Privacy Policy
There are no accounts, and nothing you write reaches our
servers. The app contains no analytics or advertising code and
does not track you. With sync off, nothing leaves your device at all. What
does travel when you turn sync on is set out precisely in section 3.
Last updated: 19 September 2026
1. What we collect
Starting with what we do not do:
- There is no sign-up, no sign-in, no account. We never ask for your name, email, or phone number.
- The app contains no analytics SDK and gathers no usage statistics.
- It shows no ads and does not read any advertising identifier.
- We do not track you, and we never share or sell data to third parties.
- Crash reports and usage data are not sent to us automatically.
- The contents of your notes and attachments never reach our servers under any circumstances, and neither does your vault password or key phrase.
There is one exception. When you turn on syncing over the internet, your device sends a device identifier and its connection address (IP and port) to our rendezvous server so that it can find your other devices for the same vault. This is what we declare on the App Store under Identifiers ▸ Device ID for the purpose of App Functionality; it is not linked to your identity and is not used for tracking. The feature is off by default, and section 3 sets out exactly what travels when it is on.
2. Where your writing lives
Every note, attachment, folder, and database you create is stored only in a folder on your own device that you chose — the vault. We cannot see its contents and we hold no copy of it.
What is encrypted, precisely
- Note contents are stored encrypted. Each document is encrypted with a key derived from your vault password (XChaCha20-Poly1305). The search index is kept in an encrypted database.
- Attached files are kept as the original files and are not encrypted. This is deliberate: it is what lets another app open and edit a PDF, Word document, or image in place.
-
Exported
.mmpfiles are not encrypted either. The format exists to be opened without a vault password, so once a file leaves the vault it no longer has the vault's protection.
Your vault password is never sent to us and cannot be recovered. If you forget it, we have no way to open the vault for you.
3. Syncing between your devices
Sync is off by default and runs only if you turn it on.
Same-network sync (LAN)
When your Mac, iPad, iPhone, or Windows PC are on the same LAN/Wi-Fi, they exchange data directly with each other. Nothing passes through our servers. The connection is encrypted (QUIC / TLS 1.3). Turning this on makes the app ask for the Local Network permission so it can announce itself and find your other devices.
Syncing over the internet
This links devices that are on different networks. It is off by default everywhere, and the setting is named differently per platform.
- macOS and Windows — Internet sync in settings, linking devices that have opened the same vault.
- iPhone and iPad — Connect to my host in settings. Leave one of your own computers switched on as the host, and your phone reaches it directly from anywhere. The data goes to your own machine.
When it is on:
-
Your device contacts our rendezvous server
(
rv.hannote.com) to find your other devices for the same vault. What the server receives is an opaque identifier derived from the vault's key phrase (it cannot be turned back into the phrase), a device identifier, and the connection address (IP and port). The vault password and the key phrase itself are never sent. - The server's only job is to tell a device where the host is; the data itself travels directly between your devices. Our server does not relay data — relaying is switched off. On networks where your devices cannot connect directly, internet sync therefore does not happen.
- The only thing the server keeps is the registration of a computer you made a host, which is stored in a database. What is stored: a hash of the opaque identifier above (not the identifier itself), that computer's connection address (IP and port), the email address and fixed identifier described below, and the time it last checked in. Registrations from devices that are not hosts are not stored at all. When a host stops checking in, its record is deleted after 30 minutes. The server keeps no connection logs by default.
- Only if you make a computer of yours the host — something you switch on yourself, in the macOS or Windows settings — that computer's registration also carries two things: the vault owner's email address and a fixed identifier unique to the vault. They are there for checking a paid subscription in the future. The identifier is derived from the key phrase but cannot be turned back into it, and unlike the rotating one above it stays the same from day to day — which is what lets a subscription's hosted vaults be counted, and it equally means the server recognises a hosted vault as the same vault over time. iPhone and iPad cannot be a host, so they send neither the email nor this identifier.
-
On macOS and Windows you can change the rendezvous
server address in settings, including running your own so that none of
our servers are used at all. On iPhone and iPad the
address is fixed to
rv.hannote.comand cannot be changed.
4. Permissions the app asks for
- Local Network — to sync with your other devices on the same Wi-Fi. Decline it and everything else in the app still works.
- Camera — used only when you take a photo to put straight into a note. The photo is saved into the vault on your device.
- Files and Photos — used only for files you pick yourself, to attach them to a note or import documents from another app.
5. Children's privacy
HanNote has no accounts and never asks for a name, email address, or age, so it gathers nothing about children either. There is no age restriction on its use.
6. Changes to this policy
If this policy changes, we will update this page and the date above. If a change ever widens what the app collects, we will say so in the app as well.
7. Contact
For any question about privacy, write to help@amatch.co.kr.
AlphaMatch Inc.