Last updated August 23, 2026
This Privacy Notice for Nicolas Raymond (doing business as njrapps) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
Download and use our mobile application (Mallard), or any other application of ours that links to this Privacy Notice
Use Mallard. Mallard is a handwriting-first note-taking app for Android tablets and stylus input. Users write, draw, and type notes, import PDFs and images, record audio, and organize their work into notebooks and folders. The app itself is free: unlimited notebooks and pages, every drawing tool, page type and background, and import and export are available to everyone at no charge. Using the app requires a Mallard account, created with Google sign-in or with an email address and a password. Notes are stored on the user's device by default, and an optional paid subscription adds cloud backup, sync and storage across the user's own devices, together with access to two on-device AI features: speech-to-text transcription, which runs entirely on the device, and handwriting recognition, which runs on the device using Google's ML Kit.
Contact us for support, or otherwise correspond with us about the app
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at support.njrapps@gmail.com.
This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by using our table of contents below to find the section you are looking for.
What personal information do we process? When you use the Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? Some of the information may be considered "special" or "sensitive" in certain jurisdictions, for example your racial or ethnic origins, sexual orientation, and religious beliefs. We do not process sensitive personal information.
Do we collect any information from third parties? We receive limited information from third parties: Google Play tells us that a purchase was made, which product it was for, whether it is in a free trial, when the current period ends, and whether the subscription is still active, and, because every Mallard user has an account, if you chose to create yours with Google sign-in rather than with an email address and a password, Google gives us your basic profile information (name, email address and profile picture).
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so.
In what situations and with which parties do we share personal information? We may share information in specific situations and with the service providers that operate parts of the Services on our behalf. We do not sell your personal information, and we do not share it with anyone for their own purposes.
How do we keep your information safe? We have adequate organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by visiting https://sites.google.com/view/mallard-legal/data-requests, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
Want to learn more about what we do with any information we collect? Review the Privacy Notice in full.
1. WHAT INFORMATION DO WE COLLECT? 2. HOW DO WE PROCESS YOUR INFORMATION? 3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION? 4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION? 5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES? 6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
7. HOW DO WE HANDLE YOUR SOCIAL LOGINS? 8. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY? 9. HOW LONG DO WE KEEP YOUR INFORMATION? 10. HOW DO WE KEEP YOUR INFORMATION SAFE? 11. DO WE COLLECT INFORMATION FROM MINORS? 12. WHAT ARE YOUR PRIVACY RIGHTS? 13. CONTROLS FOR DO-NOT-TRACK FEATURES 14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS? 15. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
16. DO WE MAKE UPDATES TO THIS NOTICE? 17. HOW CAN YOU CONTACT US ABOUT THIS NOTICE? 18. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you create your account, when you use the Services, and when you contact us for support.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
email addresses
names
passwords — chosen by you and handled by Firebase Authentication, and never visible to us
contact or authentication data
an account identifier assigned to your account by Firebase Authentication
note content, including handwriting, drawings, typed text, imported images and pdf documents, and the audio recordings you make in the app — received by us only while you hold an active Cloud + AI subscription; notes kept only on your device are never sent to us, and video files are never uploaded (only a video's details and any transcript you create are synchronised)
transcripts — produced on your device, and received by us only while you hold an active Cloud + AI subscription
Account Data. Mallard requires an account, so we collect account data from every user, not only from subscribers. If you create your account with an email address and a password, we collect that email address; your password is handled by Firebase Authentication, the sign-in service we use, and is not visible to us. If you create your account with Google sign-in, we receive your basic Google profile — your name, email address and profile picture — as described in the section called "HOW DO WE HANDLE YOUR SOCIAL LOGINS?" below. In both cases Firebase Authentication assigns your account a user identifier, which is the key under which your subscription and, if you subscribe, your cloud data are stored. We use account data to authenticate you, to attribute a subscription to the account that bought it, to keep your notes separate from those of any other account on the same device, and to respond to your support requests. Creating an account and signing in do not by themselves upload any of your notes; cloud backup and sync run only while you hold an active Cloud + AI subscription. Account data is deleted when you delete your account.
Sensitive Information. We do not process sensitive information.
Payment Data. If you choose to purchase a subscription, your payment is processed by Google Play Billing. We never receive, handle, or store payment information such as card numbers, billing addresses, or bank details, and all payment data is handled and stored by Google Play Billing. Google Play tells us that a purchase was made, which product it was for, whether it is in a free trial, when the current period ends, and whether the subscription is still active. We store that status against your account, together with a one-way hash of the purchase identifier, so that a purchase can only be used by the account that made it. You may find Google's privacy notice here: https://policies.google.com/privacy.
