InstantTerms

Acme Notes

Prohttps://acmenotes.example
Version 2CurrentManual edit

Friendlier introduction · 3 h ago

Version 1Generated

Initial draft · 3 h ago

Changes from version 1 to version 2

1 change

  1. 1Who we are

addedremoved

2 unchanged paragraphs

Privacy Policy

Acme Notes · Last updated: October 7, 2026

Change 1 · Who we are

1 edited

1. Who we are

We wrote this policy to be read, not skimmed. This Privacy Policy explains how Acme Labs ApS ("we", "us" or "our") collects, uses and shares personal information when you use Acme Notes (the "Service"), available at https://acmenotes.example.

We are the controller of your personal information. Our address is Example Street 1, 1000 Copenhagen, Denmark.

47 unchanged paragraphs

2. Information we collect

We collect the following categories of personal information:

  • Identifiers — for example user ID, IP address, advertising ID.
  • Contact details — for example name, email address.
  • Account information — for example login credentials, profile settings.
  • Payment and transaction data — for example billing address, purchase history, last four digits of your card.
  • Usage data — for example pages and features used, clicks, session duration.
  • Device and technical data — for example browser type, operating system, device model, language.
  • Approximate location — for example country or city derived from IP address.
  • Content you provide — for example files, text and other material you submit.
  • Communications — for example support conversations, emails you send us.

We collect this information directly from you, automatically when you use the Service, and from the service providers listed below.

3. How we use your information

We use your information for the purposes below. If you are in the European Economic Area (EEA) or the United Kingdom, we rely on the legal bases listed for each purpose.

Purpose Legal basis
Provide, operate and secure the service Performance of a contract; legitimate interests (security)
Create and manage your account Performance of a contract
Process payments and prevent fraud Performance of a contract; legal obligation (tax and accounting)
Understand usage and improve the service Consent where required (e.g. cookies); otherwise legitimate interests
Communicate with you and provide support Performance of a contract; legitimate interests
Provide AI-powered features you request Performance of a contract
Comply with legal obligations and enforce our terms Legal obligation; legitimate interests

Where we rely on consent, you can withdraw it at any time without affecting processing that happened before.

We do not sell your personal information.

4. Service providers we share data with

We use trusted third-party service providers to operate the Service. They process personal information on our behalf and under our instructions, unless stated otherwise below.

  • Hosting & infrastructure: Supabase
  • Payments: Stripe
  • Analytics: PostHog
  • Customer support: Intercom
  • Email: Resend
  • AI models: OpenAI

Details of each provider:

  • Intercom (Intercom R&D Unlimited Company, Ireland) — powers our live chat and support messaging, with data hosted in the European Union. It processes your name, email, messages you send us and basic usage information. See Intercom's privacy policy.
  • OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd, United States / Ireland) — processes the prompts and content you submit to AI features in order to generate a response. See OpenAI's privacy policy.
  • PostHog (PostHog, Inc., United States) — provides product analytics and feature flags, hosted in the European Union. It collects a pseudonymous identifier, device information and the features you use. See PostHog's privacy policy.
  • Resend (Resend, Inc., United States) — delivers our transactional emails (such as sign-in links and receipts) from the United States. It processes your email address and the content of the emails we send you. See Resend's privacy policy.
  • Stripe (Stripe, Inc. and Stripe Payments Europe, Ltd., United States / Ireland) — processes payments on our behalf. We do not store your full card number. Stripe also acts as an independent controller of some data to prevent fraud and comply with financial regulations. See Stripe's privacy policy.
  • Supabase (Supabase, Inc., United States) — hosts our database, file storage and user authentication in Frankfurt, Germany. See Supabase's privacy policy.

We may also disclose information to professional advisers, to a buyer or successor in a merger or acquisition, or where required by law or to protect our rights and the safety of our users.

5. Cookies and similar technologies

We use cookies and similar technologies on our website. For details, including how to manage your preferences, see our Cookie Policy.

6. AI features

Some features of the Service use third-party artificial intelligence (AI) models. When you use these features, the content you submit (such as prompts, text or files) is sent to the AI provider to generate a response. Please avoid submitting sensitive personal information to AI features.

OpenAI does not use data submitted through its API to train its models. It may retain inputs and outputs for up to 30 days to detect abuse, after which they are deleted.

7. International data transfers

Some of our service providers process personal information outside the EEA and the United Kingdom:

  • OpenAI — United States
  • Resend — United States
  • Stripe — United States

Where personal information is transferred to a country that has not been found to provide an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or the EU-U.S. Data Privacy Framework where the recipient is certified. You can ask us for a copy of these safeguards.

8. How long we keep your information

We keep personal information only for as long as needed for the purposes described in this policy. In general:

  • Account information is kept while your account is active and deleted within 30 days after you close it.
  • Transaction records are kept for as long as required by tax and accounting law (typically up to 7 years).
  • Analytics and diagnostic data are kept in identifiable form for no longer than 26 months.
  • Backups are overwritten on a rolling basis.

9. Security

We use appropriate technical and organisational measures to protect personal information, including encryption in transit, access controls and regular review of our providers' security practices. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, and to object to or restrict certain processing. To make a request, contact us at privacy@acmenotes.example. We will respond within the time required by applicable law and may need to verify your identity first.

EEA and UK residents. You have the rights of access, rectification, erasure, restriction, data portability and objection under the GDPR and UK GDPR, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.

You can unsubscribe from marketing emails at any time using the link in the email. We will still send you service-related messages, such as security notices and receipts.

11. Notice for United States residents

This section provides additional information for residents of California and other U.S. states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Texas and Oregon).

Categories collected. In the past 12 months we have collected the categories of personal information described in "Information we collect" above (identifiers, contact details, account information, payment and transaction data, usage data, device and technical data, approximate location, content you provide, communications), for the business purposes described in "How we use your information".

Your rights. You may have the right to know, access, correct and delete your personal information, and not to be discriminated against for exercising these rights. You may use an authorised agent to submit a request on your behalf.

Sale and sharing. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the past 12 months.

Sensitive information. We do not use or disclose sensitive personal information for purposes other than those permitted by law.

Appeals. If we decline your request, you may appeal by replying to our decision. If your appeal is denied, you may contact your state Attorney General.

12. Children's privacy

The Service is not intended for children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, if the changes are significant, notify you by email or through the Service.

14. Contact us

If you have questions about this policy or want to exercise your rights, contact us at:

Acme Labs ApS
Example Street 1, 1000 Copenhagen, Denmark
Email: privacy@acmenotes.example