Steel Notes Privacy Policy
This Privacy Policy explains how Pitts Ventures LLC ("we," "us," or "our") collects, uses, discloses, and protects personal information when you use the Steel Notes mobile application, website, cloud-sync service, and related features (collectively, the "Service").
1. Who we are
Steel Notes is operated by Pitts Ventures LLC, a Florida limited liability company. You can contact us at admin@steelnotes.app.
2. Where the Service is available
The Service is currently offered only in the United States and Canada. It is not intended for users in the European Economic Area, the United Kingdom, or other jurisdictions where we have not made the Service available.
Our primary cloud infrastructure is in the United States. If you use the Service from Canada, your personal information will be transferred to and processed in the United States and may be accessible to courts, law enforcement, and governmental authorities under applicable US law.
3. Information we collect
Account and authentication information. Depending on how you sign in, we collect:
- Your email address, optional display name, and internal user ID.
- For email accounts, a cryptographic hash of your password. We do not store your plaintext password.
- For Sign in with Apple, Apple's stable account identifier and, when Apple provides it, your email address or private relay address. We receive an identity token to authenticate the sign-in but do not receive your Apple Account password.
- Six-digit email verification and password-reset codes. Codes expire after 15 minutes.
- Records showing the version of the Terms and Privacy Policy you accepted, the acceptance time and signup method, and the IP address supplied by our API gateway.
- Short-lived access tokens and randomly generated refresh tokens. Refresh tokens are stored on our servers only as cryptographic hashes and normally expire after 30 days.
Device and sync information. We collect a device name, platform, device identifier, last activity time, and, when available, an Apple push-notification token. We also store sync metadata such as file versions, content hashes, sizes, deletion status, timestamps, and the device responsible for a change. Vault paths are encrypted in the database and represented by keyed hashes in storage object names.
Your content. Depending on how you use Steel Notes, we store and process:
- Notes and imported content, including Markdown text, frontmatter, folders, links, and tags.
- Images, photographs, PDFs, audio recordings, and other attachments.
- Web clips, source URLs, article text and images, and book information you choose to save.
- AI prompts and preferences, transcripts, extracted quotes, generated metadata, model identifiers, and other AI-generated results.
The Service is not end-to-end encrypted. Your cloud content is encrypted in transit and at rest, but our cloud systems and the service providers described below can process it when necessary to sync your vault or perform a feature you request.
AI usage and operational information. For AI requests, we record the user and capture identifiers, provider and model used, operation type, request time, token counts, cached-token counts, audio duration, source system, and estimated cost. We also retain limited information about failed AI jobs so that they can be displayed and retried. We do not intentionally put note text, transcripts, images, or complete AI responses in application logs.
Subscription and entitlement information. We receive and store information from Apple needed to validate and administer subscriptions, including product and transaction identifiers, subscription status, renewal status, current period end, and signed transaction or server-notification data. We also store trial start and extension dates and whether an account has complimentary access.
Support and administrative records. If you contact us, we collect the information in your message. Authorized operators can view account, entitlement, storage, device, failed-job, and aggregated AI-usage information in a private administrative console. Changes to trial or billing controls are recorded with the operator, reason, time, target user ID, request ID, and the safe before-and-after billing values. The console does not expose note contents, attachments, passwords, authentication tokens, or raw AI output.
Technical logs. Our infrastructure records information needed to secure, operate, and debug the Service, such as request identifiers, times, routes, response status and latency, user or capture identifiers, opaque storage object identifiers, file sizes, processing durations, and error details. API gateway access logs are deliberately configured not to include request paths, query strings, headers, or note content.
What we do not collect. We do not use third-party advertising, attribution, behavioral analytics, or crash-reporting SDKs. We do not collect advertising identifiers, sell personal information, or track you across unrelated apps or websites for advertising.
4. How we use information
We use information to:
- Create, authenticate, secure, and support accounts.
