Privacy Policy

Last Updated / 最后更新:August 22, 2026 / 2026 年 8 月 22 日

Overview

BB Notes provides an iOS and iPadOS note-taking app and the public bbnotes.app website, with optional AI, document conversion, analytics, subscription, and cloud-sync features. This policy explains what data leaves your device, why it is processed, who may process it, and how long it is retained.

We do not sell personal data or use BB Notes data for third-party advertising or cross-app tracking.

  • Notes can be created and edited locally. For Pro users, document packages may be uploaded automatically for cloud sync when a document is saved or closed.
  • AI content is sent only after you enable Settings → AI Data Sharing and use an AI feature.
  • Firebase Analytics collects account-linked, pseudonymous usage and device information. Our custom analytics events do not send note text, chat text, audio, images, or document contents.
  • On bbnotes.app, the Google Analytics website tag loads only after you accept analytics cookies. You can reject or change this choice through the website's Cookie settings.
  • Apple handles payment-card information. BB Notes receives purchase and subscription metadata, not your card number.

Data We Process

Account and profile

When you sign in with Apple or Google, we may process your email, provider and BB Notes account identifiers, and a name or profile image supplied by the sign-in provider. We also process subscription tier, trial eligibility, quota, and support ID. The BB Notes account ID is pseudonymous but can still be linked to your account; it is not anonymous.

Notes and user content

Depending on the features you use, we may process notes, handwriting, drawings, PDFs, Office documents, images, annotations, audio, transcripts, translations, AI conversations, and document metadata such as names, folders, and page counts. Content that always remains on your device is not collected by BB Notes.

Analytics, usage, performance, and diagnostics

Google Firebase Analytics and our Supabase backend may process a Firebase app-instance/device identifier, a pseudonymous account ID after sign-in, approximate region derived from a masked IP, app/device information, launches, screens, features, session duration, document event metadata, AI request length and mode, subscription tier, purchase events, request type/model/token/cost/status/latency, error category, and a daily account-ID plus active-date record.

After website analytics consent, Google Analytics may process a browser identifier stored in analytics cookies, page URL and title, device/browser information, approximate region, referrer or campaign source, page views, scrolls, outbound link clicks, and BBNotes App Store CTA placement. The website does not send note content, document content, or a signed-in BB Notes account ID to Google Analytics.

Our structured usage logs do not contain AI prompt text, AI response text, or audio content. We also removed free-form localized conversion error descriptions from Firebase events because those descriptions can contain a local file name or path.

Purchases

Apple processes the payment. BB Notes may store product and transaction identifiers, subscription status, expiration or revocation date, entitlement source, and point-pack amount. Firebase may receive production purchase-event metadata for revenue and conversion analysis. BB Notes does not receive payment-card or bank-account details.

AI Features

AI Data Sharing is opt-in. You can revoke permission at any time in Settings → AI Data Sharing; non-AI features remain available.

  • Chat, tutoring, translation, image analysis, and outline requests pass through our Supabase backend and OpenRouter, which routes them to model providers such as Google, OpenAI, or Anthropic.
  • Audio transcription passes through our Supabase backend directly to Groq.
  • When you select Precision Translation, microphone audio is streamed directly from your device to Soniox over an encrypted WebSocket for real-time transcription and translation. A recording session can remain connected for up to 165 minutes. BB Notes issues a short-lived, single-use credential through its backend; the permanent Soniox API key is never included in the app.
  • BB Notes does not intentionally add your email or name to a model request.

BB Notes does not use your content to train its own models. We do not promise that every external provider offers zero retention or identical training terms. OpenRouter, Groq, Soniox, and the selected model provider process data under their own current privacy, retention, and service terms. Soniox states that real-time API content is processed transiently; its content-free operational metadata may include request identifiers, timestamps, duration, model, status, quota, and billing information.

BB Notes retains structured request metadata such as account ID, request type, model, token or audio-duration count, cost, response status, and latency for up to 90 days. Conversations and generated responses may still remain inside your local note and, for Pro users, its cloud-synced document package.

Cloud Sync and Conversion

For Pro users, document packages — including notes, PDFs, images, conversations, recordings, transcripts, translations, and related files — may be uploaded automatically when a document is saved or closed. Cloud objects are stored with Cloudflare R2 and account-linked metadata with Supabase.

Data is encrypted in transit and protected by provider storage controls at rest, but BB Notes cloud sync is not end-to-end encrypted. On-device OCR and PencilKit processing remain local unless the resulting content is later included in an AI request or cloud-synced document.

