PageNote Privacy Policy
PageNote turns a PDF of lecture slides into page-by-page study notes, and matches a problem set against how far your course has got. This page describes exactly what leaves your device, where it goes, and what is kept.
The short version. Your notes, your handwriting and your PDFs stay on your device. When you ask for AI notes, that one page's text and image are relayed through our server to an AI provider and are not stored by us. The one exception is marking: if you tap Mark it on a problem you solved with Apple Pencil, that one problem's handwritten working is sent too, so the AI can see what you actually wrote. If you record a class, the audio stays on your device and is transcribed on the device; only if you switch on class key points is the text of what the lecturer just said relayed the same way — never the audio. We keep no account, run no analytics SDK in the app, show no ads, and do not track you across apps or websites. Our server does keep a usage record of which feature ran — never what was in it (see section 3).
1. Who we are
PageNote is published by an individual developer. Contact: terrygao907@gmail.com.
2. What stays on your device
- The PDFs you import, and every page image rendered from them
- All generated notes, your own typed notes, and Apple Pencil handwriting — except the working for a single problem at the moment you ask us to mark it (see section 3)
- Problem sets, your answers, and your mistake book
- Class recordings (the audio), their transcripts and translations, and the times at which you turned each page while recording
- Any API key you enter yourself, which is held in the iOS Keychain
None of this is uploaded, backed up to us, or readable by us. Deleting the app deletes it.
3. What is sent, and where
| Data | When | Where it goes | Kept? |
|---|---|---|---|
| The text and image of the page you are generating notes for | Only when you tap Generate, and only after you have given consent in the app | Relayed through PageNote Cloud to the AI provider for your tier | Not stored by us. Held only in memory for the length of the request |
| While you record a class with class key points switched on: the text transcript of roughly the last one to two minutes of what the lecturer said, the text of the slide you are on, the headings already in that page's notes, and a short running summary of the class that the AI itself wrote in the previous round. Never the audio. After class, a page's transcript text is sent again only when you ask for that page or that class to be summarised, or ask for a page to be regenerated with what the lecturer said | Class key points are off until you switch them on, and the switch names the AI provider. Recording, captions and translation work without them and send nothing | Relayed through PageNote Cloud to the AI provider for your tier, exactly like note requests | Not stored by us. Held only in memory for the length of the request. The recording and its transcript stay on your device |
| A random install identifier (a UUID generated on your device) | With every request to PageNote Cloud | PageNote Cloud | Yes — it is how free-trial usage is counted. Not linked to your name, email or Apple ID |
| A usage record: which feature you used, which AI model ran, how much quota it cost, whether it succeeded, how long it took, and the Cloudflare data centre that served it — keyed by a shortened hash of the install identifier | With every request to PageNote Cloud | PageNote Cloud (Cloudflare Analytics Engine) | Yes, for about 90 days. It contains no page text, no exercise questions and no note content — only which feature ran and what it cost us. We use it to see whether the subscription price covers the AI costs |
| A fingerprint (hash) of the document | With note requests | PageNote Cloud | Yes — so that regenerating a page in the same document does not consume trial quota twice. It is a hash, and the document cannot be reconstructed from it |
| Your App Store subscription receipt | When you generate notes as a subscriber | PageNote Cloud, verified against Apple's public keys | Transaction identifiers only, to stop the same purchase being credited twice |
| Your IP address | Every network request, as with any website | PageNote Cloud (Cloudflare) | Used for a per-day request counter on the free path, to stop abuse. The counter expires automatically and is not used to profile you |
If you use your own API key
Not available in the current version. If bring-your-own-key is offered in a future version, requests would go directly from your device to that provider, would not pass through PageNote Cloud, and we would never see the key or the content.
What runs on the device
Speech recognition and translation of a class recording always run on the device, using iOS system frameworks; the audio is not sent to us or to any AI provider. On iPads where Apple's on-device model is available, class key points and after-class summaries may be produced entirely on the device as well, in which case nothing leaves it for those features.
