Privacy Policy
Last updated August 4, 2026
This Privacy Notice for BookNote, a sole proprietorship (eenmanszaak) operated by Maciej Daszkiewicz, registered with the Dutch Chamber of Commerce (KVK) under number 42004864, VAT ID NL005427564B33 ("we," "us," "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Download and use our mobile application (BookNote), or any other application of ours that links to this Privacy Notice
- Use BookNote. BookNote is a personal reading companion app that helps users take meaningful notes on the books they read. It allows users to save insights, track reading progress, organize their notes by book, and reflect on what they’ve learned. Notes are stored securely on-device and synced through iCloud if enabled.
- Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@booknote.app.
Summary of Key Points
This summary provides key points from our Privacy Notice, but you can find details in the Table of Contents below.
- What personal information do we process? It depends on how you interact with us and the Services and the choices you make.
- Do we process any sensitive personal information? We do not process sensitive personal information.
- Do we collect information from third parties? We do not collect information from third parties.
- How do we process your information? To provide, improve, and administer our Services; communicate with you; for security/fraud prevention; and to comply with law.
- When and with whom do we share information? In specific situations and with specific third parties.
- How do we keep your information safe? Organizational and technical measures, but no method is 100% secure.
- What are your rights? Depends on your location.
- How do you exercise your rights? Submit a data subject access request or contact us.
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE PROCESS YOUR INFORMATION?
- WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
- WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
- DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- CONTROLS FOR DO-NOT-TRACK FEATURES
- DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
- HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
1. What Information Do We Collect?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you express interest in our products and Services, participate in activities on the Services, or otherwise contact us.
Personal Information Provided by You.
- Email addresses
Sensitive Information. We do not process sensitive information.
Payment Data. If you make purchases, payment data (e.g., instrument number and security code) is handled and stored by Apple. See: https://www.apple.com/legal/privacy/
Application Data. If you use our application(s), and you grant access/permission:
- Mobile Device Access. Camera, microphone, reminders, sensors, and other features (modifiable in device settings).
- Mobile Device Data. Device ID, model, manufacturer, OS and version, system configuration, app IDs, browser type/version, hardware model, ISP/carrier, IP address (or proxy), phone network, and features accessed.
- Push Notifications. We may send push notifications (you can turn them off in device settings).
This information is primarily needed to maintain security and operation of our app(s), for troubleshooting, and for internal analytics/reporting.
All personal information you provide must be true, complete, and accurate. Notify us of changes.
Information automatically collected
In Short: Some information—such as IP address and/or browser and device characteristics—is collected automatically when you visit our Services.
We automatically collect device and usage information (e.g., IP address, browser/device characteristics, OS, language preferences, referring URLs, device name, country, location, usage timestamps, pages/files viewed, searches, feature usage, system activity, error reports, hardware settings). We also use cookies and similar technologies.
Examples:
- Log and Usage Data. Diagnostic, usage, and performance information recorded in log files.
- Device Data. Details about the device used to access the Services (IP/proxy, app IDs, location, browser type, hardware model, ISP/carrier, OS, configuration).
2. How Do We Process Your Information?
In Short: To provide, improve, and administer our Services; communicate with you; ensure security and fraud prevention; and comply with law. We may also process your information for other purposes with your prior explicit consent.
Examples:
- Deliver services. Provide requested service.
- Support. Respond to inquiries and resolve issues.
- Admin messages. Send product/service details, policy/terms changes, and similar info.
- Orders. Fulfill and manage orders, payments, returns, and exchanges.
- Feedback. Request feedback and contact you about your use of the Services.
- Marketing. Send marketing/promotional communications per your preferences (opt out anytime).
- Targeted advertising. Develop and display personalized content/ads.
- Protect Services. Fraud monitoring and prevention.
- Usage trends. Understand usage to improve Services.
- Campaign effectiveness. Measure and improve promotions.
- Vital interests. Prevent harm where necessary.
3. What Legal Bases Do We Rely on to Process Your Information?
In Short: We process your personal information only when we have a valid legal reason (legal basis) under applicable law—e.g., consent, compliance with laws, contractual necessity, protection of rights, or legitimate interests.
If you are located in the EU or UK: under GDPR/UK GDPR, we may rely on:
- Consent. You can withdraw at any time. See: Withdrawing your consent.
- Performance of a Contract. To fulfill contractual obligations or at your request before entering a contract.
- Legitimate Interests. Where reasonably necessary and not overridden by your rights—for example:
- Send information about offers/discounts
- Develop and display personalized, relevant advertising
- Analyze Service usage to improve engagement/retention
- Support marketing activities
- Diagnose problems and/or prevent fraud
- Understand usage to improve user experience
- Legal Obligations. Compliance with legal duties (e.g., cooperate with regulators, defend legal rights, provide evidence).
- Vital Interests. Protect your vital interests or those of others (e.g., safety threats).
