Privacy Policy
Last updated: 6 September 2026
GeoNotes is built so that the honest answer to “what do you know about me?” can be “almost nothing.” There is no advertising, no ad tracking and no profile of you. The one thing we measure is product usage, counted without tying it to your account and described in full below. Nothing about you is ever sold, rented or shared for marketing.
Who we are
GeoNotes is operated by Victor Santos, an independent developer based in the State of Florida, United States. That is who “we” and “us” mean throughout this policy, and who is responsible, as data controller, for everything described in it.
There is no company behind it and no support desk. A question or a request reaches a person, through the contact form at the end of this page.
The short version
- Without an account, GeoNotes stores no notes on our servers. Your notes and the coordinates saved with them stay on your device, apart from the address lookup described below.
- With an account, we store your e-mail address and your notes, each one including the precise coordinates you saved it at, and nothing more than we need to keep them in sync.
- We do not track your location in the background. Ever. The app reads your position only while it is open on screen and only when you ask it to.
- We count product usage so we can see which features are actually used. It is not linked to your account, your e-mail address or your notes.
- You can delete your account and everything in it from inside the app, or from a public page (https://gnotes.vshub.app/delete-account), without asking us.
Using GeoNotes without an account
Signing in is optional and the app is fully usable without it. In that mode every note you write, coordinates included, is stored only in your device's own browser storage. It is not uploaded, not backed up by us and not visible to us. If you clear your browser data or uninstall the app, those notes are gone, because we never had a copy.
There are two exceptions: address lookup, described under Location data below, and the usage counts described under Product analytics. Neither carries your notes and neither identifies you.
What we store when you do have an account
An account exists for one reason: to sync the same notes to more than one device. To do that we store:
- Your e-mail address. It identifies the account and is where sign-in codes are sent. It is not used for marketing and you will never be added to a mailing list.
- Your notes: the text you wrote, the coordinates the note was pinned to, the address those coordinates resolved to, and the times the note was created and last changed.
- Your passkeys: the public key and identifier of each authenticator you have registered, and the date it was added. A passkey's private key never leaves your device and we never receive it.
- Your sessions: a hash of each sign-in token, when it was created, when it was last used, and the browser's user-agent string so the app can show you a readable device name in the “active sessions” list and let you sign out a device you no longer have.
That is the entire list of what your account holds. There is no name field, no phone number, no address book access, no contacts, no photos and no advertising identifier. The usage counts described below are kept separately and are never joined to it.
Location data
GeoNotes asks for location permission because a note without a place is just a note. How that permission is used:
- Your position is read only while the app is open in the foreground. There is no background location, no geofencing and no location history beyond the notes you deliberately saved.
- GPS polling stops as soon as a precise fix is reached, both to save your battery and to avoid reading more than is needed.
- A note's coordinates are never typed in or picked from a map. They are read from your device when you create the note, and a note's position can only be updated while you are back at the place it marks, from a fresh reading taken there.
To turn coordinates into a readable address, the app sends them to our server, which forwards them to the OpenStreetMap Nominatim geocoding service. The coordinates are sent at the precision your device reported them, the request carries no account identifier and no session, and the result is cached by coordinate rounded to roughly 11 metres so that nearby lookups do not generate new traffic. We do not keep a log tying a lookup to a person. Address data is © OpenStreetMap contributors (https://www.openstreetmap.org/copyright).
Location permission is not really optional, because a note is its place: the new note button stays disabled until the app has a fix accurate to about 30 metres, and refusing the permission, or granting only approximate location, means no new notes can be created, and no existing note can have its position updated. The notes you already have stay readable, and their text stays editable. If you never want coordinates leaving the device at all, the honest answer is that GeoNotes is not the app for you.
Product analytics
We use PostHog to count how GeoNotes is used, because the alternative is guessing at which features are worth keeping. It records how the app is used, which parts get opened and when a setting is changed, together with the ordinary technical details a browser sends anyway: the page address, the referring page, browser and operating system, screen size, language and your IP address, from which PostHog derives an approximate location no finer than a city.
It is deliberately kept apart from who you are. We never call PostHog's identify function, so these events are not linked to your account, your e-mail address or your passkeys, and no profile of you is built. That is not the same as the events being anonymous: the IP address and the browser identifier described below still belong to a browser, and in several countries that counts as personal data in its own right. The text of your notes is never sent, and neither are their coordinates or the addresses those resolved to.
To tell a returning visitor from a new one, PostHog stores a random identifier in your browser for a year. It is a meaningless number attached to the browser rather than to you, it is never used for advertising, and clearing your browser data removes it.
If you would rather not be counted, switch on your browser's “Do Not Track” setting: we ask PostHog to honour it, and GeoNotes behaves identically either way.
What we deliberately do not do
- No advertising, no ad identifiers, no ad networks.
- No Google Analytics, no Meta pixel and no other cross-site tracking network.
- No selling, renting or sharing of personal data with anyone for their own purposes.
- No automated decision-making, and no profile of you built out of the analytics above.
- No reading of your notes for training, ranking or any other purpose.
