Privacy Policy — Lyunotes
Effective date: August 7, 2026
lyunotech LLC (“we,” “us,” “our”) operates Lyunotes (PC and iOS, including the Glyph license unlock). This Privacy Policy explains what information we collect, why, and how it is handled.
Our approach
Lyunotes lets you choose, notebook by notebook, whether to turn on encryption. When encryption is on for a notebook, its content is encrypted on your device — using a key only you hold — before it is ever saved or synced anywhere. We do not operate a server that stores, transmits, or has any ability to decrypt that content, and neither can a cloud storage service you sync it through. Even for an encrypted notebook, structural details — such as how many files it contains, their sizes, and when they were last changed — may still be visible to your cloud storage provider as part of normal file management, even though the notebook’s content and titles are not.
If you leave a notebook unencrypted, its content is stored as ordinary files — readable like any other file — on your device, and in your own cloud storage if you choose to sync it there (“Bring Your Own Cloud” — a cloud storage service of your choice). Either way, we do not operate a server of our own that holds your notebook content, encrypted or not.
The only information we ever process on servers we control (hosted on Google Cloud) is the minimum needed to operate the optional Glyph license (iOS) and keep the app itself running, described below.
Information we collect
Lyunotes for PC: No account, no sign-in, no server connection. We do not collect any personal information, and no analytics or tracking software is included.
Lyunotes for iOS — Glyph license: To let you unlock Glyph once and use it across up to 5 devices, we use Firebase Authentication to verify who you are. Depending on how you choose to sign in, this may include:
- Your email address (if you sign in via one-time passcode email), or
- An account identifier provided by Google or Apple (if you sign in with Google or Apple), without access to your Google/Apple password or other account data
We also store, tied to that sign-in:
- A record of your Glyph license status (active/inactive)
- A list of devices linked to your license (device type and name you’ve given it, and when each was registered/last used), so you can manage your 5-device limit
- A reference to your App Store purchase (used once to confirm your purchase and prevent duplicate redemption) — Apple, not us, processes your payment details
- A short-lived verification code if you sign in by email, deleted automatically after use
We do not collect your notes, journal entries, files, or any other content you create in Lyunotes through this system — that data never reaches our servers in any form.
When you sign in, or when the app contacts our license system, standard technical data (such as your IP address and basic device information) is processed by Firebase to deliver the service and to protect against abuse. We do not use this data to identify or track you across other apps or websites.
Device integrity check: We use Apple’s App Attest (via Firebase App Check) as an additional signal to help us detect abusive or automated traffic. This produces a device attestation token that does not identify you personally.
Analytics: Google Analytics is disabled in our Firebase project. We do not use advertising SDKs. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not track users across sites or apps, Do Not Track and Global Privacy Control signals do not change our practices.
How we use this information
Solely to operate the Glyph license system: verifying your identity, checking your license entitlement, enforcing the device limit, and preventing purchase fraud/abuse. We do not use it for advertising, profiling, or any purpose unrelated to running the app.
Where this data is stored
Account, license, and device records are stored with Firebase (Google Cloud), in the United States (us-central1 region). This infrastructure is used only for the license system described above — never for your notes or files. Google acts as our data processor for this system and is contractually required to protect your data to a standard no less protective than this policy, and may not use it for its own purposes.
If you are located outside the United States, your license data is transferred to and processed in the United States. For users in the EU/UK, these transfers rely on the European Commission’s Standard Contractual Clauses (and the EU–US Data Privacy Framework where applicable) as implemented in Google Cloud’s data processing terms. We process this data as necessary to perform our contract with you (providing your Glyph license) and for our legitimate interest in preventing fraud and abuse.
How we protect this data
License data is encrypted in transit (TLS) and at rest on Google Cloud infrastructure. Access is restricted to what is necessary to operate the license system. No method of transmission or storage is 100% secure — but your note content is never in our hands to begin with, so this protection only ever concerns the minimal license data described above.
Data retention and deletion
We retain license and device records for as long as your account is active. You can delete your Glyph account and its associated license and device data at any time from Settings within the iOS app, or by contacting us at info@lyunotes.com. Deletion is confirmed by email before it takes effect, and we act on deletion requests within 30 days. A minimal purchase audit record (product and timestamp only) may remain after deletion, no longer linked to your identity. Because Lyunotes does not hold your note content in the first place, deleting your account has no effect on data stored locally on your device or in your own cloud storage — that remains fully in your control at all times.
Your rights
Depending on where you live, applicable law may give you rights over the personal information we hold about you — for example, access, correction, or deletion rights under the GDPR (EU/UK), the CCPA (California), or Japan’s Act on the Protection of Personal Information (APPI). To exercise these rights, contact info@lyunotes.com. We will respond within 30 days (45 days where the CCPA applies).
Children’s privacy
Lyunotes is not directed at children under 13 (or the higher minimum age required in your jurisdiction), and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated effective date at the top of this page.
Contact
lyunotech LLCEmail: info@lyunotes.com