Google Sign-In Data. You can create the account the app requires by signing in with your existing Google account instead of registering with an email address and a password. If you do so, we collect certain profile information about you from Google, as described in the section called "HOW DO WE HANDLE YOUR SOCIAL LOGINS?" below.
Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
Mobile Device Access. We may request access or permission to certain features from your mobile device. The only permission the app asks you to grant is access to your mobile device's microphone, which it uses when you record audio in a note. The app also declares the ordinary permissions an app of this kind needs in order to reach the network, to keep recording while the screen is off, and to complete a purchase through Google Play; those are not permissions you are asked about, and none of them gives us access to your camera, your location, your contacts or your messages. If you wish to change our access or permissions, you may do so in your device's settings.
Mobile Device Data. We automatically collect the identifiers that belong to your device and to your installation of the app — your mobile device ID and the device and application identification numbers our service providers assign — together with your Internet Protocol (IP) address (or proxy server), which our sign-in, configuration and purchase-verification service providers necessarily receive each time your device contacts them. The request that fetches our configuration also carries the version of the app, the version of your operating system, your language preference and your time zone, because those are what determine which configuration applies to your device.
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and, where you have turned usage analytics on, for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and the identifiers that belong to your device and to your installation of the app — is collected automatically when you use our Services. Usage analytics and crash reports are not: we collect those only if you turn them on.
We automatically collect certain information when you use the Services. This information may include device and installation information, such as your Internet Protocol (IP) address, the identifiers that belong to your device and to your installation of the app, and the version of the app, the version of your operating system, the language preference and the time zone that the configuration request carries. This information is primarily needed to maintain the security and operation of our Services and, where you have turned usage analytics on, for our internal analytics and reporting purposes. Usage analytics and crash reporting are not part of this automatic collection: we collect them only after you turn them on. Both are off unless you switch them on, and both may be switched off again at any time in Settings > Privacy. If you do not turn them on, the only information we collect automatically is the device, installation and application information described in the Mobile Device Data bullet above — including your Internet Protocol (IP) address, which our sign-in, configuration and purchase-verification service providers necessarily receive each time your device contacts them — together with the server log entries described in the Server Logs bullet below. Server log entries are recorded against your account identifier; the rest of this automatically collected information is not, on its own, tied to your name or contact information. We do not collect any record of the features you use unless you have turned usage analytics on, and we never collect the notes or files you open, the searches you run in the app, or any record of web browsing.
The information we collect includes:
Log and Usage Data. Only if you turn on crash reporting or usage analytics (both are off unless you switch them on, and can be switched off again at any time in Settings > Privacy): log and usage data is the service-related, diagnostic, usage, and performance information the app records when you use our Services. Depending on how you interact with us, this data may include information about your activity in the Services (such as the date/time stamps associated with your usage and which features of the app you used, recorded as fixed event names that never carry your note titles, your file names, or any text you wrote) and device event information (such as system activity, error reports (sometimes called "crash dumps"), and hardware settings).
Server Logs. Separately, and regardless of those switches, our servers record ordinary log entries when your device contacts them and when Google Play notifies us about your subscription — the date and time, the account identifier concerned, which subscription plan and state it relates to, how much storage a change added or removed, and the outcome — which we use to operate the Services, verify purchases and investigate faults.
Device Data. We collect device data such as information about the tablet or other device you use to access the Services. Depending on the device used, this device data may include information such as your IP address (or proxy server) and device and application identification numbers.
Diagnostics. Only if you turn on crash reporting (it is off unless you switch it on, and can be switched off again at any time in Settings > Privacy): crash reports, including error diagnostics, stack traces, the app version and build number, and the device model, manufacturer, operating system version and system configuration that the crash-reporting component attaches to a report so that a fault can be reproduced. Separately, if you write to our support address using the button inside the app, the draft email the app prepares for you includes your device model, your Android version and the app version, so that we can reproduce the fault; you can see and remove those lines before you send it.
Google API
Our use of information received from Google APIs will adhere to Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy#limited-use).
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We process the personal information for the following purposes listed below. We may also process your information for other purposes only with your prior explicit consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order. An account is required to use the app, so this applies to every user: we use your email address and account identifier to authenticate you, to attribute a subscription to the account that bought it, and to respond to your support requests.
To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
To send administrative information to you. We may process your information to send you service messages about your account, such as the email that verifies your address and a password reset you asked for.