Service providers
A handful of services are needed to run GeoNotes. Each one sees only the narrow slice of data its job requires:
- Cloudflare hosts the application and its database, and provides the Turnstile check that keeps the sign-in-code endpoint from being abused. As the host, Cloudflare processes the network requests that reach the service.
- PostHog receives the usage events described above. The requests are routed through our own domain rather than sent to it directly, but PostHog is still the processor: its servers are in the United States and it holds the events under the standard contractual clauses in its data-protection agreement.
- Resend delivers account e-mail: sign-in codes and deletion confirmations. It receives your e-mail address and the message.
- OpenStreetMap Nominatim resolves coordinates to an address, as described above. It receives coordinates, never an identity.
- Google Play Integrity is used only by the Android app, to confirm that a request for a sign-in code comes from a genuine, unmodified install rather than a script. It returns a verdict about the app, not about you.
Security
Everything travels over HTTPS. Sign-in is passwordless: there is no password for you to reuse and none for us to leak. E-mail sign-in codes are stored only as a hash, expire after a few minutes, are limited to a small number of attempts and are rate-limited per address. Session tokens are likewise stored only as a hash, expire after seven days, and can be revoked individually from the app's settings.
Your notes are stored on our server in ordinary form, not end-to-end encrypted. That includes the coordinates and address saved with each note, so it includes a record of the places you pinned them at. We do not read them, but we are technically able to, and so is anyone who could compel us. Please do not put passwords, financial details or anything else you would be harmed by losing control of into GeoNotes.
How long things are kept
- Notes are kept until you delete them. Deletes are immediate and permanent: there is no trash and no recovery.
- Deleted-note records keep only the note's identifier, so your other devices learn that it is gone. They are pruned after 30 days.
- Analytics events are kept by PostHog for up to seven years, its standard retention. They are never tied to your account, so deleting your account does not reach them.
- Sessions expire after seven days.
- Sign-in codes expire within minutes.
- Empty accounts (registered but left with no passkey and no notes) are removed automatically after 30 days.
Deleting your account
You do not have to ask us and you do not have to explain. In the app, open Settings → Delete account. If you no longer have the app installed, use the public page at gnotes.vshub.app/delete-account.
Deletion signs you out everywhere immediately and starts a 30-day grace window, which exists so an accidental tap is survivable. Deleting the account also removes its passkeys, so getting back in means using Recover account: we e-mail you a code, and once you have entered it you add a new passkey to the account. Do that before the window elapses and everything is restored. Once it closes, your account, your notes and every record tied to them are permanently erased, automatically. We do not keep an archived copy.
Why we are allowed to hold any of this
Data protection law in Europe and the United Kingdom asks anyone holding personal data to name the permission they are relying on, not just to describe what they collect. Ours are these two.
- Because it is what you asked for. Your notes, the coordinates saved with them, your e-mail address, your passkeys and your sessions are held because GeoNotes cannot do the thing you opened it to do without them: syncing notes to a second device means storing the notes, and signing you in without a password means storing a passkey. This is the basis the law calls performance of a contract, the contract being the Terms of Use.
- Because it is reasonable and costs you nothing. The usage counts, the Turnstile check that protects the sign-in endpoint, the rate limits and the Android integrity check rest instead on our legitimate interests: knowing which features are worth keeping, and stopping the service being abused by scripts. This basis carries a right to object, described below.
Little of this changes if you use GeoNotes without an account, because there is then almost nothing to hold. The address lookup is part of creating a note, so it sits under the first of the two, and the usage counts are the same counts.
Your rights
Depending on where you live you may have the right to access, correct, export or erase your personal data, and to object to its processing. GeoNotes is built so that you can exercise most of that yourself: your notes are in front of you in the app, editable and deletable, and account deletion is one tap away. For anything the app does not cover, use the contact form below and we will answer.
Where we rely on legitimate interests rather than on running the service itself, which in practice means the usage counts, you have the right to object. Switching on your browser's Do Not Track setting is the quickest way to do it and needs nothing from us.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain about us to your national data protection authority, and you do not have to come to us first. We would rather you wrote to us and gave us the chance to put something right, but that is your choice and nothing here asks you to give it up.
Children
GeoNotes is not directed at children under 13 and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will remove it.
Cookies
GeoNotes sets no advertising or marketing cookies. The app keeps two things in your browser: the sign-in session that keeps you logged in, which is strictly necessary and goes when you sign out, and the analytics identifier described above. Beyond those, anything kept on your device is a preference you set, it stays there, and none of it is used to identify or follow you.
International transfers
GeoNotes runs on Cloudflare's global network, and both our analytics provider and our e-mail provider operate from the United States, so data may be processed in a country other than your own. Where that amounts to a transfer out of the European Economic Area, it is covered by the standard contractual clauses in each provider's data-protection agreement. The providers listed above are used under their standard terms and data-protection commitments.
Changes to this policy
If this policy changes in a way that matters, the date at the top changes with it and the change will be announced in the app. Continuing to use GeoNotes after that means the revised policy applies.
Contact
Questions, requests or complaints: use the GeoNotes contact form.
Your use of GeoNotes is also covered by the Terms of Use.