← home

Privacy Policy

app: notiqa ai  ·  last updated: 2026-06-24

This Privacy Policy describes how Ali Kılıç ("we", "us", "our") collects, uses, and protects information when you use the Notiqa AI mobile application and any related services (collectively, the "Service"). By installing or using the Service you agree to the practices described here. If you do not agree, do not install or use the Service.

Summary. Notiqa AI is a local-first note-taking app. Your notes, drawings, and files stay on your device unless you sign in to sync them. We do not sell your data. We do not use your content to train AI models. Optional AI features send the specific content you choose (for example, a selected canvas region) to a third-party AI provider over an encrypted connection so the provider can return a result. Section 5 describes this in detail.

1. Who We Are

The Service is operated by Ali Kılıç, an individual developer based in Trabzon, Türkiye. Ali Kılıç is the data controller responsible for your personal data. Contact details are provided at the end of this document.

2. Information We Collect

We collect only what is necessary to provide and improve Notiqa AI:

  • Account data (only if you sign in): email address and a salted hash of your password, managed through our authentication provider (Supabase Auth).
  • User-generated content: notes, vector drawings, handwriting strokes, attached files and images that you create within the app. This content stays on your device unless you enable cloud sync.
  • Sync data (only if cloud sync is enabled): the above content, plus sync metadata (timestamps, device identifiers used for conflict resolution), stored on our backend (Supabase).
  • AI request content (only when you invoke an AI feature): the specific input you submit — for example a cropped region of your canvas, a stroke set, or a text prompt — is transmitted to a third-party AI provider so a response can be returned. See Section 5.
  • Device & technical data: device model, operating system version, app version, language, crash logs, and basic diagnostics needed to keep the app stable.
  • Network data: IP address and request metadata when your device communicates with our servers or third-party providers acting on our behalf.

We do not collect precise location, contacts, photos library, microphone, camera, health, financial, or biometric data unless you explicitly enable a feature that requires it.

3. How We Use Your Information

  • operate, maintain, and improve the Notiqa AI Service;
  • authenticate you and secure your account;
  • sync your content across your devices when you opt in;
  • execute AI features you explicitly invoke, by routing the selected input to an AI provider and returning the result to your device;
  • diagnose technical problems, prevent abuse, and protect the integrity of the Service;
  • comply with legal obligations.

We do not sell your personal data. We do not use your notes, drawings, or AI inputs to train our own or third-party machine-learning models. We do not use your data for advertising or behavioral tracking.

4. Legal Basis (GDPR / KVKK)

Where applicable, we process personal data on the basis of (a) the performance of a contract with you (providing the Service), (b) our legitimate interests (security, fraud prevention, product improvement), (c) your consent for optional features (cloud sync, AI features), and (d) legal obligations.

5. AI Features and Third-Party AI Providers

Notiqa AI includes optional features that use third-party AI models — for example, recognising your handwriting, solving a handwritten math expression, or generating a suggested completion. These features are off by default and only activate when you invoke them.

When you invoke an AI feature, the specific input you select (for example, a cropped image of a canvas region or a text prompt) is transmitted over HTTPS to one of the following AI providers, which act as processors for that single request:

Provider Purpose Policy
Google (Gemini API) Vision & text inference policies.google.com/privacy
Groq Text & vision inference groq.com/privacy-policy
OpenRouter Aggregated model routing (vision & text) openrouter.ai/privacy

The provider list may change over time as we add or remove fallbacks. The provider used for a given request depends on availability and the model required for the feature.

We do not store AI request inputs or outputs on our own servers beyond the in-memory window needed to deliver the response. Any result you keep in your note becomes ordinary user content and is governed by the rest of this Policy. Each AI provider processes requests under its own published policy, linked above. We have selected providers that, at the time of writing, do not train their models on API-submitted content by default, but you should review their policies for the most current terms.

AI output disclaimer. AI features may produce inaccurate, incomplete, or misleading results. Output from an AI model is a suggestion, not a verified fact. You are responsible for reviewing AI output before relying on it, especially for math, medical, legal, financial, safety-critical, or otherwise consequential use. Do not submit sensitive, confidential, or regulated data (for example, health or financial records of identifiable third parties) to AI features.

6. Storage, Hosting, and Security

When you enable cloud sync, your notes and files are stored on Supabase, our authentication, database, and object-storage provider, operating on secure cloud infrastructure. Passwords are stored exclusively as one-way salted hashes; they are never stored in plain text by us or by Supabase Auth. All communication between the app, our backend, and AI providers is encrypted using HTTPS/TLS.

No method of transmission or electronic storage is perfectly secure. We use reasonable technical and organisational measures to protect your information, but we cannot guarantee absolute security.

7. Sharing of Information

We do not sell, rent, or trade your personal data. We share limited data only with the following categories of recipients, each acting under contractual confidentiality and processing obligations:

  • Infrastructure & backend processors — Supabase (authentication, database, object storage);
  • AI providers — as listed in Section 5, only for the specific inputs you submit to AI features;
  • Operational processors — error monitoring, crash reporting, push-notification delivery, where used;
  • Legal authorities — when required by law, legal process, or to protect rights, safety, or property.

8. Your Rights

Subject to applicable law (including GDPR and KVKK), you may have the right to access, correct, delete, or export your personal data, withdraw consent for optional features, and object to or restrict certain processing. To exercise these rights, contact us using the details below. You may also delete your Notiqa AI account at any time from within the app; this removes your associated cloud-stored data within a reasonable period, subject to legal retention obligations.

9. Data Retention

We retain personal data only as long as needed to provide the Service and to comply with legal obligations. Cloud-stored content and account data are deleted within a reasonable period after you delete your account, except where retention is required by law (for example, financial or audit records). AI request inputs and outputs are not retained on our servers beyond the response window.

10. Children's Privacy

Notiqa AI is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Third-Party Links and Services

Notiqa AI may contain links to or integrations with third-party services. We are not responsible for their privacy practices or content. Review their policies before using them.

12. International Transfers

Your information may be processed in countries outside your own, including by AI providers and Supabase. Where data is transferred internationally, we rely on lawful transfer mechanisms (such as standard contractual clauses) consistent with applicable law.

13. Disclaimer and Limitation of Liability

The Service is provided "as is" and "as available", without warranties of any kind, whether express or implied, including but not limited to merchantability, fitness for a particular purpose, accuracy, or non-infringement. To the maximum extent permitted by applicable law, Ali Kılıç shall not be liable for any indirect, incidental, consequential, special, or exemplary damages, including damages for loss of data, profits, or goodwill, arising out of or in connection with your use of the Service or any AI-generated output. You use the Service and any AI features at your own risk. Nothing in this section limits any liability that cannot be limited under applicable law.

14. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always published at this URL with the "last updated" date at the top. Material changes will be communicated within the app or by email where appropriate.

15. Contact

For privacy questions, data-rights requests, or any other inquiry:
Ali Kılıç
Trabzon, Türkiye
alikilic.com.tr