To fulfill and manage your subscription purchases. We may process your information to fulfill and manage your subscription purchases and payments, and any related refunds or cancellations, made through Google Play Billing.
To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
Cloud backup and sync of your content. To store, back up and synchronise your notes, handwriting, documents, images and audio across the devices you sign in on, while you hold an active Cloud + AI subscription; signing in without a subscription does not upload anything. Video files themselves are never uploaded — they stay on the device that recorded or imported them, and only a video's details and any transcript you create are synchronised. (Retention period: While your subscription is active, then 90 days after it ends. Deleted immediately if you delete your account.)
Storage quota management. To measure how much cloud storage your files use and apply the limit of the plan you purchased.
Verifying purchases and preventing billing fraud. We confirm purchases and subscription status with Google Play, and ensure a purchase can only be used by the account that made it.
Keeping accounts and data secure. We use account identifiers and sign-in information to ensure only you can reach your own notes and files, including on a device shared by more than one account, where each account sees only the notes it created.
Delivering app configuration. When the app starts, it asks our configuration service provider for the settings we are currently applying, which is how we adjust the way the app behaves without publishing a new version. That request registers an installation identifier for your device and happens whether or not you have turned usage analytics on, and it sends us none of your notes. One of those settings can be an announcement about Mallard itself, such as an offer on a Cloud + AI subscription. We do not use the identifier, or anything else we know about you, to choose who receives that announcement: we publish the same one to everyone, and your device does not show it to you if you already subscribe.
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time, as described in the section called "WHAT ARE YOUR PRIVACY RIGHTS?" below.
Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
Diagnose problems and/or prevent fraudulent activities
prevent fraudulent or duplicate use of purchases, and make sure paying users receive what they paid for
protect your notes from unauthorised access and keep the service secure
Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
For investigations and fraud detection and prevention
For business transactions provided certain conditions are met
If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
In Short: We may share information in specific situations described in this section and/or with the service providers listed below.
Service Providers. We may share your data with vendors, service providers, contractors, or agents ("service providers") who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our service providers, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
The service providers we may share personal information with are as follows:
Cloud Computing Services
Google Cloud Platform
Functionality and Infrastructure Optimization
Cloud Firestore, Cloud Functions for Firebase and Cloud Storage for Firebase
User Account Registration and Authentication
Firebase Authentication and Google Sign-In
Remote configuration and in-app announcements
Firebase Remote Config and Firebase Installations (Google LLC) — when the app starts, your device registers an installation identifier and requests the configuration we are currently applying, which is how we deliver settings and announcements about Mallard; this happens whether or not you have turned on usage analytics
On-device handwriting recognition
Google ML Kit Digital Ink Recognition (Google LLC) — downloads the recognition model through Google Play services and may receive anonymous usage metrics from the ML Kit component; your ink is recognised on your device and is not uploaded to be read
App analytics
Google Analytics for Firebase (Google LLC) — only if you turn on usage analytics. It then receives the in-app feature-usage events described above, together with the information the component collects by itself: the version of the app and of your operating system, an identifier for this installation, the times of your sessions, and the record Google Play keeps of how the app was installed. It never receives your note titles, your file names or anything you wrote
Crash reporting
Crashlytics (Google LLC) — receives crash reports and error diagnostics only if you turn on crash reporting
Payments, subscriptions and purchase verification
Google Play Billing (Google LLC)
Every provider listed above processes your personal information only as our service provider, on our instructions and on our behalf, with one narrow exception that we describe rather than hide: the handwriting-recognition component built into the app may report anonymous metrics about its own operation to Google under Google's own terms, as described in the section called "DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?" below. That report carries no note content, no ink and no account information. We do not sell your personal information, and we do not share it with any third party for that third party's own purposes.
One recipient is not a service provider, and we name it here so that this list is complete. The first time you set up speech-to-text transcription, the app downloads the speech recognition model from Hugging Face, Inc., a public file host. We send Hugging Face nothing at all; your device requests the file, and that request tells Hugging Face what any file download tells a host, including your Internet Protocol (IP) address. No audio, video, transcript, note content or account information accompanies it. This is described further in the section called "DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?" below.
We also may need to share your personal information in the following situations:
Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. No such merger, sale, financing or acquisition has taken place, and none is in negotiation.
In Short: No. Mallard is a mobile application and uses no cookies, web beacons or pixels. The identifiers it does use are installation identifiers, described below and in the section called "HOW DO WE PROCESS YOUR INFORMATION?" above.
