Running Notes Privacy Policy
Effective date: July 21, 2026
Our approach is simple: collect only what Running Notes needs, use it only to provide the service, do not sell it, and give people an understandable way to ask questions or request deletion.
1. About this policy
This policy explains how Running Notes ("we", "us", or the "Service") handles information when you use notes.handsfree.vc, sign in, record audio, or access your Running Notes mailbox. It also explains the special privacy limitations of the public guest account.
2. Information we collect
- Google or Microsoft sign-in data: the identity provider name, its stable account identifier, your verified email address, and the time the identity was linked. We request the
openid,email, andprofilescopes. We use sign-in to authenticate you and create or find your Running Notes account. We do not intentionally store your Google or Microsoft access token, name, profile photo, contacts, files, or messages. - Account and mailbox data: an internal user ID, email address, account status, IMAP username, securely hashed IMAP password, and mailbox contents.
- Recordings: audio you choose to record and upload, associated timestamps and identifiers, file type and size, and the mailbox messages containing that audio.
- Session and operational data: an essential signed session cookie and server logs such as request events, login provider, user ID, email address, upload size, delivery outcome, error details, and security events. We do not use advertising or behavioral-tracking cookies.
3. How we use information
We use information only to authenticate users, operate accounts and IMAP mailboxes, accept and deliver recordings, display messages, enforce storage and usage limits, prevent abuse, troubleshoot failures, maintain security, and improve user-facing reliability. We do not use Google user data or recordings for advertising, credit decisions, data brokerage, or training machine-learning models.
4. Google user data
Running Notes' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google sign-in data is used only to provide and secure the sign-in and account features users request.
5. Sharing and disclosure
We do not sell or rent personal information. We may disclose information:
- to infrastructure providers that host or transmit the Service, only as needed to operate it;
- to Google or Microsoft as part of the sign-in flow you initiate;
- when you direct the Service or an IMAP client to retrieve or transmit your mailbox data;
- when required by applicable law or necessary to protect users, the Service, or others; or
- as part of a reorganization or transfer of the Service, subject to this policy or notice of materially different terms.
6. Public guest account
The guest account is intentionally shared and public. Anyone with its published mailbox credentials can read guest recordings. Never use the guest account for private, personal, confidential, or sensitive information. Guest source recordings and corresponding mailbox messages are scheduled for automatic deletion after the retention period displayed in the app, normally 24 hours. Cleanup runs hourly, so deletion can normally occur approximately 24 to 25 hours after recording. Technical failures may delay deletion, so the guest account must not be treated as private storage. Deletion from Running Notes cannot revoke copies that someone has already downloaded, cached, forwarded, or otherwise retained.
7. Retention and deletion
Registered-user account records and recordings are retained while needed to provide the Service or until they are deleted by the user where supported, removed by an administrator, or deletion is requested. Deleting a mailbox message through IMAP may not immediately delete the separately stored source recording. Operational logs are retained only as reasonably needed for security and troubleshooting. Residual copies may remain temporarily in backups or logs until they expire.
To request deletion of your account, linked OAuth identity, recordings, or other personal information, email info@handsfree.vc from the address associated with the account. We may need to verify your identity. You may separately revoke Running Notes' Google access from your Google Account settings; revocation prevents future Google sign-in authorization but does not by itself delete data already stored by Running Notes.
8. Security
We use safeguards appropriate to this small service, including TLS in transit, signed secure sessions in production, access controls, network isolation, upload limits, and one-way password hashing. No system is perfectly secure, and we cannot guarantee absolute security. Please use a unique IMAP app password and protect your devices and sessions.
9. Your choices and rights
You can decline OAuth sign-in, sign out, revoke provider authorization, manage mailbox messages through IMAP, and request access, correction, or deletion by contacting us. Depending on where you live, applicable law may provide additional privacy rights. We will respond to valid requests as required by applicable law.
10. Children
Running Notes is not directed to children under 13, or under the higher minimum age required in their country. We do not knowingly collect personal information from children below the applicable age.
11. Changes
We may update this policy as the Service changes. We will publish the revised policy here and change the effective date. Material changes will be highlighted when reasonably practical.
12. Contact
Questions, privacy requests, and complaints can be sent to info@handsfree.vc.