4. AI providers
Depending on your tier and the model you pick, page content may be processed by one of these four companies, and no others:
- Anthropic (Claude models)
- OpenAI (GPT models)
- DeepSeek
- Zhipu AI (GLM models)
What is sent to them: the text of the one page you asked for notes on, and — only if the model you picked can read images — that page's rendered image. When you import a problem set, its text is sent as well. When you tap Mark it on a problem, an image of that one problem's handwritten working is sent so the AI can mark it — only that problem, only when you tap the button, and never automatically. Nothing else: not your other handwriting, not your own typed notes, not your other documents, not any identifier that names you.
If you switch on class key points while recording a class, the text of what the lecturer said in roughly the last one to two minutes is sent as well, together with the text of the slide you are on and the headings already in that page's notes, so the AI can write down what the lecturer added beyond the slide. The audio itself is never sent, and neither are your own notes or handwriting. The same text is sent after class only when you ask for a summary of that page or that class.
If your App Store account is in mainland China, requests do not go through
Cloudflare. They go to a server we operate ourselves in Hangzhou (Alibaba Cloud) at
api.pagenote.com.cn, and from there only to DeepSeek and Zhipu AI — the requests
stay inside mainland China. That server relays and meters exactly as described above; it keeps
no page content, and it writes no usage-analytics record. The same routing applies to class
transcripts.
We have confirmed that each of these four providers offers data protection equal to what this policy promises. All four are used through their paid API tiers, where the provider's own terms state that submitted content is not used to train their models and is retained only briefly for abuse monitoring before deletion (at most 30 days across the four, and zero-retention where the provider offers it). We do not use any provider that trains on API content. If a provider ever changed those terms, we would drop that provider rather than weaken this policy — the app's model list is served from our server, so a provider can be removed for everyone without an app update.
If a request cannot be served by your chosen model, it may be retried with the backup model you selected — that model's provider is named in the consent screen too.
The app names the specific company before you consent, and asks again if you switch to a model from a provider you have not yet approved. You can withdraw consent at any time in Settings — sending stops immediately.
5. What we do not do
- No accounts, no sign-in, no password
- No analytics, telemetry, crash-reporting or advertising SDKs in the app — nothing on your device reports what you do. Our own server records which features were called and what they cost (section 3); that record never contains your content
- No tracking as defined by Apple's App Tracking Transparency — we do not link data to third-party data for advertising, and we do not share data with data brokers
- No selling of data, ever
- No reading of your notes, handwriting or documents
6. Payments
Subscriptions are handled entirely by Apple. We never see your card details, billing address or Apple ID. We only receive the signed receipt that says which product is active.
7. Retention
Page content and class transcripts are never written to disk on our side. Recordings, transcripts and translations are stored only on your device, inside the document they belong to; deleting the recording or the document deletes them. Quota records tied to an install identifier expire within twelve months. Usage records (section 3) are kept for about 90 days and then fall out of the analytics store automatically. The install identifier is stored in the iOS Keychain, which means it survives deleting and reinstalling the app — that is deliberate, and it is the only thing that stops one device from claiming the free trial over and over. Erasing the device clears it. It is a random value, not derived from your device, your Apple ID, or anything about you, and we cannot use it to identify you. If you want the server-side records tied to it deleted, email us (section 9) and we will delete them.
8. Children
PageNote is intended for students in higher and senior secondary education and is not directed at children under 13. We do not knowingly collect personal information from children.
9. Your rights
Because we hold no account and no personal identifiers, there is normally nothing personal to export or erase. If you believe we hold data relating to you, email terrygao907@gmail.com and we will respond within 30 days. Depending on where you live you may have rights under the GDPR, the UK GDPR, the CCPA or the Australian Privacy Act.
10. Changes
If this policy changes materially, the updated date at the top will change and the new version will be published here before the change takes effect in the app.