Mallard is a mobile application and does not use cookies, web beacons or pixels. It shows you no web pages of ours and contains no browser through which such technologies could operate on our behalf, and it collects no advertising identifier. The sign-in component we use includes Google's abuse-prevention technology, which runs when you sign in and checks that the request comes from a genuine device rather than from an automated attack; it is not used to recognise you across services, and it is not used to advertise to you. The analytics and crash-reporting components built into the app instead identify your installation with an identifier held on your device, which we use only to group crash reports and feature-usage events, and only for as long as you have those features turned on. A separate installation identifier is registered by our configuration service provider each time the app starts, whether or not you have those features turned on, as described above; and where you hold a Cloud + AI subscription, an identifier generated for your installation is stored with your synchronised notes, so that changes made on one of your devices can be told apart from changes made on another.
If, and only if, you turn on usage analytics or crash reporting, we permit our analytics and crash-reporting service providers to collect that information on our behalf, so that we can understand how the app is used and diagnose crashes. Both are off unless you switch them on, and both may be switched off again at any time in Settings > Privacy. We do not display third-party advertising in the Services, we carry no advertising network, and we do not permit any service provider to use your information to tailor advertising to your interests. The only promotional message the app ever shows is our own occasional announcement about a Mallard subscription, described in the section called "HOW DO WE PROCESS YOUR INFORMATION?" above.
These identifiers are not used for targeted advertising, and their use does not constitute a "sale" or a "sharing" of personal information under applicable US state laws.
Analytics
If you turn on usage analytics, we use Google Analytics for Firebase, which acts as our service provider on our instructions and on our behalf, to understand how the app is used. We do not share your information with Google, or with anyone else, for their own purposes. For more information on the privacy practices of Google, please visit the Google Privacy & Terms page (https://policies.google.com/privacy). In the app, you can turn crash reporting and usage analytics on or off at any time under Settings > Privacy. Turning a switch off stops that collection immediately and, for usage analytics, clears the analytics identifier held on your device.
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.
As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.
Our AI Products
Our AI Products are designed for the following functions:
Speech-to-text transcription of your own audio recordings and of the videos you import, which runs entirely on your device
Handwriting recognition — converting your handwriting to text, and searching your handwritten notes — which runs on your device using Google's ML Kit Digital Ink Recognition
How We Process Your Data Using AI
Both AI Products run on your device. An active Cloud + AI subscription is required to use them, but that requirement is checked against your account; it does not cause any recording, ink or note to leave your device.
Speech-to-text transcription runs entirely on your device. The audio and video you transcribe, and the transcripts produced from them, are not sent to us or to any third party in order to be processed, and we do not use them to train any model. Audio never leaves your device for transcription. One thing does involve a third party: the first time you set up transcription, the app downloads the speech recognition model — approximately 153 MB, downloaded once — from Hugging Face, Inc., a public file host. That request tells Hugging Face what any file download tells a host, including your Internet Protocol (IP) address, and it tells us nothing at all. No audio, video, transcript, note content or account information is sent with it, and every transcription you run afterwards uses the copy of the model stored on your device. Hugging Face's handling of that request is governed by its own privacy policy (https://huggingface.co/privacy). If you hold an active Cloud + AI subscription, your audio recordings and transcripts are backed up to your cloud account like the rest of your notes and are handled in line with this Privacy Notice; video files are never uploaded.
Handwriting recognition runs on your device using Google's ML Kit Digital Ink Recognition, a software component from Google LLC that is built into the app. Your ink is recognised on the device and is not uploaded to us or to Google in order to be read. Two things do involve Google: the recognition model for your language (English at launch) is downloaded once through Google Play services, and the ML Kit component may send anonymous usage and performance metrics about itself to Google, which we do not control. Google's handling of that information is governed by the ML Kit Terms of Service (https://developers.google.com/ml-kit/terms) and Google's Privacy Policy (https://policies.google.com/privacy). Text produced by recognition becomes part of your notes and is handled like the rest of your note content.
In Short: Mallard requires an account. If you choose to create or sign in to it with your Google account rather than with an email address and a password, we receive certain profile information about you from Google.
Because an account is required to use the app, you sign in either with an email address and a password or with your existing Google account. Where you choose Google, we receive certain profile information about you from Google. The profile information we receive may vary, but will often include your name, email address, and profile picture.
We will use the information we receive only for the purposes that are described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by Google. We recommend that you review Google's privacy notice (https://policies.google.com/privacy) to understand how Google collects, uses, and shares your personal information, and how you can set your privacy preferences in your Google account.