When you import a Word or PowerPoint document, BB Notes first attempts server conversion. The file passes through our Supabase backend to a service using Gotenberg and LibreOffice and is returned as a PDF. If the server is unavailable, the app may fall back to local conversion.

Firebase and Website Analytics

Firebase Analytics may collect analytics automatically while you use the app. After sign-in, BB Notes sets a pseudonymous Supabase account UUID as the Firebase user ID, so later events can be linked to that account.

Our custom events contain usage metadata, not note text, chat text, document contents, image contents, or audio. We use the data for product, reliability, and performance analytics, not third-party advertising or cross-app tracking.

On bbnotes.app, Google Analytics is optional. The tag is not loaded until you select Accept analytics. Advertising storage, advertising user data, and advertising personalisation remain denied. You can later reopen Cookie settings in the website footer to reject analytics; BB Notes then disables collection and attempts to remove its first-party Google Analytics cookies.

Firebase/Google retention is controlled separately by the Google Analytics property and Google’s policies. Aggregated reports may remain longer than event-level data. To object to analytics processing or request deletion of account-linked analytics data, contact us below.

Providers

ProviderPurpose
SupabaseAuthentication, account/profile and document metadata, usage records, AI routing, and administration
Google Analytics / Firebase AnalyticsConsented website interaction plus app-instance/device data, approximate region, product interaction, purchase events, performance, and diagnostics
Cloudflare R2Account-linked Pro cloud document storage
OpenRouterRouting text and image AI requests
Google, OpenAI, AnthropicLanguage and vision model processing selected through OpenRouter
GroqAudio transcription
SonioxDirect real-time microphone transcription, speaker/language detection, and precision translation when selected
Gotenberg / LibreOfficeOn-demand Word and PowerPoint conversion
Apple / Google Sign-InAuthentication, StoreKit entitlements, App Store payments, and platform services

Provider policies: Supabase, Google/Firebase, Cloudflare, OpenRouter, OpenAI, Anthropic, Groq, Soniox, and Apple.

Where a provider processes personal data on our behalf, we require it through applicable service terms or data-processing agreements to protect that data consistently with this policy and applicable law, and to use it only to provide the contracted service.

Retention

  • Account/profile data is kept while needed to provide the account and until deletion, subject to legal and security exceptions.
  • Pro cloud documents are kept until the relevant document or account data is deleted.
  • Raw account-linked AI and conversion usage metadata is kept for up to 90 days.
  • Non-identifying daily aggregate usage and cost totals may be kept longer.
  • The Supabase daily-active record is linked to the account and may remain for the account lifecycle.
  • Firebase data follows the configured Google Analytics retention setting and Google’s policies.
  • Minimal purchase, refund, trial-eligibility, deletion-receipt, anti-abuse, and technical deletion-tombstone records may be retained where needed for legal obligations, dispute resolution, preventing duplicate benefits, or completing late cloud-file cleanup.
  • To prevent repeated trial or referral benefits after account deletion, a restricted legacy trial ledger may retain a normalized email address, and the cross-provider anti-abuse ledger may retain namespaced SHA-256 hashes derived from a sign-in provider identifier, normalized email, or phone number. These records are pseudonymous and potentially matchable rather than anonymous, and are not used for marketing.
  • External AI and conversion providers apply their own retention terms.

Your Choices and Rights

Depending on your location, you may have rights to access, correct, export, object to processing of, or delete personal data.

  • Revoke AI permission in Settings → AI Data Sharing.
  • Export notes or delete individual documents using the relevant app controls.
  • Initiate permanent account and associated cloud-data deletion inside Profile → Delete Account. The app may ask you to reauthenticate and will show when a durable deletion request is still processing. You may also email liushenpeng1@outlook.com for privacy assistance.
  • Files stored locally on the device are kept because the shared folder is not partitioned by account; delete them separately from the BB Notes library if you also want them removed from that device.
  • Manage or cancel subscriptions through the Apple link shown before deletion. Apple billing continues until cancellation; account deletion does not cancel the subscription or automatically transfer its entitlement to a future account.
  • Confirmed deletion resets the local Firebase app-instance identity. Historical Firebase/Google records follow the configured retention setting; email us to request deletion of account-linked historical analytics data.
  • Deleting the app stops future collection from that installation but does not itself delete account or cloud data.

Security, Transfers, and Children

We use HTTPS, access controls, authenticated backend requests, and provider storage protections. No system is completely secure. Providers may process data outside your country and rely on appropriate transfer safeguards where required.

BB Notes is not directed to children under 13 and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal data.

Changes and Contact

We may update this policy when the app or our providers change. We will update the date above and provide additional notice when required.

