Public release candidate · final effective policy pending

AI Note Privacy Policy

Release candidate · reviewed 6 September 2026 · effective date pending

This is a public pre-release candidate, not a declaration that AI Note's public cloud service is available. Public paid API access remains closed. Provider account settings, international-transfer details, age scope and an effective date still require confirmation before this becomes the final release policy.

Operator and contact

AI Note (com.onsimdangai.ainote) is operated by 주식회사 온심당에이아이컴퍼니, using the brand ONSIMDANG AI COMPANY. CEO: Jaeho Choi. Business registration: 517-81-04196. Address: 2F, 3-5, Hwasancheonbyeon 2-gil, Wansan-gu, Jeonju-si, Republic of Korea. Telephone: +82 70-8805-9096.

The company's published general contact is 4wd_guitar@naver.com. Its published privacy contact is contact@onsimdang.com. These are existing company contacts; dedicated AI Note support routing and monitoring still need operational confirmation. Company website: https://onsimdang.com/. This candidate: https://onsimdang.com/en/privacy/ainote. Korean version: https://onsimdang.com/privacy/ainote.

Information kept on your device

The app saves typed notes, titles, creation times, original recordings, transcripts and organization results in private device storage. Notes and results use SQLite, and recordings are local audio files. There are no app accounts, cloud note synchronization, advertising or analytics SDKs. The Android release excludes app data from automatic cloud backup and device transfer. The app does not add its own file encryption.

A separate private settings database keeps a random installation credential, first-use cloud-processing choices, hashed content fingerprints and random retry identifiers, and the last server-reported usage. These settings survive app restarts. Cached usage is identified as last known usage when the server is unavailable; the server decides access and quotas.

Audio transcription

Before first use, a disclosure asks whether to send audio through the AI Note HTTPS server to AssemblyAI. Continuing also allows automatic transcription of subsequently saved recordings. Choosing Keep on device keeps that recording local, and later automatic saves do not repeatedly ask. You can explicitly request transcription later. The returned transcript is saved on your device. Microphone permission is used to record audio. Original recordings stay on the device when a request is declined, fails or exceeds quota. Local recording and playback do not require cloud allowance.

AI organization

After you accept its first-use disclosure, AI Organize sends the selected note or transcript through the AI Note HTTPS server to OpenAI. It sends text, not the recording. OpenAI Responses with Structured Outputs returns a summary and relevant key points, tasks or decisions. Empty sections are hidden and results are saved locally. Typed notes are not automatically sent for organization. The current server model setting is gpt-5.6-luna.

Server processing and retention

The AI Note proxy runs on Vultr in the region reported by its instance metadata as kr (Korea). Audio can occupy multipart buffers and a temporary upload file while processing. The normal bounds are 16 MiB and 30 minutes per recording; the operator verification window uses smaller limits. The app deletes its upload file on success, failure or cancellation, and removes interrupted uploads at service startup. Transcription processing has a 30-minute deadline. Organization processing has a 60-second application deadline.

SQLite transcription jobs contain a random job identifier, status, transcript, generic error, timestamps, temporary audio path and a hash of the job access capability. Status/result lookup requires that capability; its plaintext is not stored. Completed or failed jobs expire about one hour after completion. The normal completed job no longer contains its audio path. Interrupted work is marked failed on restart and is not automatically resubmitted to a paid provider.

The server atomically reserves monthly allowance before calling a provider. A validated successful result and its usage are committed together; failed or interrupted requests release the reservation. Repeated delivery of the same request uses an idempotency record so it does not submit a second provider request or count a second success. A completed request whose response is lost can still count once, because a successful result exists; the app can retry to retrieve it.

To make those retries possible, organization results are cached in the server SQLite database for approximately one hour. Input note text is not saved there. Request records contain an opaque principal, keyed hashes of retry keys and content fingerprints, operation kind, UTC month, measured audio seconds or organization count, status and timestamps. After the result cache expires, content-free idempotency metadata and successful monthly totals are retained for the current and previous UTC calendar months. Audio duration is measured on the server, rounded up to seconds. The client cannot grant itself Pro.

