Privacy Policy
Effective Date: August 29, 2026
The short version: Notre prefers direct nearby delivery. In normal mode, it can use Google Firebase to relay notes to previously paired recipients. Relay note text is encrypted on the sender's device, but sender names and routing metadata are processed by Firebase. Notre has no advertising or behavioral analytics and does not sell personal information. Local Only mode disables Firebase and remote-notification traffic after relaunch.
1. Who Operates Notre
Notre is operated by Jeremy Blanchard as part of Chasing the Twist. In this policy, “Notre,” “we,” and “us” refer to that operation. Contact information appears at the end of this policy.
2. Nearby Delivery
Notre uses Apple's Multipeer Connectivity framework to discover and communicate with nearby Notre devices over local Wi-Fi and Bluetooth. Nearby sessions require encrypted connections.
Nearby peers receive the display name and installation peer identifier that Notre advertises for discovery. Devices that connect also exchange public encryption keys so they can communicate through the internet relay later. Nearby note content travels directly between the participating devices and is not sent through Firebase unless nearby delivery is unavailable and relay fallback is enabled.
3. Internet Relay
In normal mode, Notre uses Google Firebase Authentication, App Check, Cloud Firestore, Cloud Functions, and Firebase Cloud Messaging. No user sign-up or login is required, but Notre creates an anonymous, installation-scoped Firebase account to authorize relay operations.
3.1 Relay registration
Firebase may process:
- An anonymous Firebase user identifier
- Notre's random installation peer identifier
- A Firebase Cloud Messaging registration token
- DeviceCheck and App Check attestation information
- Timestamps, IP addresses, request metadata, and operational logs
3.2 Relayed notes
Before upload, Notre encrypts note text for the intended recipient using Curve25519 key agreement and AES-GCM authenticated encryption. Firebase stores or processes:
- The encrypted note payload
- Sender and recipient peer identifiers
- The sender's anonymous Firebase identifier
- The sender's display name
- An ephemeral public encryption key
- A message identifier and creation and expiration timestamps
Firebase does not receive plaintext relay note text from Notre. The sender display name and routing metadata are not encrypted. Encryption protects note confidentiality from the relay, but no system can provide absolute security.
3.3 Delivery receipts
Delivery receipts contain message, sender, and recipient identifiers, a delivered status, and delivery and expiration timestamps. They do not contain note text.
4. Notifications
When an internet-relay note is queued, Firebase Cloud Messaging and the Apple Push Notification service may process a notification containing the sender's display name, the recipient's notification token, a message identifier, and a generic relay-note type. Notre does not include plaintext note content in remote-notification payloads.
Notification delivery depends on device settings, connectivity, Apple, Google, and iOS behavior. Users may disable notifications in iOS Settings.
5. Information Stored on the Device
Depending on how Notre is used, local storage may contain:
- The display name and random peer identifier
- Unread received notes and their sender information
- Paired-peer names, peer identifiers, and public keys
- Favorites, blocks, and private peer labels
- Recently processed message identifiers used to prevent duplicate delivery
- Outgoing delivery status and timestamps
- Note text awaiting a successful relay upload, stored temporarily in a file-protected local retry queue
- Private agreement and signing identity keys stored in the iOS Keychain
Unread notes are protected using iOS complete file protection and remain until viewed or deleted. Local data can survive app termination, device restart, and app updates. Deleting Notre removes its app-container data, while Keychain retention is controlled by iOS.
6. Local Only Mode
Local Only mode takes full effect after Notre is closed and relaunched. In Local Only mode, Notre does not configure Firebase, authenticate anonymously, register for remote notifications, attach Firestore listeners, poll the relay, show internet-only recipients, or fall back to internet delivery. Nearby delivery remains available.
Enabling Local Only by itself does not delete data previously stored by Firebase. When internet relay is active, Notre also provides a Delete Internet Relay Data control. Successful deletion removes the installation's Firebase account and associated relay records, enables Local Only, and requires a relaunch.
