Privacy Policy
Welcome to InNotes! This Privacy Policy outlines how we collect, use, and protect your personal information.
1. Controller
InNotes is operated by Marco Visin (Switzerland), the sole controller of the personal data described here. Contact: info@innotes.me.
2. Information We Collect
- Account data: name, email, identity from chosen sign‑in provider.
- Content data: notes, contacts, jobs, tags and files you upload.
- Data about your contacts: when you save a LinkedIn contact, information about that person (who is usually not an InNotes user). See section 3.
- Technical data: IP address and user agent used for account access logs and security.
- Payment data: handled by Stripe; we store your subscription status and Stripe subscription ID.
- LinkedIn session data (optional, only if you enable automation): your LinkedIn session cookies, captured by the InNotes browser extension. See section 8 below.
- Extension usage statistics (on by default, can be turned off): anonymous counts of which extension screens and features are used, identified only by a random per‑install identifier. See section 12.
- AI connector usage statistics: counts of which InNotes tools your connected AI assistant calls, and which kind of assistant it is — never the contents of those calls. Identified by a one‑way hash of your account. See section 12.
- AI connector activity record: separately from the statistics above, and kept inside your account, we record which assistants you have connected, when each was first and last used, and how many calls each has made. This one is linked to your account, not to a hash. See section 12.2.
3. Data About Other People (Your Contacts)
When you save a LinkedIn contact, InNotes stores information about that person — a third party who is typically not an InNotes user and has not interacted with InNotes directly. This section explains that processing, as required by Article 14 GDPR.
What we store about a contact:
- Name, LinkedIn public profile handle and LinkedIn member identifier.
- Profile picture (see note on hosting below), current company and location.
- Tags, notes and AI‑generated "memories" you attach to them (see section 5).
Where this data comes from:
- You capture it — through the browser extension or manual entry while you browse LinkedIn.
- Automated refresh — if you have enabled automation and have a live LinkedIn session, a background job re‑reads your saved contacts' public LinkedIn profiles (roughly every 30 days) to keep their name, company, location and photo current, using your LinkedIn session as described in section 8.
Profile pictures are re‑hosted. InNotes stores its own copy of a contact's profile picture on Cloudflare R2 and serves it from a publicly reachable URL, so the current image keeps displaying even after LinkedIn's own link expires.
Legal basis — legitimate interests (Art. 6(1)(f)): our and your legitimate interest in maintaining a personal, CRM‑style record of your professional network. If you are the subject of such a record, you can object to this processing at any time, and can ask us to give you access to, correct, or erase the data we hold about you — even without an InNotes account — by contacting info@innotes.me. We will act on a valid request across the contact records and memories that concern you.
Public notes about a contact. A note you attach to a contact is private by default. Notes you explicitly mark as public may be visible to other InNotes users who track the same LinkedIn person, shown in their "shared with you" view for that person. Publishing a note publicly is an optional, paid capability that is off by default; private notes and AI memories are never exposed this way.
4. Purposes and Legal Bases
- Provide the service (contract performance art. 6(1)(b) GDPR).
- Maintain your contact records and keep contact details current, including the automated refresh in section 3 (legitimate interests art. 6(1)(f)).
- Security and fraud prevention (legitimate interests art. 6(1)(f)).
- Billing via Stripe (contract performance art. 6(1)(b)).
- Website analytics only with your consent (art. 6(1)(a)).
- Browser‑extension and AI‑connector usage statistics, to understand how much they are used and which features to improve (legitimate interests art. 6(1)(f)). These are counts of feature and tool names, never your content — see section 12, including how to object.
- The AI‑connector activity record, to know which assistants are connected to an account, support you when one misbehaves, and decide what to keep maintaining (legitimate interests art. 6(1)(f)). This is separate from the statistics above, stays inside your account, and is objected to by writing to us rather than with the switch — see section 12.2.
- Communications about the service (legitimate interests or consent where required).
5. Automated Processing and AI
InNotes offers optional, AI‑assisted features. When you use one, the relevant content is sent to OpenAI (see section 7) to generate the result. No decision producing legal or similarly significant effects is made solely by automated means (art. 22 GDPR) — every output is advisory and shown to you for your own judgement. These features include:
- Job matching score (about you): your CV, job preferences and a job description are sent to OpenAI, which returns a 0–100 "matching score" with a short rationale and strengths/weaknesses. It gates access to nothing.
- AI "memories" (about your contacts): short AI‑written facts about a contact; each memory's text is sent to OpenAI to build a searchable embedding stored alongside it. Memories are always private to you and can be listed, edited and deleted by you.