Abuse and cost protections count attempts even when user allowance is restored. The server processes network IPs, keeps keyed IP hashes in counters, and retains request-type/status aggregates. Counters expire after roughly 24 hours from their bucket; HTTP aggregates cover the current UTC date and six previous dates. Aggregate monthly cost-attempt counts cover the current and previous months. These counters contain no note content, audio, API keys or raw IP. AI Note nginx and Uvicorn access logging are disabled. Hosting/provider operational records are separate.

Cleanup runs about every minute and at startup; downtime can delay deletion. These are application-level logical deletion schedules, not guarantees of physical erasure from SQLite pages, storage media or separate infrastructure backups.

The schema also supports plan, expiry and hashed purchase reference for future verified subscriptions, with expired entitlement bookkeeping removed 35 days after expiry. Actual purchases and Pro grants are not connected. Production app attestation is pending; temporary installation identity does not prevent reinstall abuse completely. Public paid access remains closed, with only short, bounded operator verification windows.

Subscription Billing and Abuse Prevention Identifiers

1. Google Play Subscription (Pro) Verification: When a user subscribes to or restores the Pro monthly plan (ainote_pro_monthly) via Google Play, the Google Play Billing system generates a purchase token, which is transmitted over secure HTTPS to the AI Note server. The server verifies subscription validity (ACTIVE or GRACE_PERIOD status) and expiration timestamp directly with the Google Play Android Publisher API. To prevent unauthorized reuse of purchase tokens across accounts, a one-way cryptographic hash (SHA-256) of the token along with the expiration date is retained on the server. If the subscription expires or is canceled, Pro entitlements are automatically revoked.

2. Fair Free Quota Enforcement and Reinstallation Abuse Prevention: AI Note provides free tier allowances (30 minutes/month of voice transcription and 3 AI summaries/day). To prevent fraudulent quota resetting through repeated app uninstall and reinstall cycles, the app generates a deterministic, obfuscated installation credential by combining the device's Android SSAID (ANDROID_ID) with a secret salt and computing a one-way cryptographic hash (SHA-256). The raw Android SSAID is never transmitted or stored on the server and is never used to track individuals across services.

External providers and international processing

AssemblyAI and OpenAI process the submitted content for the requested operation. Their processing may occur outside Korea or your country. Exact recipient-region, contractual transfer details and actual account retention/training settings remain to be confirmed; this candidate makes no promise of zero retention or universal provider deletion.

OpenAI API content is not used for training by default unless the customer opts in. The proxy sends store=false, which does not eliminate other retention. Standard abuse monitoring can retain content for up to 30 days, and caching can have separate retention. Account-specific controls have not been verified. See https://developers.openai.com/api/docs/guides/your-data.

AssemblyAI documents typical uploaded-audio deletion within 24–48 hours; asynchronous final transcript artifacts can persist without a configured TTL or other applicable arrangement. The current adapter does not send transcript DELETE requests. Actual TTL and training opt-out settings remain unverified. See https://support.assemblyai.com/articles/2240096256-does-assemblyai-offer-zero-data-retention and https://www.assemblyai.com/docs/data-retention-and-model-training.

Choices and deletion

You may keep typed notes and recordings locally and decline cloud processing. This version remembers accepted choices and has no separate screen to revoke them. Android Clear storage or uninstall removes choices together with local notes and audio; it is not a way to change consent while preserving those files. Denying microphone permission leaves text notes usable. There is no individual-note delete function or app account in this version. Server records follow the schedules above. Uninstalling does not itself delete provider copies.

Privacy requests can be addressed to the existing company privacy contact, contact@onsimdang.com. Before release, the operator must confirm how it will receive AI Note requests and handle provider-side deletion. Age scope is not yet finalized. Updates and the final effective date will be published at this policy address.

Security

Provider API keys remain on the server and are not embedded in Flutter. HTTPS, restricted server files, bounded access and an isolated service protect processing. This is not end-to-end encryption. The company will review this candidate again before public cloud access or actual subscriptions are enabled.