7. Shared Links
The optional “Share as image…” action creates a URL such as https://notre.chasingthetwist.com/notre/note?text=...&from=.... The note text and sender name are contained in the URL and are not protected by Notre's relay encryption.
A shared URL may be processed or retained by the selected sharing service, recipients, browsers, link-preview services, and Cloudflare. Anyone who receives or forwards the URL may be able to read its contents. Users should not put sensitive information in a shared-link note.
8. Website Data
The Notre website does not use advertising cookies or behavioral analytics operated by us. It is delivered through Cloudflare, which may process IP addresses, request headers, requested URLs, timestamps, security events, and network diagnostics. Because shared note content is in the URL, Cloudflare request information may include that content.
9. Service Providers
We use the following providers to operate Notre:
- Google Firebase for anonymous authentication, app attestation, encrypted relay storage, backend functions, and messaging
- Apple for iOS, DeviceCheck, local networking, Keychain, and push notifications
- Cloudflare for website delivery, security, and network operations
- Any sharing application selected by the user for an optional shared link
These providers process information under their own terms and privacy policies and may process data in countries other than the user's country.
10. Retention and Deletion
- Relay notes: Deleted after successful receipt and durable local storage. Undelivered documents carry a seven-day expiration and are removed through Firestore expiration processing.
- Delivery receipts: Deleted after the sender records delivery. Unprocessed receipts carry a seven-day expiration.
- Inactive relay installations: Firebase installation records and anonymous accounts are scheduled for deletion after 90 days without a check-in.
- Invalid notification tokens: Removed when Firebase reports that they are no longer registered.
- Operational logs: Retained according to the security and operational policies of Google, Apple, and Cloudflare.
- Pending outgoing relay notes: Removed from the local retry queue after Firebase accepts the encrypted relay document, nearby delivery is acknowledged, the failed delivery is cleared, or internet relay data is deleted.
- Local data: Retained until viewed, cleared, or removed with the app, depending on the data category.
Expiration processing is asynchronous, so deletion may occur after the stated expiration time rather than at that exact moment.
Backend deletion cannot remove notes already delivered to another person's device, shared URLs or copies retained by other services, screenshots, or other copies made by a recipient.
11. Advertising, Analytics, and Sale of Data
Notre does not include advertising SDKs, Firebase Analytics, or behavioral tracking. We do not sell or rent personal information and do not share it for cross-context behavioral advertising.
12. Privacy Choices and Rights
Users can:
- Use Local Only mode
- Delete internet-relay data through Notre while internet relay is active
- Delete individual unread notes and clear completed delivery-history entries
- Block or unblock peers and email us to report a concern; note text is shared in a report only if the user chooses to include it
- Disable notification permission in iOS Settings
- Contact us to request access, correction, or deletion where applicable
Depending on location, users may have additional rights to access, correct, delete, restrict, or object to processing, or to receive a portable copy of personal information. We may need information sufficient to verify that a request relates to the requesting installation.
13. Legal Bases for Processing
Where applicable law requires a legal basis, we process information as necessary to provide the features a user requests, to maintain the security and reliability of Notre, and for our legitimate interests in operating and protecting the service. Optional link sharing occurs only when initiated by the user. Notification permission is controlled through iOS.
14. Children's Privacy
Notre does not ask for a user's age and does not knowingly use children's information for advertising or profiling. Parents and guardians should supervise a child's use, consider Local Only mode, and instruct children not to include personal or sensitive information in display names, notes, or shared links. Contact us if you believe a child has provided information that should be deleted.
15. Changes to This Policy
We may update this policy when Notre's features, providers, or legal obligations change. The effective date at the top identifies the latest revision. Material changes will be communicated as required by applicable law.
16. Contact
For privacy questions or requests:
Operator: Jeremy Blanchard, Chasing the Twist
Email: [email protected]
Website: https://chasingthetwist.com/