In Short: We may transfer, store, and process your information in countries other than your own.
Our servers are located in Canada. Regardless of your location, please be aware that your information may be transferred to, stored by, and processed by us in our facilities and in the facilities of the service providers with whom we may share your personal information (see "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above), including facilities in Canada, the United States, and other countries.
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.
European Commission's Standard Contractual Clauses:
We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between us and our service providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. Our Standard Contractual Clauses can be provided upon request. We have implemented similar appropriate safeguards with our other service providers and further details can be provided upon request.
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us.
In practice this means: account data (your email address, your account identifier and, for Google sign-in, your name and profile picture) is kept for as long as your account exists and is deleted when you delete your account. Content you have backed up to the cloud is kept while your Cloud + AI subscription is active and for 90 days after it lapses, so that you can resubscribe or export it; after those 90 days it is permanently deleted. If you delete your account, your cloud content is deleted immediately, without the 90-day period. Server log entries are kept for a short operational period and are then deleted automatically on our logging provider's own schedule. Notes and files that exist only on your device are never held by us at all.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. All data transmitted between the app and our services is encrypted in transit using TLS, and the app is configured to refuse unencrypted network connections. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
In Short: We do not knowingly collect data from or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction.
We do not knowingly collect, solicit data from, or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or the equivalent age as specified by law in your jurisdiction or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age or the equivalent age as specified by law in your jurisdiction has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18 or the equivalent age as specified by law in your jurisdiction, please contact us at support.njrapps@gmail.com.
In Short: Depending on your state of residence in the US or in some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. If a decision that produces legal or similarly significant effects is made solely by automated means, we will inform you, explain the main factors, and offer a simple way to request human review. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the UK and are unhappy with how we have handled your personal information, you can make a complaint directly to us. This is in addition to the rights you have under the UK General Data Protection Regulation and the Data Protection Act 2018.
How to contact us:
Online: https://sites.google.com/view/mallard-legal/data-requests
Email: support.njrapps@gmail.com
What happens after you complain
We will acknowledge your complaint within 30 days of receiving it.
We will investigate without unjustifiable or excessive delay.
We will keep you informed of progress and explain the outcome.
If you are not happy with our final response, you can refer your complaint to the Information Commissioner's Office, the UK supervisory authority.
Website: ico.org.uk/make-a-complaint (http://ico.org.uk/make-a-complaint)
Helpline: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority (https://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm) or UK data protection authority (https://ico.org.uk/make-a-complaint/data-protection-complaints/data-protection-complaints/).
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch/edoeb/en/home.html).
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent for usage analytics and crash reporting at any time in the app under Settings > Privacy, and otherwise by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
Change the email address or the password on your account from within the app under Settings > Account.
Delete your account from within the app under Settings > Account, or by emailing us from the address registered to your account.
Upon your request to terminate your account, we will delete your account, its account data and everything stored in your cloud account from our active databases, immediately; the 90-day retention period that applies after a subscription lapses does not apply to account deletion. Notes and files on your device are not removed by that action. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.
If you have questions or comments about your privacy rights, you may email us at support.njrapps@gmail.com.
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.
In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. More information is provided below.
Categories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The examples in each row are the statutory examples of that category; the entry in the Collected column states what we actually collect, and what we do not. For a comprehensive inventory of all personal information we process, please refer to the section "WHAT INFORMATION DO WE COLLECT?"
Category — Examples — Collected
A. Identifiers — Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name — YES (email address, account identifier and IP address from every user, since an account is required to use the app, together with the identifiers that belong to your device and to your installation of the app, plus your name and profile picture if you sign in with Google; we never collect postal address or telephone number)
B. Personal information as defined in the California Customer Records statute — Name, contact information, education, employment, employment history, and financial information — YES (your email address, and your name if you sign in with Google, in the same way as category A; we collect no education, employment or employment history information, and no financial information)
C. Protected classification characteristics under state or federal law — Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data — NO
D. Commercial information — Transaction information, purchase history, financial details, and payment information — YES (subscription and purchase status received from Google Play only; we never receive financial details or payment information)
E. Biometric information — Fingerprints and voiceprints — NO
F. Internet or other similar network activity — Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements — YES (in-app feature-usage events only, and only if you turn on usage analytics; we do not collect browsing history or search history)
G. Geolocation data — Device location — NO
H. Audio, electronic, sensory, or similar information — Images and audio, video or call recordings created in connection with our business activities — YES (the notes and files you choose to back up while you hold an active Cloud + AI subscription — your handwriting, typed text, note and folder names, images, imported PDFs, audio recordings, transcripts, and the details of your videos; we never make recordings ourselves, and video files are never uploaded)
I. Professional or employment-related information — Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us — NO
J. Education Information — Student records and directory information — NO
K. Inferences drawn from collected personal information — Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics — NO
L. Sensitive personal Information — NO
We may also collect other personal information outside of these categories when you correspond with us by email, in the context of:
Receiving help through our customer support channels; and
Facilitation in the delivery of our Services and to respond to your inquiries.