- Other AI helpers: CV analysis, tag suggestions, importing a job from a PDF, and drafting follow‑up messages. Depending on the feature, the content sent to OpenAI may include your CV, job preferences, job descriptions, your notes, and the names of the contacts involved.
6. Data Security
We take reasonable measures to protect your personal information from unauthorized access, use, or disclosure.
7. Processors, Sub‑processors and International Transfers
The InNotes web application is hosted on Vercel in the European Union (Frankfurt region); one nightly maintenance job runs in a United States region. We use the following sub‑processors:
- Vercel — application hosting and serverless compute (EU/Frankfurt for the app; US for a nightly maintenance job).
- Neon — managed PostgreSQL database (the primary datastore for your account, contacts, notes, memories and jobs).
- Cloudflare R2 — media storage: re‑hosted contact profile photos (public URLs) and the attachments, CVs and PDFs you upload.
- OpenAI — the AI features in section 5; depending on the feature, receives your CV, job‑preference, job‑description, note and memory text, and the names of contacts involved.
- Google (Maps Directions API) — computes travel time to a job; receives your saved home location and the job's location.
- Stripe — payment processing (we store subscription IDs).
- Email delivery via an SMTP provider (transactional, onboarding and reminder emails).
- Matomo — analytics for the website, the browser extension and the AI connector, self‑hosted by us rather than run by a third party. It receives page, feature and tool names and counts only, never your content. See section 12.
- LinkedIn automation service (only if you enable automation) — an InNotes‑operated scraping service and an n8n workflow component that receive your LinkedIn session cookies to act on your behalf on LinkedIn. See section 8.
The web application is hosted in the EU (Frankfurt). Some data is processed by sub‑processors located outside the EEA/Switzerland — including OpenAI, Google, Stripe and Cloudflare (United States) and the InNotes‑operated LinkedIn automation service. Where personal data is transferred outside the EEA/Switzerland, appropriate safeguards such as the Standard Contractual Clauses and/or the EU–US Data Privacy Framework are relied upon where applicable. We do not sell your personal data or your contacts' personal data.
8. LinkedIn Integration and Automation (optional)
InNotes offers optional features that act on your behalf on LinkedIn — for example searching for jobs and resolving the stable identifier of contacts you add. These features are off by default and only operate if you explicitly enable automation and consent to the collection of your LinkedIn session.
- What we collect: when you enable automation, the InNotes browser extension reads your LinkedIn session cookies (such as
li_atandJSESSIONID) from your browser and sends them to InNotes. - Why: these cookies let InNotes make authenticated requests to LinkedIn on your behalf to provide the automation features you turned on (job search, contact identity resolution and the automated contact refresh in section 3).
- Who processes them: the cookies are sent to an InNotes‑operated scraping service (and, for job automation, an n8n workflow component) solely to perform those actions. They are not sold or shared for advertising.
- Legal basis: your explicit consent (art. 6(1)(a) GDPR), given when you enable automation.
- Storage and security: the session cookies are encrypted at rest (AES‑256‑GCM) and access is restricted to the automation features.
- Retention and withdrawal: you can disable automation at any time from your profile settings, which deletes your stored LinkedIn session and stops all automation. The session is also discarded when it expires.
Using these features means InNotes accesses LinkedIn with your credentials; you are responsible for ensuring this is compatible with your agreements with LinkedIn. See our Terms & Conditions.
9. Data Retention
- Access and activity logs (IP address, user agent, last‑access records and the AI‑connector activity record in section 12.2) are retained for 365 days and then automatically purged.
- Everything else — your account, contacts, notes, memories, jobs, tags, attachments and media — is retained for the life of your account and removed when you delete your account.
Account deletion is self‑service (see section 10) and removes your data across our database and media storage.
10. Your Rights
- Access, rectification, erasure, restriction, and portability.
- Object to processing based on legitimate interests — the contact records in section 3, the extension usage statistics in section 12.1 (switchable off in the extension popup), the AI‑connector statistics in section 12.2 (switchable off in Profile → Preferences), and the AI‑connector activity record in section 12.2, which has no self‑service switch: write to info@innotes.me and we set a flag on your account that stops it being recorded, then erase what is there.
- Withdraw consent at any time (for website analytics and for LinkedIn automation).
- Lodge a complaint with your supervisory authority.
You can export your data and delete your account from your profile settings or by contacting us. People who are not InNotes users but are saved as someone's contact can exercise these rights over the data held about them by contacting info@innotes.me.
11. Cookies
See our Cookie Policy for details about essential and analytics cookies and how to manage your preferences.