Email: liushenpeng1@outlook.com

BB Notes 隐私政策(简体中文)

概览

BB Notes 提供 iOS/iPadOS 笔记应用及公开的 bbnotes.app 网站,并包含可选 AI、文档转换、分析、订阅和云同步功能。本政策说明哪些数据会离开您的设备、处理目的、可能的处理方和保留期限。

我们不会出售个人数据,也不会将 BB Notes 数据用于第三方广告或跨应用跟踪。

  • 笔记可以在本地创建和编辑。对于 Pro 用户,文档保存或关闭时,文档包可能会自动上传以实现云同步。
  • 只有在您启用 设置 → AI 数据共享 并使用 AI 功能后,相关内容才会发送给 AI 服务商。
  • Firebase Analytics 会收集与化名账号标识关联的使用和设备信息;我们的自定义分析事件不会发送笔记正文、聊天正文、音频、图片或文档内容。
  • 在 bbnotes.app 上,只有您同意分析 Cookie 后才会加载 Google Analytics 网站代码;您可拒绝或通过网站页脚的 Cookie 设置修改选择。
  • 支付卡信息由 Apple 处理;BB Notes 仅接收购买和订阅元数据。

我们处理的数据

账号和资料

使用 Apple 或 Google 登录时,我们可能处理邮箱、登录服务商标识、BB Notes 账号 ID,以及服务商提供的姓名和头像。我们还会处理订阅等级、试用资格、配额和客服 ID。账号 ID 是化名标识,但仍可关联到您的账号,并非完全匿名。

笔记和用户内容

根据您使用的功能,我们可能处理笔记、手写内容、绘图、PDF、Office 文档、图片、批注、录音、转写、译文、AI 对话,以及文档名称、文件夹和页数等元数据。始终只保留在设备上的内容不属于 BB Notes 的服务器收集。

分析、用量、性能和诊断

Google Firebase Analytics 和 Supabase 后端可能处理 Firebase 应用实例/设备标识、登录后关联的化名账号 ID、由掩码 IP 推导的大致地区、应用和设备信息、启动、页面、功能、会话时长、文档事件元数据、AI 请求长度与模式、订阅等级、购买事件、请求类型/模型/Token/费用/状态/耗时、错误类别,以及账号 ID 与活跃日期组成的每日活跃记录。

您同意网站分析后,Google Analytics 可能处理分析 Cookie 中的浏览器标识、页面网址和标题、设备/浏览器信息、大致地区、引荐或推广来源、页面浏览、滚动、出站链接点击及 BBNotes App Store 按钮位置。网站不会向 Google Analytics 发送笔记正文、文档内容或已登录的 BB Notes 账号 ID。

结构化用量日志不包含 AI 提示词、AI 回复正文或音频内容。我们也已停止向 Firebase 发送自由格式的本地化转换错误描述,因为其中可能包含本地文件名或路径。

购买

支付由 Apple 完成。BB Notes 可能保存产品和交易标识、订阅状态、到期/撤销时间、权益来源和点数包数量。Firebase 可能接收正式环境的购买事件元数据,用于收入和转化分析。BB Notes 不会获得银行卡号或银行账户信息。

AI 功能

AI 数据共享需要主动授权。您可以随时在 设置 → AI 数据共享 撤回许可,其他非 AI 功能仍可使用。

  • 聊天、辅导、翻译、图片分析和大纲请求会先经过 Supabase 后端,再由 OpenRouter 路由至 Google、OpenAI、Anthropic 等模型服务商。
  • 录音转写会经 Supabase 后端直接发送给 Groq。
  • 选择精准转译时,麦克风音频会通过加密 WebSocket 从设备直接流式传输至 Soniox,用于实时转写与翻译;单次录音连接最长可持续 165 分钟。BB Notes 后端只签发短期、单次使用的凭证,永久 Soniox API 密钥不会包含在应用中。
  • BB Notes 不会有意把您的姓名或邮箱加入模型请求。

BB Notes 不会使用您的内容训练自有模型。我们不承诺所有外部模型服务商均为零保留,也不承诺其训练条款完全一致;OpenRouter、Groq、Soniox 和具体模型服务商会依据各自当前政策处理数据。Soniox 表示实时 API 内容仅作瞬时处理;其不含内容的运营元数据可能包括请求标识、时间、时长、模型、状态、配额和计费信息。

BB Notes 会把账号 ID、请求类型、模型、Token/音频时长、费用、响应状态和耗时等结构化元数据保留最多 90 天。对话和生成内容仍可能保存在本地笔记中,Pro 用户还可能通过云同步保存。

