Last updated September 12, 2026
Kapy Notes Privacy Policy
Kapy Notes is provided by Kapybara LLC and is built around a simple promise: your notes belong on your device, not on our servers.
Your notes stay local unless you turn on sync
Notes, preferences, and layout settings are stored in the application-support storage on your device. Kapy Notes works fully offline and never sends a note anywhere until you sign in and turn sync on.
What sync stores, and what we can read
Sync is optional and off until you enable it. When you do, your notes are encrypted on your device before they are sent, using a key derived from an encryption passphrase that you choose and that never leaves your device. We cannot read your notes, and neither can anyone who obtains a copy of our database.
What our servers hold is the sealed result and the little that syncing cannot work without: your email address, an identifier for each note, when it last changed, whether it was deleted, and how many bytes it occupies. We do not hold your notes in readable form, your encryption passphrase, or your recovery key.
Because we never have your passphrase, we cannot reset it or recover your notes for you. That is why a recovery key is shown once during setup. You can sign out at any time, which removes the key and the session from that device and leaves your notes on it, and you can delete your account and everything stored for it from Settings.
Notes you share with other people
You can share a note with another Kapy Notes account, or with a group of them. A shared note is encrypted with a key that only the members of that shared space hold: each member's copy of the key is sealed to a public key that their own device generated, and their private half never leaves their device. Our servers store and relay the sealed notes and the sealed keys, and can read neither.
To make that work, our servers additionally hold: which accounts are in which shared space, the email address an invitation was sent to, each member's public keys, and an identifier for each shared space and note. Those are the facts sharing cannot work without. Inviting someone sends them an email with a link that only works for the address it was sent to.
One honest limit. Because our servers hand out members' public keys, a server that lied about whose key is whose could, in principle, read a shared space. The app protects against this by remembering every member's key the first time it sees it and warning you if it changes, and by showing a key fingerprint you can compare with the other person in conversation. Until you have done that, shared notes are protected against a server that only looks, not one that actively deceives. Your own unshared notes are not affected by this: nobody but you holds their key.
When you remove someone from a shared space, or leave one, they stop receiving anything new right away and the space's keys are changed. What they had already downloaded stays on their devices, as it would with anything you had already sent them.
Voice notes and transcription
A voice note is recorded on your device and stays there. It is saved with the note it belongs to and plays back from the device, and if sync is on it is encrypted before it is stored or sent, exactly like a picture. Recording needs no account and no network: on its own, a voice note goes nowhere.
Turning a recording into text is a separate thing, and it is off until you turn it on. The app asks first, names who does the work, and says what is sent. If you decline, recording still works and nothing leaves your device.
When you do turn it on, the recording is sent to our server and passed to Cloudflare Workers AI, which transcribes it and writes a short summary. This is the one thing Kapy Notes sends readable rather than sealed, because a recording cannot be transcribed without being listened to. We ask Cloudflare not to log the audio or the text and not to use either to train or improve any model. Neither Cloudflare nor we keep the recording once the text comes back. What we do keep is the accounting a monthly limit needs: how many seconds were transcribed, when, and a fingerprint of the audio, so that retrying a request that failed does not charge you for it twice. The transcript and the summary are returned to your device and stored with the note, encrypted like the rest of it.
You can turn transcription off again at any time in Settings. Recordings you made before turning it on are not sent unless you ask for them.
Blocking and reporting
If you block someone, we store the email address you blocked against your account, so that we can stop delivering their invitations. If you unblock them, the record is deleted.
If you report an invitation, a note, or a person, we store what you tell us: the reason you chose, anything you wrote in the box, and the addresses and identifiers involved. Reports are kept after the reporting account is closed, and the address they were filed from is kept with them, because a report is a record about somebody else's behaviour and harassment is a thing that makes people close accounts.
Reporting a note is the one place where the text of an encrypted note is stored readable by us, and it never happens on its own. The app asks, in the moment, whether to send a copy of that one note; if you say no, the report is still filed and still acted on, and the note stays encrypted. If you say yes, that note's text is sent to us unencrypted, for that report, and nothing else in your account is affected.
