1. Who is responsible
goto LCS UG (haftungsbeschränkt)Paul-Heyse-Straße 31 b
80336 München
Germany
Email: contact@gotolcs.com
goto LCS UG is the controller responsible for personal data processed through KlarNotes, this website, and support correspondence as described in this policy. See our imprint for the full company details.
2. Notes stored on your device
The iOS app saves notes inside its local app storage. The web app uses browser storage. This can include note titles and text, checklists, selected photos on iOS, colors, pins, archive and trash status, organization settings, timestamps, pending changes, and recovery copies.
This information lets you write, search, organize, restore, and export your notes. In local mode, note content is not automatically sent to us. On iOS, folder structure and note locations are currently kept on the device, including in exports.
Local and signed-in libraries are separate. Signing in or subscribing does not automatically move or upload local notes. A signed-in library may keep downloaded notes and pending edits on the device so you can continue using that cache offline. Signing out clears the active credentials but does not erase the account’s saved device cache.
KlarNotes does not apply its own end-to-end encryption to notes or photos. Local data is readable by the app within the protections provided by your device or browser. Cloud connections use HTTPS, but the KlarNotes service can read synced content.
Apple device or iCloud backups may include local app data depending on your settings. These backups are controlled by Apple and your device settings, separately from KlarNotes sync. Browser storage can be cleared or evicted, and deleting the iOS app removes its local app container. Export important notes before clearing storage or changing devices.
3. Photos you add
On iOS, the system Photos picker gives KlarNotes access to the photos you select. We do not request access to your entire photo library. Selected images are copied into the current library and converted to optimized JPEG files; original EXIF and location metadata are not copied. The app also stores image dimensions, file size, an identifier, and integrity information.
Photos added to local notes stay in that local library. Photos in a synced library are uploaded to private cloud storage and accessed through temporary authorized links. Removing a photo from a note does not immediately erase every retained copy: local files and cloud assets can remain for undo and recovery. See retention below.
When you share a photo or export a library, the destination you choose receives that content. Those copies are then governed by the destination’s settings and privacy practices.
4. Accounts and optional sync
If you create an account or sign in, Auth0 (an Okta service) handles authentication. Account processing includes your email address, email-verification status, account identifiers, the profile information you provide to the sign-in service, and technical authentication and security information. KlarNotes stores the account identifier and email information needed to recognize your account. We do not store your account password in the KlarNotes notes database.
A verified paid subscription is required for cloud sync. The service processes the notes, checklist items, photos, edits, timestamps, device or client identifiers, and sync and recovery records in your synced library. It uses these records to keep changes consistent, enforce access, and recover conflicting edits. Sync runs while the app is active; it is not a separate device backup service.
When you explicitly share a note from the web app, the service processes the recipient’s email address, membership, and access role. The recipient can access the shared content according to that role. Revoking access does not remove copies they have already downloaded or exported.
Account information is needed to provide account features; you can continue using local notes without providing it. The legal basis for requested account and sync services is Article 6(1)(b) GDPR. Protecting accounts, preventing abuse, and resolving service errors also serves our legitimate interests under Article 6(1)(f) GDPR.
5. Apple subscriptions and RevenueCat
Optional iOS sync subscriptions are purchased through Apple. Apple handles payment details. KlarNotes uses RevenueCat to validate purchases, restore subscriptions, and determine whether your account has sync access. RevenueCat is configured after your KlarNotes account has been verified.
RevenueCat processes your internal KlarNotes account ID, purchase and transaction history, product and subscription identifiers, renewal and expiration information, and subscription status. This purchase information also supports subscription reporting in RevenueCat. KlarNotes records the subscription status and expiry needed to authorize sync. We do not send your note text or photos to RevenueCat, and do not receive your full payment-card details.
Processing needed to provide and restore your purchase is based on Article 6(1)(b) GDPR. Fraud prevention and understanding subscription performance are based on our legitimate interests under Article 6(1)(f); records required by law are processed under Article 6(1)(c).