云同步和文档转换

对于 Pro 用户,文档保存或关闭时,包含笔记、PDF、图片、对话、录音、转写、译文和相关文件的文档包可能自动上传。云文件存放于 Cloudflare R2,账号关联的元数据存放于 Supabase。

传输过程使用加密,存储服务商提供静态数据保护,但 BB Notes 云同步并非端到端加密。设备端 OCR 和 PencilKit 处理保持在本地,除非结果随后被加入 AI 请求或云同步文档。

导入 Word 或 PowerPoint 时,BB Notes 会优先尝试服务端转换:文件经 Supabase 后端发送到使用 Gotenberg/LibreOffice 的服务,再以 PDF 返回。服务不可用时,应用可能改用本地转换。

Firebase 与网站分析

使用应用时,Firebase Analytics 可能自动收集分析数据。登录后,BB Notes 会把 Supabase 账号 UUID 设置为 Firebase 用户 ID,因此之后的事件可以关联到该账号。

我们的自定义事件只包含用量元数据,不包含笔记正文、聊天正文、文档内容、图片内容或音频。这些数据用于产品、可靠性和性能分析,不用于第三方广告或跨应用跟踪。

bbnotes.app 的 Google Analytics 为可选功能,只有点击同意分析后才会加载。广告存储、广告用户数据和广告个性化始终保持拒绝。您之后可以通过网站页脚的 Cookie 设置改为拒绝;BB Notes 会停止收集并尝试移除第一方 Google Analytics Cookie。

Firebase/Google 的保留期限由 Google Analytics 属性设置及 Google 政策单独决定。若要反对分析处理或请求删除与账号关联的分析数据,请通过下方邮箱联系我们。

第三方服务商代表我们处理个人数据时,我们会通过适用的服务条款或数据处理协议,要求其按照本政策及适用法律提供一致的数据保护,并仅为提供约定服务而使用相关数据。

数据保留

  • 账号和资料在提供账号所需期间保留,删除后仍可能因法律或安全原因保留有限记录。
  • Pro 云文档保留至相关文档或账号数据被删除。
  • 与账号关联的 AI 和转换原始用量元数据最多保留 90 天。
  • 不含身份标识的每日用量和成本汇总可保留更长时间。
  • Supabase 每日活跃记录与账号关联,并可能在账号生命周期内保留。
  • Firebase 数据按 Google Analytics 保留设置和 Google 政策处理。
  • 为履行法律义务、处理争议、防止重复领取权益或滥用,以及清理迟到上传的云文件,可能保留最少量的购买、退款、试用资格、删除凭证、反滥用或技术删除墓碑记录。
  • 为防止删除账号后重复领取试用或推荐奖励,受限的旧版试用账本可能保留标准化邮箱,跨登录服务商的反滥用账本还可能保留由登录服务商标识、标准化邮箱或手机号生成的带命名空间 SHA-256 哈希。这些记录属于可能被匹配的化名数据,并非完全匿名,且不会用于营销。
  • 外部 AI 和转换服务商适用各自的保留条款。

您的选择和权利

您可以在 设置 → AI 数据共享 撤回 AI 许可,通过相应的应用功能导出笔记或删除文档。

您可以在 个人资料 → 删除账号 中发起永久删除账号及相关云数据;应用可能要求重新认证,并会在后台任务尚未完成时显示处理状态。隐私协助也可联系 liushenpeng1@outlook.com

为避免误删同一设备上其他账号的离线内容,删除账号时会保留设备本地共享文件夹中的笔记和录音;如也要从该设备移除,请在 BB Notes 资料库中另行删除。

App Store 订阅需通过删除确认页提供的 Apple 链接管理或取消;在您取消前 Apple 会继续计费,删除账号不会取消订阅,也不会把剩余权益自动转移到未来新建的账号。

确认删除后,应用会重置本机 Firebase 实例标识;历史分析记录仍按 Google Analytics 的保留设置处理,如需删除与账号关联的历史分析数据请联系我们。仅卸载应用也不会自动删除账号或云端数据。

安全、跨境处理和儿童

我们使用 HTTPS、访问控制、经过身份验证的后端请求和服务商存储保护,但任何系统都无法保证绝对安全。服务商可能在您所在国家/地区以外处理数据,并在适用时采用相应的数据传输保障。

BB Notes 不面向 13 岁以下儿童,也不会有意收集其个人数据。如您认为儿童提供了个人数据,请联系我们。

变更和联系

功能或服务商发生变化时,我们可能更新本政策,并更新顶部日期;法律要求时会提供额外通知。

邮箱:liushenpeng1@outlook.com