- Sync and restore vault content across your devices.
- Process captures, transcription, extraction, metadata, and other AI features you request.
- Look up book metadata and covers when you request those features.
- Deliver transactional email and service notifications.
- Determine trials, subscriptions, complimentary access, and other entitlements.
- Measure provider usage and cost, diagnose failed work, prevent abuse, enforce limits, and maintain the Service.
- Respond to support, privacy, legal, and security requests.
- Keep an audit trail of sensitive operator changes.
We do not use your content to train our own AI models, use it for advertising, or intentionally opt your content into an AI provider's model-training program.
5. AI and automated processing
Steel Notes offers both on-device and cloud processing options:
- On-device processing. If you select Apple Vision OCR, image recognition for that operation occurs on your device rather than through a cloud AI model. The App may also use Apple's on-device Foundation Models to suggest a title. Content you later sync is still stored in our AWS infrastructure.
- Cloud image and text processing. Depending on your selected preference, account default, availability, or an automatic fallback after an error or unusable response, content may be processed by Anthropic Claude through Amazon Bedrock, Google's Gemini API, or OpenAI's API. A fallback can send the same submitted content to another listed provider.
- Voice transcription. Audio submitted for cloud transcription is processed by Amazon Transcribe.
AI output can be inaccurate, incomplete, or inappropriate. Steel Notes stores the provider/model identifier with AI-generated content where available so the result remains traceable.
We use provider API and business services rather than consumer chat products. Provider handling and temporary retention are governed by their terms and data controls. Amazon states that Bedrock model providers do not receive customer prompts or completions; OpenAI states that API inputs and outputs are not used for training by default; and Google's paid Gemini API terms state that prompts and responses are not used to improve its products. Those providers may still process or temporarily retain data for security, abuse prevention, legal compliance, or service operation.
6. Storage and international transfers
Our primary account database, file storage, queues, and application processing run on Amazon Web Services in the United States, principally the us-east-1 region. Amazon Bedrock may route inference among supported US AWS regions. Google, OpenAI, Apple, Resend, Cloudflare, and other providers listed below may process information in the United States or other places where they operate.
On your device, the App stores vault files and a local SQLite index in its sandbox or app group, and stores authentication credentials in the Apple Keychain. We do not use iCloud or CloudKit to sync your vault.
When you request book metadata or covers, the App sends an ISBN or search terms such as title and author directly to Google Books or Open Library. When you open a source link, import remote media, or clip a web page, your device communicates with that third-party website, which receives ordinary network information such as your IP address and may apply its own privacy policy.
7. Retention and deletion
- Account, device, entitlement, subscription, acceptance, and AI-usage records: retained while your account exists, unless a longer period is required for security, legal, tax, or dispute-resolution purposes.
- Active notes and attachments: retained until you delete them or delete your account.
- Deleted vault files: moved to server-side trash and automatically deleted after approximately 30 days. Sync tombstones are retained for approximately 90 days so deletions can propagate to other devices.
- Voice audio: deleted from our cloud storage after successful transcription and durable creation of the result. If processing fails, it may remain so you can retry, until the job or account is deleted.
- Intermediate AI result files: deleted after the result is consumed or automatically after approximately 30 days. Final content saved into a note remains with that note.
- Verification and reset records: codes expire after 15 minutes. Associated records are removed when used, replaced, invalidated, or cleaned from our systems.
- Refresh tokens: normally expire after 30 days and are removed when rotated, invalidated, expired and cleaned, or the account is deleted.
- Technical logs: AWS Lambda and API Gateway logs are configured for approximately 30 days of retention.
- Administrative audit records: retained to preserve the integrity of the operator audit trail. They contain a user ID and limited billing-control history, are not automatically removed when the target account is deleted, and do not contain note content or credentials.