Apple manages subscription renewal and cancellation. Cancelling a subscription does not itself delete your KlarNotes account or notes. Read Apple’s Privacy Policy and RevenueCat’s Privacy Policy for their practices.
6. Website visits and essential storage
When you open the website or connect to the web app or sync service, infrastructure providers process technical request information needed to deliver and protect the service. This may include your IP address, request time, page or endpoint requested, referring page, browser or device information, and errors or security events.
KlarNotes’ hosting architecture uses Amazon Web Services (AWS), with the notes database and photo storage configured for Frankfurt, Germany. Content delivery, authentication, billing, and support providers may process data in other locations; this is not a promise that all processing stays in the EU. AWS describes its practices in its Privacy Notice.
The public website does not set analytics or advertising cookies, load external fonts, or embed advertising trackers. The web app uses essential browser storage for notes, app caching, and remembering the selected account. Authentication may use essential session cookies on the sign-in service. KlarNotes does not include advertising or analytics that record what you write. Subscription reporting is described separately above.
The legal basis for service delivery and security logs is our legitimate interest in operating and protecting the service under Article 6(1)(f) GDPR. Local storage and authentication support the functions you request.
7. Support correspondence
If you email contact@gotolcs.com, we receive your email address, message, and any attachments or information you choose to include. Support email is handled through Google Workspace. We use it to respond to and document your request.
The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual requests, and otherwise our legitimate interest in providing support under Article 6(1)(f). Please include only the information needed to explain the issue; you do not need to send your whole notes library.
8. Service providers and international processing
We use AWS for infrastructure, Auth0/Okta for authentication, RevenueCat for subscription validation and reporting, and Google Workspace for support email. Apple separately provides App Store payments, device services, and any Apple backups or diagnostics you enable. We may disclose information where legally required or necessary to protect the service and establish, exercise, or defend legal claims.
Some providers may process information outside the European Economic Area. Where required, transfers rely on an applicable adequacy decision or appropriate safeguards, such as EU Standard Contractual Clauses. Contact us for information about the safeguards relevant to your data. Further information is available in Okta’s Privacy Policy, RevenueCat’s Privacy Policy, and Google Workspace’s data processing terms.
9. Retention, export, and deletion
Local notes, photos, cached account data, and recovery records remain in the app or browser until removed. Moving a note to Trash, removing a photo, signing out, or cancelling a subscription is not permanent erasure of all copies. Recovery data and removed photo files may remain stored. Deleting the app or clearing its browser storage removes local app data; it does not delete existing Apple backups, exports, or cloud records. Offloading an iOS app can preserve its data.
Cloud notes, sync history, and photo assets are retained to provide the account, sync, and recovery features. There is currently no automatic permanent-erasure schedule for trashed notes or removed photos. For account deletion or erasure of developer-held data, email contact@gotolcs.com. We may need to verify the request before acting. Limited records may need to be retained for legal obligations, security, or legal claims, and backups may remain until their applicable retention cycle ends.
Support correspondence and technical records are kept only as long as necessary to resolve requests, deliver and protect the service, meet applicable obligations, or establish and defend legal claims. Retention depends on the record’s purpose and the applicable provider settings. Purchase records may also be subject to Apple’s and RevenueCat’s retention requirements.
You can export your current library in Settings. On iOS, exports with photos include image files in a ZIP; libraries without photos export as JSON. We cannot retrieve notes kept only on your device.
10. Your rights
Where the GDPR applies, you may request access, correction, erasure, restriction, or portability of personal data, subject to the applicable conditions. You can object to processing based on legitimate interests for reasons relating to your situation. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.
You may complain to a data-protection authority, including in the country where you live or work. Our competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA). To exercise a right or ask a privacy question, email contact@gotolcs.com.
KlarNotes does not use your notes for advertising profiles or decisions with legal or similarly significant effects based solely on automated processing. Subscription access is checked automatically against your purchase status; contact support if you believe that status is incorrect.
11. Changes to this policy
We may update this policy when KlarNotes, its service providers, or applicable requirements change. The date at the top identifies this version. Material changes will be explained here before the relevant feature or service update is released.