PageNote 隐私政策
PageNote 把一份 PDF 课件变成逐页的学习笔记,并把习题册按授课进度对到具体页上。 这一页说清楚:什么东西会离开你的设备、去了哪儿、留没留下。
一句话版本。笔记、手写和 PDF 都留在你自己的设备上。点「生成」时, 只有那一页的文字和图片会经我们的服务器转发给 AI 服务商,我们不存。 只有一个例外:你在某道题上点了「批改」,那一道题的手写作答会一起发出去—— 不然 AI 看不见你到底写了什么。 录课的话,录音留在你设备上、在设备上转成文字;只有你打开「课堂要点」,老师刚说的那段文字 才会同样经我们转发——录音本身永远不发。 没有账号,App 里不接任何分析 SDK,没有广告,不跨 App 或网站追踪你。 我们的服务器会记「哪个功能被调用了」,但不记里面是什么(见第 3 节)。
1. 我们是谁
PageNote 由个人开发者发布。联系方式: terrygao907@gmail.com。
2. 只留在你设备上的
- 你导入的 PDF,以及由它渲染出的每一页图片
- 全部生成的笔记、你自己敲的笔记、Apple Pencil 手写——只有你点「批改」的那一道题的 手写作答例外(见第 3 节)
- 习题册、你的作答、错题本
- 课堂录音(音频)、它的转写和翻译、以及录音时你每次翻页的时刻
- 你自己填的 API Key,存在 iOS 钥匙串里
这些都不会上传、不会备份到我们这里、我们也读不到。删掉 App 就一起删了。
3. 会发出去的,以及发去哪
| 数据 | 什么时候 | 去哪 | 存不存 |
|---|---|---|---|
| 你正在生成笔记的那一页的文字和图片 | 只有你点「生成」时,且必须先在 App 里同意 | 经 PageNote 云端转发给你所在档位对应的 AI 服务商 | 我们不存。只在请求期间存在于内存里 |
| 录课且打开了「课堂要点」时:老师最近一两分钟说的话的转写文字、你正停在的那页课件的文字、 这页笔记里已经写着的小标题,以及 AI 自己上一轮写的一小段「这节课讲到哪了」。 永远不发录音。下课之后,只有你点「整理这页 / 整理这节课」或 「结合课堂重新生成」时,那几页的转写文字才会再发一次 | 「课堂要点」默认关着,要你自己打开,打开时会点名 AI 服务商。录音、字幕、翻译不依赖它, 也什么都不发 | 经 PageNote 云端转发给你所在档位对应的 AI 服务商,和笔记请求完全一样 | 我们不存。只在请求期间存在于内存里。录音和转写都留在你设备上 |
| 一个随机的安装标识(设备本地生成的 UUID) | 每次请求 PageNote 云端时 | PageNote 云端 | 存。免费试用额度靠它记账。不与你的姓名、邮箱或 Apple ID 关联 |
| 用量记录:用了哪个功能、由哪个模型生成、扣了多少额度、成没成功、耗时多久、 由哪个机房处理——按安装标识的短哈希分组 | 每次请求 PageNote 云端时 | PageNote 云端(Cloudflare Analytics Engine) | 存,约 90 天。其中没有任何页面文字、题目或笔记内容, 只有「跑了哪个功能、花了我们多少钱」。用途是确认订阅价格能不能覆盖 AI 成本 |
| 文档指纹(哈希) | 随笔记请求 | PageNote 云端 | 存。用来保证同一份文档重新生成某页不会重复扣试用额度。 它是哈希,还原不出文档内容 |
| 你的 App Store 订阅凭证 | 订阅用户生成笔记时 | PageNote 云端,用 Apple 公钥验签 | 只存交易 ID,防止同一笔购买重复入账 |
| 你的 IP 地址 | 每次网络请求,和访问任何网站一样 | PageNote 云端(Cloudflare) | 用于免费通道的按日请求计数,防刷。计数自动过期,不用于给你画像 |
如果你用自己的 API Key
选了服务商并填了自己的 Key,请求从你的设备直接发给那家服务商, 不经过 PageNote 云端,我们既看不到 Key 也看不到内容。每家服务商在 App 里单独授权。
哪些在设备上跑
