We Noted It Privacy Policy
Last updated: 17 September 2026
1. Who operates We Noted It
We Noted It is operated by Angelo Ghafoerkhan, an independent developer based in the Netherlands. For privacy questions, contact angeloghafoerkhan@gmail.com.
2. Contact information
Privacy questions and requests may be sent to angeloghafoerkhan@gmail.com.
3. What We Noted It does
We Noted It accepts a meeting or event image, extracts candidate event information, applies a minimum-quality check, and can create the requested event in Google Calendar after authorization.
4. What personal data may be processed
- Uploaded or captured images: an image selected through the browser for event extraction.
- Extracted event information: event title or what, date and time or when, location or where when available, and other event details needed to create the requested Calendar event.
- Google authentication information: authorization information and account identifier needed to sign you in and request the configured Google Calendar permission.
- Account and usage information: email address, account identifiers, credit balance, and OCR usage records needed to provide accounts, free requests, and purchased credits.
- Payment information: payment and purchase information handled by Stripe when you buy credits. We do not receive or store your full card number.
- Local acceptance record: a versioned browser-local marker that the Terms checkbox and Privacy Policy acknowledgement were completed. It is not tied to a Google-authenticated identity.
5. Uploaded and captured images
Images are processed for the extraction needed for the requested calendar event. We Noted It's intended behavior is not to intentionally retain uploaded or captured images after the processing required for that event request.
In the current browser implementation, the selected image is held temporarily in page memory during processing. Provider-specific handling and retention are outside We Noted It's direct control.
6. Extracted event information
Extracted fields are temporarily held in the browser for the current flow. They are used to apply the quality check and, when authorized, create the requested Google Calendar event. We Noted It's intended behavior is not to intentionally retain extracted event data after that processing.
7. Google authentication and Calendar access
We Noted It uses Google Identity Services and Google Calendar only to
create the event requested by the user. The current implementation
requests the calendar.events permission and sends the
candidate event to the primary Google Calendar through Google's event
creation API after authorization.
We Noted It does not claim to read existing Calendar events and does not request access to contacts, Gmail, Drive, or other Google services.
Google user data obtained through authorization is used only to provide the requested Calendar functionality. It is not sold or used for advertising. We Noted It does not claim Google approval or compliance certification; Google's Limited Use requirements and other applicable Google requirements remain applicable.
8. AI and OCR processing
The current application sends the selected image through a secured OpenRouter server function for image understanding and structured event extraction. The OpenRouter API key remains server-side and is not exposed to the browser.
OpenRouter receives the image and extraction request needed to provide this feature. We Noted It does not use the images to advertise to you. OpenRouter's own privacy terms and retention settings also apply to that processing.
9. Purposes of processing
Processing is intended to provide image-based event extraction, apply the current quality gate, create the Calendar event requested by the user, operate the acceptance gate, and respond to privacy requests.
10. Legal bases
We process data to provide the service you request, to perform our agreement with you, to maintain account security and usage limits, and where required, on the basis of your consent. You can withdraw consent for optional integrations by disconnecting Google Calendar or contacting us.
The Terms checkbox records agreement to the user agreement. The Privacy Policy checkbox records acknowledgement that this notice was read. It is not blanket consent to processing. If a specific activity requires consent, that consent must be collected separately.
11. Third-party providers
The service uses Supabase for authentication, database records, and server functions; Google Identity Services and Google APIs for authentication and Calendar event creation; OpenRouter for image understanding; Stripe for credit payments; and Vercel for hosting. These providers process data under their own privacy policies and contractual security obligations.
12. Retention and deletion
We Noted It does not intentionally retain uploaded images or extracted event data after the processing required to create the requested Calendar event. This does not describe or control retention by Google, OpenRouter, Vercel, or any future provider.
The acceptance marker remains in local browser storage until it is cleared or replaced by a later application version. Account, credit, and usage records are kept while needed to provide the service, prevent abuse, meet accounting requirements, or resolve disputes. You may request account and personal-data deletion by emailing us; some records may be retained where legally required.
13. Security
We use HTTPS, server-side functions for provider secrets, access controls, and limited data retention. OAuth refresh tokens and service credentials are not intentionally exposed in the browser. No online service can guarantee absolute security, so users should only upload images they are comfortable processing.
14. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard.
15. User rights
Depending on the legal basis and circumstances, users may contact angeloghafoerkhan@gmail.com regarding applicable GDPR rights, including access, correction, deletion, restriction of processing, objection, data portability where applicable, and withdrawal of consent where consent is the applicable legal basis. No particular right is promised for every activity.
16. Complaints
Users in the Netherlands may contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl if they have concerns about our processing.
17. Changes to this policy
We may update this policy when the service or applicable law changes. The latest version and its effective date will always be published on this page. Material changes may be communicated through the service or by email where appropriate.
18. Contact
Privacy questions and requests: angeloghafoerkhan@gmail.com.