posted in channels you parse
- Associations with topics and groups
Ghost users have specific rights — see Section 8.
2. How We Use Your Information
We use your information to:
2.1 Provide and Improve the Service
- Create and maintain your account
- Display your content and connections
- Generate AI-powered features (digests, tags, recommendations)
- Personalize your experience
- Fix bugs and improve performance
2.2 Communication
- Send important account notifications (security, subscription changes)
- Respond to support requests
- Send promotional messages (you can opt out)
2.3 Safety and Legal Compliance
- Detect and prevent fraud or abuse
- Comply with legal obligations
- Protect the rights of users and the Developer
3. AI Processing
Conoted uses AI to power key features. Your content may be sent to the following AI providers for processing:
| Provider | Purpose | Data Sent |
|---|---|---|
| OpenAI (ChatGPT) | Tag clustering, contact recommendations | Notes text, tags, user activity metadata |
| Google Gemini | Digest generation, summarization | Messages from parsed channels |
What exactly is sent
For a digest, each source message is sent as: its text (and, for voice or video notes, the transcription we generated), the author's public @username, the title and public link of the chat or channel it came from, its timestamp, and a marker showing which message it replied to. Nothing else about you travels with it — no email, no phone number, no contact list, no device identifier.
For tagging and note-linking, we send the text and tags of the note being processed and the tags already present on your account, so the model can match them.
For lead filters, we send the text of messages from the chats the filter watches together with the criteria you set.
What the providers do with it
- We do not train models on your content, and we do not permit providers to. Under the standard API terms of OpenAI, Anthropic and Google, content submitted through the API is not used to train their models.
- Providers do retain it briefly. Each keeps API inputs for a limited period — typically up to 30 days — for abuse monitoring, then deletes them. This is their retention, not ours, and it applies to every API customer.
- We do not have an enterprise zero-retention agreement. We are stating this plainly rather than implying stronger protection than we have. If that changes, this section changes with it.
- Requests are made over TLS from our servers. Your device never talks to an AI provider directly.
You can ask us to exclude your account from AI features by contacting support. Some features stop working without them — digests and tag suggestions in particular.
AI providers have their own privacy policies:
- OpenAI: https://openai.com/privacy/
- Google Gemini: https://policies.google.com/privacy
4. Third-Party Services
We use the following third parties to operate Conoted:
| Service | Purpose | Data Shared |
|---|---|---|
| Firebase (Google) | Analytics, crash reporting | Usage patterns, crash logs, device info |
| Sentry | Error tracking | Error logs, stack traces, device info |
| OneSignal | Push notifications | Device tokens, notification preferences |
| Apple Sign-In | Authentication | Apple ID, email (if shared) |
| Google Sign-In | Authentication | Email, name, avatar |
| Telegram | Account connection, parsing | Telegram user ID, messages (if authorized) |
| Apple App Store / Google Play | Billing | Purchase information |
| Hosting (server infrastructure) | Service operation | All user data (encrypted at rest) |
Each provider has its own privacy policy. Review them before using Conoted.
Crash reports and product analytics
The mobile app sends crash reports to Firebase Crashlytics and Sentry, and usage events to Firebase Analytics. Concretely that means: the stack trace of the failure, the app version, the device model and OS version, and an install identifier generated by the SDK. Which screens you opened is recorded as event names; the contents of your notes are not sent, and neither is your email or name.
These records are keyed to an install, not to you by name. They are not linked to your Conoted account, so a crash report cannot be traced back to your identity by whoever reads it.
How long they are kept, using each provider's configured window:
- Firebase Crashlytics: crash reports are kept for 90 days
- Firebase Analytics: event data is kept for 2 months
- Sentry: error events are kept for 90 days
Server-side error tracking via Sentry is currently not enabled — our backend sends nothing there.
We do not use any of this for advertising, and we do not sell or share it with data brokers.
5. How Your Content Is Shared
Conoted is designed for both private and collaborative use. Your content is shared based on visibility settings:
5.1 Private Notes (Default)
Visible only to you. Not shared with other users, displayed on public feeds, or used in recommendations.
5.2 Group Notes
Visible to members of the group where posted. Not visible to non-members.
5.3 Public Notes
Visible to ALL registered Conoted users, including future users. When you publish a note as public:
- Your full content, name, and tags become searchable and visible in the platform
- Your note may appear in other users' "For You" recommendations (if tag matches)
- Other users may copy, screenshot, or reference your note
Before publishing, you see a clear warning explaining the scope of publication.
5.4 Digests
Digests generated from group content are visible only to group members. They include summaries and contributor mentions. External channels/groups you parse are not made publicly visible — only summaries seen by your group members.