12. Usage Statistics
Two parts of InNotes report aggregate usage statistics to our self‑hosted Matomo instance, so we can see how much they are used and which features are worth improving: the browser extension, and the AI connector (MCP). Both are deliberately limited to counting. Section 12.2 also covers a record that is not statistics and never reaches Matomo — the AI‑connector activity record kept inside your account. Website analytics are separate and covered by your cookie consent — see our Cookie Policy.
12.1 Browser extension
- What is sent: the name of the screen opened (for example "profile" or "job") and the name of the action performed (for example "note created", "job saved"), from a fixed, predefined list.
- What is never sent: your notes, memories, contacts, contact names, LinkedIn profile URLs or identifiers, job details, search terms, your email address or your InNotes account identifier.
- How the extension is identified: by a random identifier generated on your device when the extension is installed. It is not derived from your account and is not linked to your InNotes user; it only lets us tell one installation from another and recognise repeat use.
- Cookies: none. These statistics are sent without cookies, and no analytics cookie is attached to them.
- Where it goes: a Matomo instance operated by us. The statistics are not shared with third parties and are never used for advertising or profiling.
- Legal basis: our legitimate interest in understanding how the extension is used so we can maintain and improve it (art. 6(1)(f) GDPR). We have weighed this against your interests: the data is anonymous, limited to a predefined list of feature names, carries none of your content, and cannot be used to single you out or to make decisions about you.
- Your right to object: open the extension popup and clear the "Help improve InNotes by sharing anonymous usage statistics" checkbox. Reporting stops immediately, on every device signed in with that browser profile.
12.2 AI connector (MCP)
When you connect an AI assistant to InNotes over MCP, we record that a call happened, which tool it used and which kind of assistant made it. We do not record what the call was about.
Two separate records come out of this, and they are governed differently. The usage statistics below leave your account for our analytics and can be switched off. The activity record described after them stays inside your account, is what tells you and our support staff which assistants are connected to it, and is not covered by that switch.
- What is sent: the protocol method (for example "tools/call"), the name of the tool used (for example "remember" or "list_contacts") from the fixed set of tools we publish, and which assistant is calling — Claude, Claude Code, ChatGPT, Cursor and a few others we recognise, or simply "other".
- What is never sent: the arguments of the call. That is where your note text, contact names, memories and search terms are, and they never leave your account for our analytics. The assistant's raw identification string is not forwarded either, only the name we matched it to.
- How you are identified: by a one‑way cryptographic hash of your InNotes account identifier. It cannot be reversed to your account, but — unlike the extension's random installation identifier — it is derived from it, and it is stable, so it lets us count distinct users and recognise repeat use. We consider this pseudonymous rather than anonymous, and we treat it as personal data.
- Cookies: none. These calls are server‑to‑server and carry no cookie.
- Where it goes: the same Matomo instance operated by us, tagged so the connector can be told apart from the extension and the website. Not shared with third parties, never used for advertising or profiling.
- Legal basis: our legitimate interest in understanding how the AI connector is used so we can maintain and improve it (art. 6(1)(f) GDPR). Weighed against your interests: the content of your work is excluded by design, what is recorded comes from a closed vocabulary, and the identifier cannot be reversed or used to make decisions about you.
- Your right to object: go to Profile → Preferences and clear "Allow anonymous usage statistics from the AI connector". Reporting to our analytics for your account stops immediately. It does not switch off the activity record described next, which exists for a different purpose. You can also write to info@innotes.me if you prefer.
Activity record (inside your account)
- What is recorded: for each assistant you connect — its name from the same closed list as above — when you first used it, when you last used it, and how many calls it has made. Nothing about what the calls contained.
- How you are identified: by your InNotes account, directly. Unlike the statistics above this is not hashed, because the whole point is to be able to tell you, and our support and administration staff, which assistants are on your account.
- Where it goes: nowhere. It stays in our database, is never sent to our analytics or to any third party, and is included in your data export (section 10) so you can see exactly what it holds.
- Why we keep it: our legitimate interest in operating the service (art. 6(1)(f) GDPR) — recognising which integrations an account actually uses, supporting you when a connector misbehaves, and deciding what to keep maintaining. Weighed against your interests: it is four values per assistant, carries none of your content, and is deleted with your account.
- Retention: 365 days after the last use of that assistant, then purged automatically — the same limit as the access logs in section 9.
- Your right to object: because this rests on legitimate interests, you can object to it under art. 21 GDPR. There is no self‑service switch for it — the one in Profile → Preferences governs the statistics above — so write to info@innotes.me. We erase what is there and set a flag on your account that stops it being recorded again; your connectors keep working exactly as before. It is also deleted in full when you delete your account.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page.
14. Contact Us
Email: info@innotes.me