xotes — Privacy Policy
Last updated: June 14, 2026
This Privacy Policy explains how Xotes LLC ("xotes," "we," "us," or "our") collects, uses, and protects your information when you use the xotes application and website at xotes.ai (the "Service"). Xotes LLC is a limited liability company organized in Ohio, United States.
By using xotes, you agree to the practices described in this policy. If you don't agree, please don't use the Service.
1. Who we are
xotes is a private journaling and note-taking application — a modern commonplace book — that uses artificial intelligence to help you capture, organize, transcribe, and reflect on your notes. The data controller is Xotes LLC, Ohio, United States. You can reach us at privacy@xotes.ai.
2. Information we collect
Information you provide:
- Account information — the email address and authentication details you use to create and sign in to your account.
- Your content ("Entries") — the notes, journal entries, text, and any images or documents you create, write, or upload to the Service. Entries are often deeply personal, and we treat them with care.
- Billing information — when you purchase a subscription, your payment is handled by our payment processor (Stripe) or, for purchases made inside a mobile app, by the Apple App Store or Google Play. These providers collect your payment details directly. We receive limited information such as your subscription plan, status, and billing confirmations, and we do not store your full payment-card number.
- Communications — messages you send us, such as support requests.
Information collected automatically:
- Usage and device data — how you interact with the Service, the features you use, and technical details such as device type, browser, and operating system.
- Cookies and local storage — we use essential cookies and local storage to keep you signed in and to operate core features, and product-analytics technology (see Section 8) to understand how the Service is used.
3. How we use your information
We use your information to:
- Provide and operate the Service — store your Entries, keep you signed in, and sync your data.
- Power AI features — organizing, sorting, transcribing, and generating insights from the Entries you choose to process (see Section 4).
- Process payments, manage your subscription, and prevent fraudulent or unauthorized transactions.
- Respond to your support requests and communicate with you about the Service.
- Understand usage, improve features, fix bugs, and keep the Service secure.
- Comply with our legal obligations.
We do not sell your personal information or your Entries, and we never use your Entries for advertising.
4. AI features and your content
xotes uses artificial intelligence to power features like sorting, transcription (Scan), and Insights.
- AI processing is scoped and on demand — only the Entry content you choose to run through an AI feature is sent for processing. Your writing is not continuously monitored.
- That content is sent to Anthropic, PBC (provider of the Claude AI models) through its API solely to generate the result we return to you.
- Anthropic does not use content submitted through its API to train its AI models.
- AI output can be inaccurate or incomplete, and it is not professional advice of any kind (see our Terms of Service).
5. How we share information
We share information only with the service providers ("subprocessors") that help us run xotes, each under contracts that limit how they may use the data:
- Anthropic, PBC — AI processing of the Entry content you choose to analyze.
- Supabase (provided through Lovable Cloud) — secure cloud hosting, database storage, and authentication.
- Stripe — payment and subscription processing on the web. Subscriptions purchased inside a mobile app are processed by the Apple App Store or Google Play.
- PostHog — privacy-conscious product analytics that help us understand how the Service is used.
We may also disclose information when required by law or legal process, to protect the rights, safety, and security of our users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you).
We do not sell or rent your personal information.
6. Data retention and deletion
- Your Entries and account data are stored for as long as your account is active.
- You can delete any Entry at any time, and you can delete your entire account from within the Service. Deleting your account triggers a cascading deletion that removes your Entries and associated personal data from our active systems.
- Residual copies in encrypted backups are purged within 30 days.
- We retain limited transaction and billing records for as long as required for legal, tax, accounting, and dispute-resolution purposes.
7. Your rights and choices
You can:
- Access and review your Entries directly in the Service.
- Correct or update your account information and Entries at any time.
- Export your data — xotes lets you export your Entries as Markdown from your account settings.
- Delete individual Entries or your entire account from within the Service.
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to or restrict certain processing and to withdraw consent. To make any such request, email privacy@xotes.ai, and we will respond as required by applicable law.
California residents (CCPA/CPRA): In the past 12 months, we have collected the categories of personal information described in Section 2 (identifiers such as your email, your user-generated content, commercial/transaction information related to your subscription, and internet or other usage activity). We use it for the purposes in Section 3. We do not sell or share your personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights. You may request access, deletion, or correction by emailing privacy@xotes.ai.
EU/UK/EEA residents (GDPR): Our legal bases for processing are: performance of our contract with you (to provide the Service and your subscription), your consent (for non-essential analytics), our legitimate interests (to secure and improve the Service and prevent fraud), and compliance with legal obligations. You have the right to access, rectify, erase, restrict, or object to processing, and to data portability, and you may lodge a complaint with your local supervisory authority. Where your data is processed in the United States by our providers, we rely on appropriate safeguards for any such transfers.
8. Cookies and analytics
We use essential cookies and local storage to keep you signed in and to run core features. We also use PostHog to collect product-analytics information about how the Service is used so we can improve it. You can control cookies through your browser settings; disabling essential cookies may affect how the Service works.
9. Security
We protect your information using reasonable technical and organizational measures, including encryption in transit (HTTPS) and encryption at rest, authenticated access controls, and reputable infrastructure providers. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.
10. Age requirement and minors' privacy
xotes is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from individuals under 18. If you believe someone under 18 has provided us personal information, email privacy@xotes.ai and we will delete it.
11. International users
xotes is operated from the United States. If you use the Service from elsewhere, your information will be processed in the United States and other countries where our providers operate, which may have data protection laws different from those in your country.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice within the Service.
13. Contact us
Xotes LLC — Ohio, United States Privacy questions: privacy@xotes.ai General contact: contact@xotes.ai