If you are located in Canada: we may rely on express or implied consent. You may withdraw consent at any time. In limited cases, applicable law permits processing without consent, including (illustrative):
- Where collection is clearly in an individual’s interests and consent cannot be obtained in time
- Investigations; fraud detection/prevention
- Certain business transactions (subject to conditions)
- Witness statements for insurance claims
- Identifying injured/ill/deceased persons and contacting next of kin
- Reasonable grounds of financial abuse
- Where obtaining consent would compromise availability/accuracy for breach-of-law investigations
- Compliance with subpoena/warrant/court order
- Information produced in employment/business/professional context consistent with its purpose
- Journalistic/artistic/literary purposes
- Publicly available information specified by regulation
- Disclosure of de-identified information for approved research/statistics (with ethics/confidentiality safeguards)
4. When and With Whom Do We Share Your Personal Information?
In Short: We may share information in specific situations and/or with specific third parties.
Situations include:
- Business Transfers. In connection with, or during negotiations of, a merger, sale of assets, financing, or acquisition of all or part of our business.
- Analytics Service Providers. We share usage data with PostHog (PostHog Inc.) to analyze app usage and improve our Services. PostHog processes data on servers located in the EU. Privacy: https://posthog.com/privacy
5. Do We Use Cookies and Other Tracking Technologies?
In Short: We may use cookies and similar technologies to collect and store information.
These technologies help maintain security, prevent crashes, fix bugs, save preferences, and support basic functions. We may allow third parties/service providers to use tracking technologies for analytics and advertising (including managing/serving ads, tailoring ads to your interests, and sending cart reminders subject to your communication preferences).
To the extent these technologies are deemed a “sale”/“sharing” under certain US state laws (including targeted advertising), you can opt out as described in US residents’ rights.
Specific details may be set out in our Cookie Notice.
Firebase Analytics
We may use Firebase Analytics (a Google service) to track and analyze use of the Services, such as feature usage, session completion, and app interactions. This data is collected anonymously. Privacy: https://policies.google.com/privacy
PostHog Analytics
We use PostHog to track and analyze use of the Services, such as feature usage, onboarding completion, reading sessions, and app interactions. Data is collected with an anonymous device identifier and stored on EU servers. Privacy: https://posthog.com/privacy
6. How Long Do We Keep Your Information?
In Short: We keep information as long as necessary for the purposes outlined in this Notice unless otherwise required by law.
When no ongoing legitimate business need exists, we delete or anonymize information. If deletion is not possible (e.g., backups), we securely store and isolate it until deletion is possible.
7. How Do We Keep Your Information Safe?
In Short: We use organizational and technical measures to protect personal information.
Despite safeguards, no electronic transmission or storage technology is 100% secure. Transmission of personal information to and from our Services is at your own risk. Access the Services within a secure environment.
8. Do We Collect Information From Minors?
In Short: We do not knowingly collect data from or market to children under 18 (or the equivalent age in your jurisdiction), nor do we knowingly sell such personal information.
By using the Services, you represent that you are at least 18 (or the equivalent age) or that you are the parent/guardian and consent to the minor’s use. If we learn we collected data from users under 18 (or equivalent), we will deactivate the account and delete the data. Report concerns to info@booknote.app.
9. What Are Your Privacy Rights?
In Short: Depending on your location (e.g., EEA, UK, Switzerland, Canada, certain US states), you may have rights to access, correct, delete, restrict processing, data portability, object, and avoid solely automated decision-making with legal/similarly significant effects. Where decisions are solely automated, we will inform you, explain key factors, and provide a way to request human review.
We will act on requests consistent with applicable laws.
- EEA/UK: You may complain to your Member State DPA or the UK ICO: https://ico.org.uk/make-a-complaint/.
- Switzerland: Contact the FDPIC.
Withdrawing your consent. Where processing relies on consent (express or implied), you may withdraw at any time by contacting us (see Contact). This does not affect processing prior to withdrawal or processing on other lawful grounds.
Opting out of marketing. Unsubscribe via links in emails or contact us. We may still send non-marketing communications (e.g., service, support).
Cookies and similar technologies. Most browsers accept cookies by default. You can remove or reject cookies, but some features may be affected.
Questions about your rights: info@booknote.app.
10. Controls for Do-Not-Track Features
Most browsers and some mobile OS/apps include a Do-Not-Track (DNT) setting. No uniform standard exists for recognizing/implementing DNT signals, so we do not currently respond to DNT signals. If a standard is adopted that we must follow, we will update this Notice. California law also requires disclosure of our response to DNT signals; we do not respond at this time.
11. Do United States Residents Have Specific Privacy Rights?
In Short: If you are a resident of CA, CO, CT, DE, FL, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA, you may have rights to access details about the personal information we maintain and how we processed it, correct inaccuracies, obtain a copy, delete it, and/or withdraw consent. These rights may be limited by law.