When an authenticated account-deletion request succeeds, Steel Notes deletes that user's S3 objects and active account records, including content, devices, authentication providers, refresh tokens, subscription data, prompts, AI-usage records, and failed-job records. Database information may remain in encrypted backups for up to seven additional days before being overwritten. Limited administrative audit, security, transaction, or legal records may be retained as described above. Copies held by Apple or another provider are governed by that provider's retention rules.
Deleting the App does not delete your cloud account or subscription. Cancel any subscription through Apple and use the in-app account-deletion control or contact us.
8. When we disclose information
We disclose information only as needed to operate the Service, at your direction, or for legal and security reasons. Current service providers include:
| Provider | Purpose |
|---|---|
| Apple Inc. | Sign in with Apple, StoreKit purchases and subscriptions, App Store distribution, device services, and APNs push tokens/delivery |
| Amazon Web Services | Database, file storage, API and worker compute, queues, monitoring, push infrastructure, Amazon Transcribe, and Amazon Bedrock AI inference |
| Anthropic | Claude models made available through Amazon Bedrock; AWS states model providers do not receive Bedrock customer prompts or completions |
| Google LLC | Gemini AI processing and Google Books metadata and cover lookup |
| OpenAI, L.L.C. | Optional OpenAI API image and text processing |
| Plus Five Five, Inc. (Resend) | Account verification, password-reset, and other transactional email |
| Cloudflare, Inc. | DNS and security for the private administrative site, including authentication and proxying of limited account and billing information |
| Internet Archive / Open Library | Book metadata and cover lookup requested from the App |
We may also disclose information to professional advisers, authorities, or other parties when reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, or security incidents; protect users or the public; enforce our agreements; or complete a merger, financing, acquisition, reorganization, or sale of assets with appropriate protections.
We do not sell personal information or share it for cross-context behavioral advertising.
9. Your choices and privacy rights
AI choice. You can choose an available model in Settings, including an on-device OCR option where supported. Do not submit content to a cloud AI feature if you do not want it processed by the cloud providers described above.
Access and export. You can export a Markdown copy of the vault content and locally available attachments on your device. You may also contact us to request access to other personal information associated with your account.
Correction. You can change your display name in the App. Contact us to request correction of other inaccurate account information.
Deletion. You can delete individual items in the App. To delete your account and cloud content, open Settings, choose Delete Account, and confirm. You may also request deletion by emailing admin@steelnotes.app from the address associated with your account. Because deleting the App alone does not cancel an Apple subscription, manage the subscription separately in your Apple Account settings.
Privacy requests. Depending on where you live, you may have rights to know or access, correct, delete, or obtain a copy of personal information, and to appeal or complain about our response. California residents may also have rights to opt out of sale or sharing and limit certain uses of sensitive personal information; Steel Notes does not sell personal information or share it for cross-context behavioral advertising. Canadian residents may request access to and correction of personal information and may withdraw consent subject to legal or contractual restrictions and reasonable notice.
Send requests to admin@steelnotes.app. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising an applicable privacy right.
10. Security
We use administrative, technical, and physical safeguards designed to protect information, including TLS in transit, encryption at rest in AWS, private S3 access, Argon2id password hashing, SHA-256 refresh-token hashing, short-lived access tokens, encrypted vault paths, opaque storage keys, least-privilege access controls, and audit logging for sensitive operator actions.
No system is perfectly secure. Steel Notes is not end-to-end encrypted, and we cannot guarantee absolute security. Keep your account and devices secure and contact us if you believe your account has been compromised.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us and we will take appropriate steps to delete it.
Users who are at least 13 but below the age of majority where they live may use the Service only with permission from a parent or legal guardian.
12. Changes to this policy
We may update this policy as the Service or law changes. If a change is material, we will provide notice in the App, by email, or through another reasonable method before it takes effect where required. The dates at the top identify the current version.
13. Contact
Pitts Ventures LLC
719 North Rd
Jupiter, FL 33458
United States
admin@steelnotes.app