Currency exchange rates
Currency calculations normally use exchange-rate data fetched from Frankfurter through its api.frankfurter.dev endpoint. If Frankfurter cannot return a usable rate snapshot, the app may use ExchangeRate-API through its open.er-api.com endpoint as a fallback. These requests do not include your notes, calculations, or other app content. Like any network request, the selected rate provider receives ordinary connection information such as your IP address and may process it under its own terms and privacy policy.
Update checks on macOS and Windows
The desktop app checks once a day whether a newer version has been released, by requesting a small file from dl.kapynotes.com that contains only the latest version number. The request carries no notes, calculations, or other app content, and no identifier for you or your device. As with any network request, our infrastructure provider, Cloudflare, receives ordinary connection information such as your IP address in order to serve the file.
Nothing is downloaded or installed unless you press Update. The mobile apps do not check for updates; the App Store and Google Play handle that.
Purchases
Buying in the mobile app goes through the App Store or Google Play. Buying Pro Lifetime on kapynotes.com goes through a RevenueCat-hosted Stripe checkout. Payment details belong to the store or Stripe and never reach us. What reaches us is that a purchase happened, which product it was, and the payment provider's transaction id, which we keep against your account so the same purchase can never be granted twice.
You can buy in the mobile app without an account. The app then identifies itself to RevenueCat with an id generated for the device, which says nothing about you, and the purchase joins your account the first time you sign in. Web checkout asks you to sign in first and sends your Kapy Notes account id to RevenueCat so Pro reaches the right account immediately. RevenueCat and Stripe receive ordinary transaction and connection information, such as your IP address, and handle it under their respective privacy terms.
Plan checks while signed out
When you are not signed in, the app checks about once a day whether the Forever Free limits are in effect, by requesting a small file from api.kapynotes.com that says only that, how long the Pro trial lasts, and how many notes Forever Free keeps editable. The request carries no notes, calculations, or other app content, and no identifier for you or your device. As with any network request, the server that answers receives ordinary connection information such as your IP address. When you are signed in, the app learns the same thing from your account instead.
This website
kapynotes.com uses SnowAnalytics, a privacy-friendly analytics tool, in its cookie-less mode: it sets no cookies, stores nothing in your browser, and does not track you across sites or between visits. It honours the Global Privacy Control and Do Not Track browser signals. The site uses no advertising trackers or contact forms. Cloudflare processes ordinary network information to deliver the site securely and reliably.
The purchase page lets you sign in with your email address and a six-digit code. It sends those directly to our account API and keeps the returned session token only in the page's memory until it opens checkout; it does not put that token in local storage. Signing in on the purchase page sends no notes, encryption keys, or app content.
Children
Kapy Notes is a general-purpose notebook and is not directed at children under 13. Used without sync it collects no personal information at all. With sync on, the only personal information it collects is the email address the account is created with, and we do not knowingly create accounts for children under 13.
Deleting your data
Delete individual notes inside Kapy Notes whenever you like. Removing the app and its application data removes the locally stored Kapy Notes data from that device, subject to your operating system's backup behavior.
If you turned on sync, you have an account, and you can close it from Settings › Sync in the app with Delete account. That erases the account and everything stored for it: the synced notes, their attachments, and the wrapped encryption key. This happens immediately and irreversibly. Nobody can undo it, ourselves included, because the key that unwraps those notes goes with it. If you own shared spaces, you are asked to hand each one to another member or stop sharing it first, so that closing your account cannot silently take a family's notes with it. If you cannot reach the app, email us from the account's address and we will do it for you; see deleting your account for both routes.
We also delete accounts nobody returns to. If an account is not signed in to for two years we may close it and erase everything stored under it, after emailing the address on the account at least thirty days beforehand. Signing in resets that entirely. We keep a record of which day an account was last used, to a day's precision, for no other purpose than this. Notes held only on your own devices are untouched by it: they are not ours to delete.
Changes to this policy
If Kapy Notes ever starts handling data differently, this page will be updated before that version is released, and the date at the top will change.
Who is responsible
Kapy Notes is published by Kapybara LLC, registered in Wyoming, United States and operating from Delhi, India. Kapybara LLC is the controller of the personal data described above: your email address, the sealed note data held for accounts with sync turned on, and the membership and invitation records of any shared spaces you are in. Used without sync, the app stores nothing with us to be a controller of.
Contact
Questions about privacy can be sent to hello@kapynotes.com.