Privacy Policy
Last updated: 2026-07-19
This Privacy Policy explains how Dizitart (a sole proprietorship registered in Kolkata, West Bengal, India — "Dizitart", "we", "us", "our") handles information in connection with the Spoolnote mobile application ("Spoolnote", "the App").
The short version: Spoolnote collects nothing automatically. There are no accounts, no analytics, no telemetry, and no background reporting of any kind. There is exactly one exception, and you control it entirely: if you choose to send us a bug report, the App shows you precisely what will be sent and lets you edit or delete any of it first. That report is anonymous — it carries no name, no email, and no identifier of any kind.
Your recordings, transcripts, and notes are never part of that — Spoolnote never sends them anywhere, and a bug report doesn't contain them. Everything below explains what that means in practice.
1. What We Don't Collect
Dizitart does not collect, receive, transmit, or have access to any of the following — not automatically, and not in a bug report either:
- Your voice recordings
- Transcripts generated from your recordings
- Summaries and chat conversations produced by the on-device AI assistant
- Entry titles, tags, or search queries
- Your name, email, or phone number — the App has no field for any of them, so there is nothing to send
- Any account identifier — there are no accounts
- Any device identifier or advertising identifier — the App does not generate or transmit one at all
- Location data
- Contacts
- Analytics, usage statistics, or behavioral data
- Automatic crash reports or background diagnostic reporting
There is no sign-up, login, or account of any kind. Nothing is sent to us in the background, ever, under any circumstances.
The one exception is what you type. If you send a bug report (Section 4), we receive the message exactly as you wrote it — so if you choose to put something identifying in it, we'll have that. Nothing else in a report identifies you.
We do not sell, rent, or license your data, and we do not share it with any third party for compensation — for advertising, profiling, or any other purpose. This applies to everything described in this policy, including bug reports you send us, and it applies regardless of where you live, including under India's Digital Personal Data Protection Act, 2023 (DPDP), the EU's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
2. What Happens On Your Device
Recording, on-device transcription, search indexing, tagging, on-device AI summarization, and the AI chat assistant — including the local vector index that lets chat find relevant entries (retrieval-augmented generation) — all run entirely locally on your device, using a local database file stored in the App's own private storage area. Chat uses the same on-device AI model as summarization; asking a question, whether about a single entry or across all of them, sends nothing off your device.
If you leave "Save chat history on this device" enabled in Settings (it is on by default), your chat conversations are stored in that same local database, alongside your recordings and transcripts, and are never transmitted anywhere. You can turn the setting off so conversations aren't kept, and "Clear all chat history" in Settings deletes what's already stored.
None of this data is transmitted anywhere. Uninstalling the App or deleting an entry removes it from your device; Dizitart has no copy to delete on our end, because we never had one.
3. Network Activity
Spoolnote makes network connections in only three situations, all of them started by you:
- AI model downloads. Spoolnote no longer ships with a bundled model, so on first launch it takes you to a model-selection screen where you download at least one transcription model before the App is usable; a separate model for summarization and chat is an optional download you can add later, and you manage models, in Settings. In each case the App downloads the model file directly from Hugging Face's public infrastructure (
huggingface.co) and verifies its integrity via checksum before use. Whether it is the required first-launch download or a later optional one, this is a direct device-to-Hugging-Face transfer; Dizitart is not a party to it and does not see or log it. - In-app purchases. Subscribing to Spoolnote Premium is handled entirely by Apple's App Store or Google Play Store billing infrastructure. Your payment details are never seen by Dizitart — Apple/Google process the transaction and tell your device whether you're entitled to the subscription; that's the only information the App receives, and it's not sent to Dizitart either.
- Sending a bug report. If — and only if — you tap "Report a bug" in Settings and then tap "Send report", the App sends your report to a server operated by Dizitart. This is the only case in which Dizitart receives any data from you. Section 4 describes it in full.
No analytics SDK, no advertising SDK, no automatic crash-reporting SDK, and no A/B testing framework is included in Spoolnote. Nothing here runs on its own — each of the three cases above happens only in response to something you deliberately do.
4. When You Send a Bug Report
Reporting a bug is entirely voluntary. If you never use the feature, Dizitart never receives anything from you.
When you tap Settings → "Report a bug", the App opens a review screen showing you the exact contents of the report before anything is sent. You can edit or delete any part of it, and nothing is transmitted until you tap "Send report". Whatever is in the message box at that moment is what gets sent — nothing is added afterwards.
What a report can include:
- Your description of the problem — whatever you type.
- App and OS version — e.g. "Spoolnote 1.0+1 · android 14". This is the whole of the device information we receive. It contains no device ID, no advertising ID, and nothing else that identifies you or your handset individually.
- This session's debug log — a short, in-memory list of recent errors and events from the App (timestamps, error messages, and possibly technical stack traces). It exists only while the App is running and is discarded when you close it. It is prefilled into the message box so you can read it, shorten it, or delete it entirely before sending.
- Your IP address. As with any internet request, our hosting provider necessarily sees the IP address the report was sent from. We do not store it in the report or use it to identify or track you.
Where it goes. The report is sent over an encrypted (HTTPS) connection to a Cloudflare Worker operated by Dizitart, which turns it into an issue in Dizitart's private GitHub issue tracker. Only Dizitart can see it. Cloudflare and GitHub act as our service providers in handling this data — see Section 8.
No images, ever. A report is text only. Spoolnote cannot take a screenshot — it has no screen-capture capability at all — and never sends images of any kind.
Reports are anonymous. There is no name field, no email field, no account, and no device identifier. The App has nothing to attach to your report that would tell us who sent it, and the report itself carries nothing of the kind. This is how the App is built, not a promise about how we behave: we cannot identify you from a report even if we wanted to.
