Last Updated: April 29, 2026 Effective Date: April 29, 2026 Version: 2.0

CffeaNote (the "App") is designed with your privacy as the highest priority. The App collects only the minimum amount of personal information and never sells your data or uses it for advertising purposes.

This Privacy Policy is prepared in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), Japan's Act on the Protection of Personal Information (APPI), and applicable data protection laws of other jurisdictions.

Note: In case of any discrepancy between this English version and the Japanese original, the Japanese version shall prevail.

Table of Contents
  1. Data Controller
  2. Information We Collect
  3. Purposes of Use
  4. Legal Basis (GDPR)
  5. Where Data Is Stored
  6. International Data Transfers
  7. Sharing with Third Parties
  8. Data Retention
  9. Your Rights
  10. Right to Lodge a Complaint (EU/EEA)
  11. California Residents (CCPA / CPRA)
  12. Japan (APPI)
  13. Security Measures
  14. Advertising, Analytics & Tracking
  15. Children's Privacy
  16. Cookies
  17. Changes to this Policy
  18. Contact Us

1. Data Controller

The App is operated by an independent developer. We have not appointed an EU representative under GDPR Article 27, as the scale of our data processing falls below the threshold requiring such an appointment. Users in the EU/EEA may contact us directly via the email address above.

2. Information We Collect

2.1 Information processed within the App

The following content, entered by users, is stored on the user's device and (if signed in to iCloud) in the user's own iCloud account:

The App does not collect your name, email address, location, device identifiers, usage analytics, or advertising IDs.

2.2 Information from email inquiries

When you contact us via email, we receive the following:

This website does not use any contact forms, analytics tools, or third-party scripts. All inquiries are sent directly from your own email client.

3. Purposes of Use

4. Legal Basis for Processing (GDPR / EU/EEA Users)

For users in the EU/EEA, we process personal data on the following legal bases (GDPR Article 6(1)):

5. Where Data Is Stored

6. International Data Transfers

Personal data of users in the EU/EEA or the UK may be transferred to Japan, the United States, or other countries through iCloud sync or email correspondence with the developer.

7. Sharing with Third Parties

We do not sell or share personal data with third parties. We do not provide data to advertising networks, analytics providers, or data brokers.

Apple iCloud / CloudKit serves as infrastructure to store the user's own data in the user's own iCloud account; the developer cannot view that data.

8. Data Retention

9. Your Rights

Subject to applicable law, you have the following rights:

Because the App is designed so that you control your own data, most of these rights can be exercised directly within the App and iOS Settings. For other requests, please contact us via the Contact page. We will respond within 30 days (or within one month, extendable up to three months, where GDPR applies). No fee is charged for exercising your rights, except for manifestly unfounded or excessive requests.

10. Right to Lodge a Complaint (EU/EEA Users)

If you are located in the EU/EEA and have concerns about how we handle your personal data, you have the right to lodge a complaint with the Data Protection Authority (DPA) in your country. A list of DPAs is available on the European Data Protection Board members page.

11. California Residents (CCPA / CPRA)

California residents have the following rights under the CCPA / CPRA:

Do Not Sell or Share My Personal Information: We do not sell or share your personal information. We do not share data for cross-context behavioral advertising.

Under the CCPA, the categories of personal information we collect are limited to "identifiers (email)" and "commercial information (inquiry content)". We have not sold or shared this information in the preceding 12 months.

12. Japan (APPI)

13. Security Measures

We protect user data using the iOS security features (App Sandbox, file encryption) and Apple iCloud security features (encryption in transit and at rest). The developer has no means of accessing your in-App data directly.

This website is served over HTTPS via GitHub Pages.

14. Advertising, Analytics & Tracking

15. Children's Privacy

The App is not intended for children under the age of 13 (or up to 16 in certain EU/EEA Member States). We do not knowingly collect personal information from individuals in this age group. If we receive such information by mistake, we will promptly delete it after verification.

16. Cookies

This website does not use cookies or any similar tracking technologies (local storage, web beacons, fingerprinting, etc.).

17. Changes to this Policy

We may update this Privacy Policy in response to changes in laws, App functionality, or our operations. When we make material changes, we will update the "Last Updated" date at the top of this page and notify users in the App's release notes.

18. Contact Us

If you have questions about this Privacy Policy, would like to exercise your rights, or have any feedback, please contact us: