NoteBeeZ Privacy Policy
Effective date: 4 September 2026
Version: 2026-09-04
This Privacy Policy explains how personal data is handled when you use the NoteBeeZ Android application, its Cloudflare-hosted backend, and the related public pages at https://notebeez.badluckstudios.com (together, the Service).
1. Controller and contact
For account administration, security, subscription verification, support, and operation of the Service, the controller is:
Bad Luck Studios e.U.
Feßtgasse 10/24
1160 Wien
Austria
Commercial register number: FN 683233f
Commercial register court: Handelsgericht Wien
Email: notebeez@badluckstudios.com
Privacy requests may be sent to the email address above.
An organization using NoteBeeZ for its business may determine why and how its beekeeping, personnel, and operational data is used. For that organization-controlled content, the organization may be a separate controller and Bad Luck Studios e.U. may act as its processor. Members should first address workplace-data questions to their organization owner or employer. Bad Luck Studios e.U. remains responsible for its own controller activities described above.
2. Scope and important distinction between device and cloud data
NoteBeeZ is free to download and may show its interface as a read-only preview, but ordinary additive diary use requires a registered account, an active organization membership, and an active server-confirmed organization entitlement. The entitlement is required to create or make non-deletion edits, import or restore, upload or synchronize new/non-deletion-updated content, change organization settings, expand team/assignment access, use AI or analytics, create or rotate QR access, or connect/select/synchronize Google Calendar. Subject to authentication, role, scope, and safety checks, existing supported records remain readable and exportable after entitlement ends. The controls that remain available are safety reporting/moderation; deletion of an authorized photo or voice draft; confirmed deletion of local-diary data, an account, or an organization; moderation removal; pending-invitation revocation, member suspension/removal/permission reduction, and assignment revocation; QR-request denial/read resolution; Calendar disconnect/task unsync; and acceptance of the server version when discarding a sync conflict. Historical records remain correction-first rather than generally deletable from the app.
"Local-first" describes how an authorized diary operation may be stored on the Android device first, remain usable during a temporary loss of network connectivity, and synchronize through the Cloudflare backend later. It does not describe a free, accountless, device-only diary. Legacy device records from an earlier app state or data that has already been synchronized may remain locally until the device user migrates or deletes it, clears app storage, or uninstalls the app.
The Android app disables Android system backup for its private application data. Device-cached data nevertheless remains under the control of the device user and may exist in user-created export or backup files. Deleting a cloud account does not remotely erase local copies, exported files, another member's device, Google Calendar events, or backups held outside the Service.
3. Data we process
Depending on the features you choose, we process the following categories:
- Account and profile data: email address, display name, optional avatar or phone field, preferred language, time zone, authentication provider, Google account subject identifier, and email-verification status. Ordinary users authenticate through Google Sign-In or a one-time email link. For a narrowly pre-created reviewer or support account only, we also process the submitted assigned password long enough to compare its SHA-256 value with a deployment-secret verifier; the submitted password is not stored in D1 or application logs.
- Organization and authorization data: organization name and settings, memberships, roles, permissions, apiary or hive assignments, invitations, invitation status, and activity records needed to show who performed an action.
- Beekeeping and business content: apiaries, optional address or coordinates entered by a user, hives, queens, inspections, treatments, feeding, harvests, movements, equipment, pests and disease observations, varroa observations, notes, photos, tasks, costs, revenues, and other records entered by authorized users.
- Voice and AI data: audio selected for transcription, duration, transcript, prompt or question, the smallest relevant authorized record context, generated draft segments, warnings, reviewed output, model identifiers, and usage totals. A generated draft is not added to the production diary until a user confirms it.
- AI safety-report data: only after a signed-in user opens the in-app report dialog, selects a reason, and confirms, we receive the selected reason category, pseudonymous account and organization identifiers, the output type, an opaque reference to the existing organization-scoped AI job, an optional segment position, submission/status timestamps, and rate-limit records. The report request has no free-text field and does not send or create a second copy of the displayed answer, question, transcript, source records, photo, or audio.
- Private-workspace safety-report data: only after a signed-in organization member opens the report dialog beside another member or supported shared item, chooses a bounded reason, and confirms, we receive pseudonymous account, organization, and membership bindings; the allowlisted target kind and opaque existing target ID; reason, status, resolution and timestamps; and hourly rate-limit records. The Worker—not Android—resolves the existing target, author/uploader, tenant, and permitted scope. The request has no free-text field and does not copy the target's profile, title, note, caption, photo, audio, or other content. Reporter identity is withheld from the ordinary owner/administrator review projection but remains narrowly available to authorized Bad Luck Studios personnel for abuse prevention, rights requests, security, and exceptional conflict review.
- Calendar data: encrypted Google OAuth tokens, granted scopes, selected calendar identifier and name, task and event identifiers, synchronization state, reminders, and the task information placed into Google Calendar at the user's request.
- Subscription and purchase data: Google Play product, base-plan and offer identifiers, purchase token in encrypted form, a token hash, subscription state, expiry, auto-renewal and acknowledgement status, hashed order or account binding, Real-time Developer Notification identifiers, and verification results. We do not receive or store full payment-card or bank-account details.
- Device, synchronization, and security data: a random installation identifier, app/build and Android version, device model when diagnostics are submitted, locale, time zone, notification setting, sync cursors, mutation identifiers, token and QR hashes, session metadata, rate-limit records, redacted error codes, request identifier, and hashed IP address or user-agent where needed for sign-in protection and audit security.
- Legal and support data: accepted legal-document versions and time, export and deletion requests, communications with support, and optional diagnostics you deliberately submit. Diagnostic descriptions are filtered for obvious email addresses, bearer credentials, and token-like strings, but you should still avoid entering diary content or secrets.
- Public-page request data: ordinary HTTP request and security data that Cloudflare necessarily processes to deliver and protect the website and Worker. We do not intentionally place advertising or cross-site analytics cookies on these pages.
Please do not enter personal data about another person unless you are authorized to do so. NoteBeeZ is not intended for human medical records or special-category personal data. Beekeeping observations about animal health are not a substitute for professional veterinary records or legally required registers.
4. Sources of data
We receive data directly from you, from authorized members of your organization, from your Android device during synchronization or an explicitly confirmed AI or private-workspace safety report, from Google when you use Google Sign-In, Calendar, or Play Billing, and from OpenAI only as the response to an AI request that you initiated through our Cloudflare Worker.
5. Purposes and legal bases
We process personal data only where a legal basis applies:
- Contract, Article 6(1)(b) GDPR: create and authenticate an account; provide local-to-cloud synchronization, organizations, access control, private media, exports, requested AI functions, Calendar synchronization, support, and subscription entitlements; and take steps you request before entering a contract.
- Legal obligations, Article 6(1)(c) GDPR: comply with applicable accounting, tax, consumer-protection, court, regulatory, security-incident, and data-protection obligations.
- Legitimate interests, Article 6(1)(f) GDPR: secure accounts and tenants; receive and review explicitly submitted AI and private-workspace safety reports; investigate reported abuse; remove content or restrict access where proportionate; prevent fraud, harmful output, malicious reporting, replay, retaliation, and unauthorized access; keep narrowly scoped audit evidence; diagnose failures; enforce service limits; defend legal claims; and operate a reliable Service. We balance these interests against users' rights, require reviewer conflict checks, withhold reporter identity from ordinary workspace review, and minimize or hash identifiers where practical.
- Consent, Article 6(1)(a) GDPR, where specifically requested: only for an optional activity for which consent is the appropriate basis. Android permissions and Google authorization screens also control device or provider access, but granting a technical permission is not automatically the legal basis for every processing activity. You may withdraw consent for future processing at any time without affecting prior lawful processing.
If your employer or organization is the controller of organization content, it is responsible for selecting and communicating its legal basis, including any workplace monitoring or employment-law requirements. Because consent is often not freely given in an employment relationship, an organization should not rely on employee consent without legal review.
6. Optional permissions and connected services
- Microphone: used only when you start recording or dictation. Local Android speech recognition can be chosen where available. Cloud AI transcription sends selected audio through our Worker to OpenAI.
- Camera: used only when you take a photo or scan a QR code.
- Notifications: used for local reminders and operational notices if allowed by the device user. NoteBeeZ does not currently require a third-party push-notification provider.
- Google Sign-In: optional alternative to email magic-link registration. Google provides the identity claims needed to verify the sign-in.
- Assigned reviewer or support sign-in: not a public registration method. If Bad Luck Studios e.U. supplies a credential for controlled app-store review, testing, or support, the Worker accepts only the preconfigured account email and compares the submitted high-entropy password with a deployment-secret SHA-256 verifier. Attempts are rate-limited by account and network address; the credential can be rotated, disabled, or revoked.
- Google Calendar: separate and optional. The requested scopes are limited to reading the calendar list and managing events owned by NoteBeeZ. Tokens are encrypted in D1 and are not returned to other organization members. Disconnecting attempts to revoke tokens and remove linked NoteBeeZ events. If Google access has already been revoked or Google is unavailable, you may need to remove remaining events directly in Google Calendar.
- Google Play Billing: used for the NoteBeeZ Premium organization subscription. Google processes checkout and payment credentials. The Worker verifies purchases with Google before enabling paid features.
- AI: optional and user-initiated. The Worker sends only the selected audio or text and bounded authorized context to OpenAI. Text-model requests use
store: false. We do not use diary content to train our own model, and we do not authorize providers to use it for advertising. Provider-side transient security or abuse-monitoring retention may still apply under the applicable provider terms and enterprise/API configuration. The separate in-app report action is sent only after confirmation, remains in Cloudflare D1, and is not forwarded to OpenAI. - Private team reporting and moderation: optional and user-initiated. A confirmed report remains in Cloudflare D1 and is not sent to Google or OpenAI. Authorized owners/administrators may review a reporter-confidential projection and may remove the referenced content, suspend the bound non-owner member where role rules permit, record another action, or dismiss the report. A reviewer cannot decide their own submission or a report against them. Exceptional conflicts may be handled by narrowly authorized Bad Luck Studios personnel. NoteBeeZ has no public feed or one-to-one messaging and therefore does not maintain a social user-block list; organization membership, roles, assignments, suspension, and removal control interaction.
7. Recipients and processors
We do not sell or rent personal data. We do not use diary content for advertising and the app contains no advertising SDK or third-party analytics SDK by default. Data is disclosed only as needed to operate requested features, comply with law, protect rights and security, or complete a business transfer subject to appropriate safeguards.
The principal service providers are:
- Cloudflare, Inc. and its affiliates: Workers runtime, D1 database, private R2 object storage, Email Service delivery, network security, and operational request logging.
- Google LLC and its affiliates: identity verification when Google Sign-In is chosen, Google Calendar when connected, and Google Play subscription checkout, status, and verification.
- OpenAI, L.L.C. and its affiliates: optional transcription and text-model processing initiated by the user through the Worker.
Each provider processes data under its own terms and data-protection commitments. Their current policies should be reviewed as part of production release and vendor management. We may also disclose the minimum necessary information to professional advisers, courts, authorities, or law enforcement when legally required or necessary to establish, exercise, or defend legal claims.
8. International transfers
Cloudflare, Google, or OpenAI may process data outside Austria or the European Economic Area. Where Chapter V GDPR applies, transfers are to be covered by an applicable adequacy decision, the EU Standard Contractual Clauses with supplementary measures where required, or another lawful transfer mechanism. Provider infrastructure and legal terms can change, so the production controller must keep transfer assessments and processing agreements current.
9. Retention
Our production retention periods are:
- Local app data: until the device user deletes it in NoteBeeZ, clears app storage, or uninstalls the app. User-created exports and backups remain wherever the user saved or shared them.
- Account profile: while the account is active. Confirmed account deletion immediately revokes active sessions, removes memberships, disconnects Calendar integrations, and replaces direct profile identifiers with an anonymous deleted-user value. Organization content that the user created may remain as an organization record without an active profile attribution.
- Assigned reviewer or support credential: only while the narrowly pre-created account is needed for its controlled purpose. The raw password is not stored in D1; its deployment-secret verifier is rotated or removed when the credential is replaced or withdrawn. Rate-limit records follow the applicable short security window.
- Cloud organization content, audit history, sync history, AI drafts, retained photos/audio, Calendar links, and subscription state: while the organization exists. Authorized photo or retained-voice deletion and moderation removal take the affected item out of active use, but tombstones and organization audit history may remain until organization deletion so offline devices can synchronize safely and authorized owners can investigate changes. Other historical diary records are correction-first rather than generally individually deletable in the app.
- Organization deletion: access is frozen immediately. Private R2 media and prepared exports are deleted immediately where possible and retried automatically on failure. Production D1 organization data is purged after 30 days. No restoration service is promised during that period.
- Voice audio: by default, the device audio file and any temporary uploaded copy are deleted after successful transcription. If the user explicitly chooses to retain audio, it remains until the user deletes it or the organization is purged. Transcripts and accepted records follow organization-content retention.
- Prepared export files and private-media manifests: 7 days, then their R2 objects and artifact mappings expire. Expired export job metadata may remain with the organization until organization deletion.
- Email sign-in and short-lived authorization material: email magic links expire after 15 minutes, email exchange codes after 2 minutes, and Google Sign-In nonces and Calendar OAuth state after 10 minutes. Expired rows are removed by scheduled maintenance. Access tokens expire after 15 minutes. Rotating refresh-session rows expire after 30 days and are then removed.
- Synchronization receipts: 90 days. Other change and tombstone records remain with the organization as described above.
- AI safety reports: at most 90 days from submission, then automatically deleted by scheduled maintenance. They contain no copied AI output or free-text description. Account deletion anonymizes the profile but does not extend this deadline; organization purge deletes reports sooner through tenant-cascade deletion. A strictly necessary legal hold may apply only as described below.
- Private-workspace safety reports: at most 90 days from submission, then automatically deleted by scheduled maintenance; their hourly rate-limit counters expire after the applicable window. They contain no copied reported content or free-text allegation. Account deletion anonymizes the profile but does not extend the deadline, and organization purge deletes the report sooner. The underlying organization item follows the ordinary content schedule unless an authorized moderation decision soft-deletes it. A strictly necessary legal hold may apply only as described below.
- Redacted support diagnostics: 30 days.
- Scheduled maintenance run records: 90 days.
- Completed or cancelled deletion-request receipts: 180 days after completion or last update. Pending or failed deletion requests remain until resolved so deletion is not silently abandoned.
- Processed Play billing notification and verification-attempt records: 400 days. The organization's current encrypted purchase token and subscription state remain while the organization exists so entitlement can be verified, restored, and protected from fraud.
- Support correspondence and legal claims: only as long as needed for the request or dispute, normally no more than 24 months after closure, unless law or an active claim requires longer.
- Records required by law: for the specific statutory period. Accounting or tax records that Bad Luck Studios e.U. is legally required to retain may ordinarily be kept for up to seven years under Austrian requirements, or longer where a pending proceeding legally requires it. We do not keep unrelated diary content merely because a billing record must be retained.
Scheduled deletion is not instantaneous in distributed systems. Short backup, cache, provider, or disaster-recovery remnants may persist until overwritten under the relevant provider cycle, isolated from ordinary use. Data may be held longer only where necessary to comply with law, preserve evidence of a security incident, resolve a payment or deletion failure, or establish, exercise, or defend legal claims. Access is restricted during such a hold.
10. Security
We use HTTPS, tenant and role checks, assignment-scoped authorization, rotating and revocable sessions, hashed one-time and QR tokens, a deployment-secret verifier and rate limits for the narrowly assigned reviewer or support password, Android Keystore protection for app credentials, server-side encryption for Google and Play tokens, private R2 buckets, request-size limits, idempotency and report rate-limit controls, immutable core report evidence, reviewer conflict checks, and logs designed to exclude request bodies, diary content, credentials, email addresses, transcripts, safety-report bodies, reporter identities, and raw provider responses.
No service is perfectly secure. Users must protect their device and email or Google account, and an authorized reviewer or support recipient must also protect any assigned credential. Keep the app updated, use only intended invitation recipients, and report suspected unauthorized access promptly.
11. Organization members and workplace transparency
An organization owner controls invitations, roles, scope assignments, subscription, organization-wide export, and organization deletion. Authorized owners or managers may see activity history and work content within their scope. NoteBeeZ is not designed for covert employee surveillance, continuous location tracking, contact-book collection, or background microphone recording.
An AI safety report is not placed in the organization's ordinary activity feed or owner export, because exposing the reporter through those operational tools could discourage safety reporting or create workplace retaliation risk. The report remains available to appropriately authorized Bad Luck Studios personnel for safety review and to the reporting person through an authenticated data-subject request where legally required. An organization export still contains the underlying organization AI job/output under the ordinary content rules, but not the separate report row.
A private-workspace safety report is likewise excluded from ordinary activity and organization export. An owner or administrator reviewing it in the app sees the existing target, reason, status, and age, but not reporter identity. The reviewer must not try to identify or retaliate against a reporter. Core submission evidence cannot be rewritten; only bounded review status and outcome fields can change, and a terminal outcome cannot be reopened. The report remains available to appropriately authorized Bad Luck Studios personnel for abuse prevention, exceptional conflict review, security, legal obligations, and authenticated rights requests. The underlying organization content remains independently visible or exportable under its ordinary authorization and retention rules until it is deleted.
An employer or organization using NoteBeeZ must provide members with its own privacy information, use proportionate permissions, establish a lawful basis, honor labor and works-council rules, avoid entering unnecessary personal information, and respond to requests concerning organization-controlled data. Bad Luck Studios e.U. cannot determine those purposes for the organization.
12. Automated processing
NoteBeeZ produces heuristic risk flags, operational indices, summaries, and AI suggestions. These may be inaccurate and do not create legal or similarly significant decisions about a person. The Service does not use personal data for solely automated employment decisions, credit decisions, insurance decisions, biometric identification, or advertising profiles. Users must review AI drafts before saving them and must apply professional judgment before acting.
13. Your GDPR rights
Subject to the conditions and exceptions in applicable law, you may request:
- access to personal data and information about its processing;
- correction of inaccurate data;
- deletion;
- restriction of processing;
- portability of data you provided where the legal requirements apply;
- objection to processing based on legitimate interests; and
- withdrawal of consent for future processing where consent is the legal basis.
You may access, correct, export, or delete much of your data directly in the app. AI and private-workspace safety reports are deliberately excluded from an organization owner's operational export; a reporting person can request access to their report through the address below. A report subject may also ask about applicable processing, but access may be limited where disclosure would adversely affect another person's rights, confidentiality, security, or abuse-prevention measures. Send requests to notebeez@badluckstudios.com. We may request proportionate identity verification. We generally respond within one month; that period may be extended by up to two further months for complex or numerous requests as permitted by Article 12 GDPR.
Organization-controlled data may require coordination with the organization that acts as controller. A request does not override another person's rights, legal retention, ownership of organization records, or the need to preserve evidence of a valid transaction or security event.
You also have the right to complain to a supervisory authority, in particular in the EEA state of your habitual residence, workplace, or alleged infringement. In Austria:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien
Austria
https://www.dsb.gv.at
14. Children
The Service is intended for adults carrying out personal or professional beekeeping operations and is not directed to children. You must be at least 18 years old to create a cloud account or purchase a subscription. Do not submit a child's personal data through diary notes or media.
15. Changes
We may update this Policy when the Service, providers, law, or retention practices change. A new effective date and version will be shown. Material changes will be presented in the app or otherwise communicated where required. If acceptance is legally or contractually required, cloud use will pause until the current documents are reviewed.
16. Official legal references
This Policy is designed around the information duties in Articles 12 to 14 and the rights in Articles 15 to 22 of the EU General Data Protection Regulation. Information about Austrian data-subject rights and complaints is available from the Austrian Data Protection Authority.
This document is a product-specific disclosure, not legal advice. Bad Luck Studios e.U. should have qualified Austrian/EU counsel confirm the final production configuration, controller/processor allocation, international-transfer safeguards, employment use, and translations before launch.