The one exception is you: if you type something identifying into the message — your name, your email, details about yourself — we receive it, because we receive the message exactly as you wrote it. That's your choice to make, and you can see and edit the whole message before sending.
What it's used for. Diagnosing and fixing the bug you reported. That's all. Nobody replies to reports — there's no address to reply to — and they are never used for analytics, profiling, advertising, or marketing, and never sold or shared for compensation.
How long we keep it. Bug reports are kept for up to 12 months from submission, or until you ask us to delete them, whichever comes first. To have a report deleted, email support@dizitart.com — see Section 7.
Legal basis (GDPR). An anonymous report — app version, OS version, and a technical debug log — generally isn't personal data at all, since it identifies nobody. If a report does contain personal data because you chose to type it in, then where the GDPR applies we rely on your consent, given when you tap "Send report" after reviewing the contents. You can withdraw it by asking us to delete the report; withdrawal doesn't affect processing already carried out.
International transfers. Dizitart is based in India, and Cloudflare and GitHub process bug reports on servers outside your country. Where the GDPR applies, these transfers are covered by those providers' standard data-processing terms, which incorporate the European Commission's Standard Contractual Clauses.
5. Data Storage & Backup
Your recordings, transcripts, and app database are stored only in Spoolnote's private app storage on your device, and are explicitly excluded from cloud backup (android:allowBackup="false" on Android; the iOS Documents directory is flagged excluded-from-backup). This means the data does not leave your device via automatic phone backups either. If you want a copy elsewhere, use the App's own export/share feature for individual entries — that's the only way your entries leave the device, and only when you choose it. Exports go wherever you send them; they don't come to us.
Bug reports you choose to send are the one category of data held on Dizitart's systems rather than your device; Section 4 covers them.
6. Children's Privacy
Spoolnote does not knowingly direct itself at children under 13, and collects nothing automatically from any user regardless of age. Because bug reports are anonymous, the only way we could ever hold a child's personal data is if they typed it into a report themselves. If you believe that has happened, contact us at support@dizitart.com with enough detail to identify the report and we'll delete it.
7. Your Rights
For everything on your device — your recordings, transcripts, entries, tags, and searches — there is nothing for us to access, correct, export, or delete, because we never receive it. It lives solely on your device, under your control, at all times, and you can delete any or all of it by deleting entries in the App or uninstalling it.
For a bug report you've sent us, the picture changed when we made reports anonymous, and we want to be straight with you about the tradeoff.
Because a report carries no name, no email, no account, and no device identifier, we usually hold nothing that counts as your personal data — an app version, an OS version, and a technical log identify nobody. That's a genuine privacy gain. But it cuts both ways: we also can't tell which report is yours. Rights like access, correction, and deletion all depend on connecting data to a person, and we deliberately hold nothing that makes that connection. Under the GDPR (Article 11), a controller that can't identify someone isn't required to collect extra information just to service such requests — and we'd rather stay unable to identify you than start collecting identifiers so we could.
We're not using that as a way to refuse you. If you can describe your report well enough for us to find it — roughly when you sent it, what the bug was, distinctive wording — we will delete it, and we'll help you identify it if we can. Under India's DPDP Act 2023, the EU's GDPR, and California's CCPA, depending on where you live, your rights over data we can identify as yours include access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Email support@dizitart.com and we aim to respond within 30 days. If you're not satisfied with our response, you have the right to complain to your data-protection authority: the Data Protection Board of India under the DPDP Act, or your local supervisory authority under the GDPR.
How deletion actually works. Once we've identified the report, we delete it within 30 days, and it's gone from our side. A report is a single text issue, so deleting it is a real delete — there's no copy of it anywhere else in our systems. GitHub, like any hosting provider, may retain its own operational backups briefly under its standard terms; that's outside our control and applies to their infrastructure, not to anything we hold. And every report ages out after 12 months regardless of whether anyone asks.
CCPA specifically. We do not sell or share your personal information as those terms are defined by the CCPA, and we never have. There is no account or service tier that could discriminate against you for exercising these rights.
Breach notification. If a security breach ever affects personal data you've sent us, we will notify the relevant authorities as required under the DPDP Act, GDPR, and other applicable law. Because reports are anonymous and we hold no contact details, we have no way to notify affected people individually — so we would announce it publicly instead, through an in-app notice and the App's release notes.
8. Third-Party Services
Spoolnote's third-party touchpoints are:
- Cloudflare — hosts the Worker that receives bug reports. https://www.cloudflare.com/privacypolicy/
- GitHub (Microsoft) — stores bug reports as issues in Dizitart's private repository. https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
- Hugging Face — hosts the AI models you can choose to download. https://huggingface.co/privacy
- Apple / Google — app distribution and billing. https://www.apple.com/legal/privacy/ · https://policies.google.com/privacy
Cloudflare and GitHub process bug-report data on our behalf as service providers, under their own terms. Hugging Face and Apple/Google receive no data from Dizitart about you — your device deals with them directly, and your use of those services is governed by their own privacy policies.
9. Grievance Officer / Contact
In accordance with applicable Indian IT rules and the DPDP Act, the following is our designated contact for privacy-related queries, data-rights requests, or complaints:
Dizitart (sole proprietorship), Kolkata, West Bengal, India Email: support@dizitart.com
We aim to acknowledge privacy-related queries promptly, and to resolve data-rights requests within the 30 days described in Section 7.
10. Changes to This Policy
We may update this Privacy Policy from time to time; the "Last updated" date above will reflect the most recent revision. Material changes will be reflected in the App's release notes or an in-app notice where practical.