5.5 Recommendations (Expert Finder)
Conoted may recommend you to other users as an "expert" in topics based on your activity. You can:
- Opt out of expert recommendations in Settings
- Hide your profile from non-members
- Request deletion of your expertise data
6. Data Retention
We retain your data:
- Active accounts: for as long as you use the Service
- Deleted accounts: content is removed within 30 days
- Backups: may persist in encrypted backups for up to 90 days
- Legal requirements: certain data retained longer when required by law
On Your Device
Two things live on your phone, not on our servers.
Your sign-in credentials are held in the platform's secure store — the iOS Keychain or the Android Keystore — never in ordinary app files. That is the access token, its expiry, and your user id. On iOS the entry is readable only after the device has been unlocked once since boot.
An offline copy of your own content is held in a local database so the app opens and works without a connection: your notes, the people you have in the app, and a queue of changes waiting to sync.
What happens when you leave:
- Signing out erases the credentials from the secure store immediately. The offline copy of your notes is left in place, so that signing back in on the same device does not have to re-download everything.
- Deleting the app removes both — the credentials and the offline database go with the app's storage.
If you want the offline copy gone without deleting the app, sign out and then delete the app; or ask support to confirm deletion of the server-side data, which is what Section 7.3 covers.
Public Notes
If you made notes public, they may persist in other users' viewed history, screenshots, or archives even after you delete your account. We cannot remove content that others have saved independently.
Ghost Users
Data about non-Conoted users (from Telegram/Slack parsing) is retained as long as:
- Their referenced content is still in our system
- Their referenced groups are still active
Ghost users can request deletion — see Section 8.
7. Your Rights (Including GDPR Rights)
You have the right to:
7.1 Access
Request a copy of the personal data we hold about you.
7.2 Correction
Update incorrect or incomplete information in your profile settings.
7.3 Deletion
Delete your account and associated data. You can:
- Close your account in Settings
- Request full data deletion by emailing support@conoted.com
7.4 Data Portability
Request your data in a machine-readable format (JSON export).
7.5 Restriction
Request that we limit how we use your data.
7.6 Objection
Object to processing based on legitimate interests (e.g., analytics, recommendations).
7.7 Withdraw Consent
If you previously consented to specific data use, you may withdraw consent at any time.
7.8 Complaint
File a complaint with your local data protection authority if you believe we're misusing your data.
To exercise any of these rights, contact us at support@conoted.com. We will respond within 30 days.
8. Rights of Ghost Users
If you are NOT a Conoted user but your data appears in our system (due to being referenced in public Telegram channels parsed by our users), you have these rights:
- Deletion: You can request complete removal of your data from Conoted
- Objection: You can request that your name/content not appear in any Conoted feature
Contact: support@conoted.com with:
- Your Telegram username or display name
- Source channel where you appeared
- Reason for request (optional)
We will process within 14 days and notify you when complete.
9. Children's Privacy
Conoted is intended for users 13 and older. We do not knowingly collect personal information from children under 13.
If we learn we have collected data from a child under 13, we will delete it immediately. Parents or guardians who believe their child has provided us with information should contact support@conoted.com.
10. International Data Transfers
Conoted operates globally. Your data may be transferred to and processed in countries outside your country of residence, including countries that may have different data protection laws.
When transferring data from the EU/EEA to third countries, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Other legally-recognized transfer mechanisms
11. Data Security
We implement industry-standard measures to protect your data:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for sensitive data
- Regular security audits
- Access controls and authentication
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
In case of a data breach affecting your personal information, we will notify you within 72 hours of discovery, as required by applicable law.
12. Cookies and Tracking
We use:
- Essential cookies: required for the Service to function (authentication, session management)
- Analytics cookies: to understand usage patterns (can be disabled)
- No advertising cookies: we do not show ads
You can manage cookies through your browser settings.
13. Marketing Communications
We may send you:
- Service announcements (required, cannot opt out)
- Product updates and tips (can opt out)
- Promotional offers (can opt out)
Opt-out options are available in Settings → Notifications or by following the unsubscribe link in emails.
14. Changes to This Privacy Policy
We may update this Privacy Policy. Changes will be communicated:
- Via email for material changes
- Via in-app notification
- By posting at conoted.com/privacy with updated "Effective Date"
Continued use of the Service after changes constitutes your acceptance.
15. Contact Information
Data Controller:
Streltsov Company D.O.O.
Dubovica bb, 85310 Budva, Montenegro
Contact:
- Email: support@conoted.com
- Website: https://conoted.com
This Privacy Policy was last updated on June 3, 2026.