课堂录音的语音识别和翻译一律在设备上跑,用的是 iOS 系统框架;录音不会发给我们, 也不会发给任何 AI 服务商。在支持苹果设备端模型的 iPad 上,课堂要点和课后整理也可能完全在 设备上生成——那时这些功能一个字都不会离开设备。
4. AI 服务商
按你所在的档位和你选的模型,页面内容可能由下面**四家之一**处理,没有别家:
- Anthropic(Claude 系列)
- OpenAI(GPT 系列)
- DeepSeek
- 智谱 AI(GLM 系列)
发出去的是什么:你点了生成的**那一页**的文字,以及——只有在你选的模型能看图时——那一页的 渲染图。导入习题册时会再发一次习题册的文字。你在某道题上点「**批改**」时,会发出那一道题的 手写作答图片,好让 AI 看见你怎么写的——只发那一道,只在你按下按钮时发,绝不自动发。 除此之外什么都不发:不发你其它的手写笔迹、不发你自己打的笔记、不发你其它的文档、 不发任何能指认到你本人的标识。
录课时如果你打开了「课堂要点」,老师最近一两分钟说的话的文字也会发出去, 连同你正停在的那页课件的文字和这页笔记里已有的小标题,好让 AI 记下老师比课件多讲的东西。 录音本身永远不发,你自己的笔记和手写也不发。下课之后只有你点整理这页或这节课时, 这些文字才会再发一次。
如果你的 App Store 账号在中国大陆,请求不走 Cloudflare,而是走我们自己
在杭州运营的一台服务器(阿里云,api.pagenote.com.cn),并且只转给 DeepSeek
和智谱 AI——请求全程留在中国大陆境内。那台服务器同样只做转发和计量,不保存页面内容,
也不写用量统计记录。课堂转写的文字走同一条路。
我们已经确认这四家提供的数据保护不低于本政策的承诺。 四家全部走各自的付费 API 通道,服务商条款明确写明提交的内容**不用于训练它们的模型**, 只为滥用监测短暂留存后删除(四家里最长 30 天,能选零留存的就选零留存)。 我们不使用任何会拿 API 内容训练的服务商。哪一家改了这些条款,我们会把那一家下架, 而不是放宽这份政策——App 的模型表是从我们服务器下发的,撤掉一家不需要发新版本。
App 会在你同意之前点名具体是哪一家, 你随时可以在设置里撤回——撤回后立即停止发送。
5. 我们不做的事
- 没有账号、不用登录、没有密码
- App 里不接任何分析、埋点、崩溃上报或广告 SDK——你设备上没有任何东西在上报你的行为。 我们自己的服务器会记录调用了哪些功能、花了多少成本(见第 3 节),那份记录里没有你的内容
- 不做 Apple ATT 定义的「追踪」——不把数据与第三方数据关联用于广告,不与数据经纪商共享
- 永不出售数据
- 不读你的笔记、手写和文档
6. 支付
订阅完全由 Apple 处理。我们看不到你的卡号、账单地址或 Apple ID, 只收到那份说明「哪个产品有效」的签名凭证。
7. 保留期
页面内容和课堂转写在我们这边从不落盘。录音、转写和翻译只存在你设备上、放在它所属的 那份文档里;删掉那条录音或那份文档就一起删了。与安装标识关联的额度记录在 12 个月内过期。 用量记录(见第 3 节)保留约 90 天,之后自动从统计库里滚出去。 这个安装标识存在 iOS 钥匙串里,也就是说它删掉 App 再重装依然存在—— 这是故意的,也是唯一挡得住同一台设备反复领免费试用的东西。抹掉设备会清掉它。 它是一个随机值,不由你的设备、Apple ID 或任何和你有关的东西推导出来,我们也无法用它认出你是谁。 想删掉服务端与它关联的记录,发邮件给我们(见第 9 节),我们会删。
8. 儿童
PageNote 面向高等教育和高中阶段的学生,不面向 13 岁以下儿童, 也不会有意收集儿童的个人信息。
9. 你的权利
因为我们没有账号、也没有个人标识符,通常没有属于你个人的数据可供导出或删除。 如果你认为我们持有与你相关的数据,发邮件到 terrygao907@gmail.com,我们会在 30 天内回复。 视你所在地区,你可能享有 GDPR、英国 GDPR、CCPA 或澳大利亚隐私法下的权利。
10. 变更
本政策若有实质变更,顶部的更新日期会随之变化,且新版本会在 App 内相应改动生效前 先发布在这里。