Categories of Personal Information We Collect (last 12 months)
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Real name, alias, postal address, phone number, unique identifier, online identifier, IP address, email address, account name | YES |
| B. Customer Records (CA) | Name, contact info, education, employment, employment history, financial info | NO |
| C. Protected classifications | Gender, age, DOB, race/ethnicity, national origin, marital status, other demographics | NO |
| D. Commercial information | Transactions, purchases, financial/payment details | NO |
| E. Biometric information | Fingerprints, voiceprints | NO |
| F. Internet/network activity | Browsing/search history, online behavior/interactions with our/others' sites/apps/ads | YES |
| G. Geolocation data | Device location | NO |
| H. Audio/electronic/sensory | Images; audio, video, or call recordings created for business activities | NO |
| I. Professional/employment | Business contact details, job title, work history, qualifications (if you apply) | NO |
| J. Education information | Student records, directory info | NO |
| K. Inferences | Profiles/summaries about preferences/characteristics | NO |
| L. Sensitive personal information | — | NO |
We may also collect personal information outside these categories when you interact with us (support, surveys/contests, delivery of Services, responding to inquiries).
Retention examples:
- Category A — until the user requests deletion or unsubscribes from communications.
Sources of Personal Information
See: What information do we collect?
How We Use and Share Personal Information
See: How we process your information
Will your information be shared with anyone else?
We may disclose personal information to service providers under written contracts. See: Sharing.
We may use personal information for our own business purposes (e.g., internal research/technology development/demonstration). This is not a “sale.”
We have not disclosed, sold, or shared personal information to third parties for business or commercial purposes in the preceding 12 months, and we will not sell or share such information of visitors, users, or consumers.
Your Rights (US states)
You may have the rights to:
- Know whether we process your personal data
- Access your personal data
- Correct inaccuracies
- Delete your personal data
- Obtain a copy of data you provided
- Non-discrimination for exercising rights
- Opt out of targeted advertising (or “sharing” under CA law), sale of personal data, or profiling in furtherance of decisions with legal/similarly significant effects
Depending on your state, you may also have rights to:
- Access categories of personal data processed (e.g., MN)
- Obtain a list of categories of third parties to whom we disclosed data (e.g., CA, DE, MD)
- Obtain a list of specific third parties to whom we disclosed data (e.g., MN, OR)
- Review/understand/correct profiling (e.g., MN)
- Limit use/disclosure of sensitive personal data (e.g., CA)
- Opt out of collection of sensitive data and personal data via voice/facial recognition features (e.g., FL)
How to Exercise Your Rights
Submit a data subject access request, email info@booknote.app, or use the contact details below.
You may designate an authorized agent to act on your behalf. We may deny a request from an agent lacking proof of valid authorization.
Request Verification
We must verify your identity before acting on a request. We will use the information provided only for verification/security/fraud-prevention. If we cannot verify you with existing data, we may request additional information. For agent-submitted requests, we may need (i) identity verification and (ii) your written, signed permission.
Appeals
If we decline your request, you may appeal by emailing info@booknote.app. We will provide a written explanation. If denied, you may complain to your state attorney general.
California “Shine The Light” (Civ. Code §1798.83)
California residents may request, once per year and free of charge, information about categories of personal information (if any) disclosed to third parties for direct marketing and the names/addresses of such third parties for the preceding calendar year. Submit requests using the contact details in Contact.
12. Do Other Regions Have Specific Privacy Rights?
In Short: You may have additional rights based on your country of residence.
Australia and New Zealand
We collect/process personal information under Australia’s Privacy Act 1988 and New Zealand’s Privacy Act 2020. This Notice satisfies the Acts’ requirements (what we collect, sources, purposes, recipients).
If you do not provide information necessary for its purpose, it may affect our ability to provide services, e.g., to:
- Offer requested products/services
- Respond to/help with your requests
You may request access to or correction of your personal information at any time (see Review/Update/Delete).
Complaints:
- Australia — OAIC
- New Zealand — Privacy Commissioner
Republic of South Africa
You may request access to or correction of your personal information at any time (see Review/Update/Delete).
If unsatisfied with how we handle a complaint, contact the regulator:
- Information Regulator (South Africa) — https://inforegulator.org.za/
- General enquiries: enquiries@inforegulator.org.za
- Complaints (POPIA/PAIA Form 5): PAIAComplaints@inforegulator.org.za & POPIAComplaints@inforegulator.org.za
13. Do We Make Updates to This Notice?
In Short: Yes. We will update this Notice as necessary to remain compliant with relevant laws.
The updated version will be indicated by an updated “Revised” date at the top. If we make material changes, we may notify you by prominently posting a notice or by sending you a notification. Review this Notice periodically to stay informed.
14. How Can You Contact Us About This Notice?
If you have questions or comments, email info@booknote.app or contact us by post at:
Maciej DaszkiewiczBinckhorstlaan 313A
The Hague, South Holland 2516BC
Netherlands
KVK: 42004864
BTW: NL005427564B33
15. How Can You Review, Update, or Delete the Data We Collect From You?
Depending on your country/state of residence, you may have rights to request access to the personal information we collect, details on how we processed it, corrections, deletion, or to withdraw consent (subject to legal limits). To submit a request, use our data subject access request.