Sources of Personal Information
We collect personal information from you, from your device, and from Google, as described in the section called "WHAT INFORMATION DO WE COLLECT?" above.
How We Use and Share Personal Information
We use and share your personal information as described in the sections called "HOW DO WE PROCESS YOUR INFORMATION?" and "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above.
Will your information be shared with anyone else?
We may disclose your personal information to our service providers pursuant to a written contract between us and each service provider. The service providers are named in the section called "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above.
We may use aggregated and de-identified information for our own business purposes, such as understanding how the Services are used and improving them. This is not considered to be "selling" of your personal information. We do not use the content of your notes, your recordings or your transcripts for research, and we do not use them to train any model.
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the following categories of personal information to our service providers for a business or commercial purpose in the preceding twelve (12) months (the only recipient that is not a service provider is the file host described in the section called "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above, which your device contacts directly and to which we disclose nothing): A. Identifiers, B. Personal information as defined in the California Customer Records statute, D. Commercial information, F. Internet or other similar network activity (only from users who turned on usage analytics), and H. Audio, electronic, sensory, or similar information — the note content and files you choose to store in your cloud account.
The categories of service providers to whom we disclosed personal information for a business or commercial purpose can be found under "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:
Right to know whether or not we are processing your personal data
Right to access your personal data
Right to correct inaccuracies in your personal data
Right to request the deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to non-discrimination for exercising your rights
Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California’s privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
Depending upon the state where you live, you may also have the following rights:
Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota)
Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in California, Delaware, and Maryland)
Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in Minnesota and Oregon)
Right to obtain a list of third parties to which we have sold personal data (as permitted by applicable law, including the privacy law in Connecticut)
Right to review, understand, question, and depending on where you live, correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Connecticut and Minnesota)
Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California)
Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida)
How to Exercise Your Rights
To exercise these rights, you can contact us by visiting https://sites.google.com/view/mallard-legal/data-requests, by emailing us at support.njrapps@gmail.com, or by referring to the contact details at the bottom of this document.
Under certain US state data protection laws, you can designate an authorized agent to make a request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with applicable laws.
Request Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.
If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request and the agent will need to provide a written and signed permission from you to submit such request on your behalf.
Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at support.njrapps@gmail.com. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may submit a complaint to your state attorney general.
California "Shine The Light" Law
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. We do not disclose personal information to third parties for direct marketing purposes. If you are a California resident and would like to make such a request, please submit your request in writing to us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?"
In Short: You may have additional rights based on the country you reside in.
Australia and New Zealand
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020 (Privacy Act).
This Privacy Notice satisfies the notice requirements defined in both Privacy Acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information.
If you do not wish to provide the personal information necessary to fulfill their applicable purpose, it may affect our ability to provide our services, in particular:
offer you the products or services that you want
respond to or help with your requests
manage your account with us
confirm your identity and protect your account
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?"
If you believe we are unlawfully processing your personal information, you have the right to submit a complaint about a breach of the Australian Privacy Principles to the Office of the Australian Information Commissioner (https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us) and a breach of New Zealand's Privacy Principles to the Office of New Zealand Privacy Commissioner (https://www.privacy.org.nz/your-rights/making-a-complaint/).
Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?"
If you are unsatisfied with the manner in which we address any complaint with regard to our processing of personal information, you can contact the office of the regulator, the details of which are:
The Information Regulator (South Africa) (https://inforegulator.org.za/) General enquiries: enquiries@inforegulator.org.za Complaints (complete POPIA/PAIA form 5): PAIAComplaints@inforegulator.org.za & POPIAComplaints@inforegulator.org.za
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes, you will be shown a notice in the app the next time you open it, and you will be asked to confirm that you have read and agree to the revised documents before you continue. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
If you have questions or comments about this notice, you may email us at support.njrapps@gmail.com
You have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please visit: https://sites.google.com/view/mallard-legal/data-requests.