Privacy Policy
SOFT-JP ("we") sets out below how we handle your information in Anota, a Markdown note service (the "Service").
1. Information we collect
| Category | Details | How we collect it |
|---|---|---|
| Account information | Name, email address, Google / Microsoft account identifier, and the profile information you enter | Information received when you sign in with Google / Microsoft, your input, and registration by your team administrator |
| Your data | Notes, drafts, version history, comments, reactions, uploaded images, and folder, subscription and favorite settings | Your actions |
| Activity logs | Type and time of actions such as signing in and creating or updating notes, IP address, and browser type (User-Agent) | Recorded automatically when you use the Service |
| API keys | The API keys you issue (the key itself is stored within your own separated data so that you can show it again later) | When you issue a key |
| Team settings | IP allowlist and Slack / Microsoft Teams webhook URLs (team use only) | Input by your team administrator |
Signing in
For personal use, you sign in with your Google account. The first time you sign in, we create your account with the name, email address and account identifier we receive from Google. We identify you by Google's permanent account identifier. The Service never receives your password.
For team use, you sign in with the Google or Microsoft account whose email address your team administrator registered.
2. How we use information
- To provide the Service (signing in, saving, showing and publishing notes, sending notifications, and so on)
- To let team administrators review usage (activity logs, team use only)
- To prevent and investigate unauthorized access and to handle failures
- To send important notices about the Service
- To improve the Service
3. Browser storage and analytics
The Service stores a token that keeps you signed in and your display settings (such as the sidebar width and state, and the display language) in your browser's localStorage. When you enter the password of a public folder, the viewing token is stored in sessionStorage, which is cleared when you close the tab.
The sign-in page loads Google's sign-in feature (Google Identity Services). Google may use cookies to sign you in.
The product site (anota.info) uses Google Analytics to understand how it is used. Google Analytics collects access information with cookies, but it does not include information that identifies you, such as your name or email address. You can opt out with the Google Analytics Opt-out Browser Add-on. The app itself (app.anota.info and team addresses) does not use Google Analytics.
Advertising
On the free plan and on the product site, we show ads from Google AdSense, a third-party ad service. We do not show ads on the paid plan.
Third-party vendors, including Google, use cookies to serve ads based on your prior visits to the Service and other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to the Service and other sites.
You can opt out of personalized advertising in Google's Ads Settings, and opt out of third-party vendors' cookies at www.aboutads.info. See Google's advertising policies for how Google handles information.
To show ads on note pages of the free plan, the URL of the page (including the number that identifies the note), browser and device information, your IP address and cookie information are sent to Google. We never send the body or title of your notes to ad vendors for advertising.
Markdown viewer and browser extension
In the Markdown viewer (app.anota.info/p/viewer) and when you drop a file onto the notes screen, the file is displayed only within your browser and is not sent to our servers. It is sent only when you save it as a note by pressing "Save to Anota" or "Save as note".
The browser extension "Anota Markdown Viewer" reads the content of Markdown files (such as .md) that you open, and their URL (when "Add the original URL" is enabled in the settings), and passes them within your browser to the Markdown viewer above for display. While handing over, the content is kept temporarily inside the extension and is deleted once passed (or after 10 minutes if it is not picked up). The extension never sends the content or URL to our servers or to third parties, and it does not collect usage data or show ads.
4. Sharing with third parties
We do not share your information with third parties except:
- With your consent
- When required by law
- When necessary to protect a person's life, body or property and it is difficult to obtain your consent
Notes in folders you make public, and notes visible through share links, can be read by anyone on the internet. If your team administrator registers a webhook, the note title and the name of the person who updated or commented on it are sent to that destination.
5. Service providers and storage location
| Provider | Purpose |
|---|---|
| Amazon Web Services (Tokyo region) | Running the Service and storing your data and activity logs |
| Google LLC | Authentication at sign-in, advertising, and analytics on the product site |
| Microsoft Corporation | Authentication at sign-in (team use only) |
6. Security
- All communication is encrypted with HTTPS.
- We store data separately for each user (for personal use) or each team, and check access permissions every time a note is opened.
- API keys are verified using hashes. Only the person who issued a key can show it (no one else, including administrators, can see it).
- Team administrators can restrict access by IP address.
7. Retention and deletion
- Notes moved to the trash are permanently deleted after 30 days, including their body, history and comments.
- Activity logs are kept for one year and then deleted.
- To delete your account and data, contact us at the address below. For team use, please also talk to your team administrator. Deleted data cannot be restored.
8. Requests for disclosure, correction and deletion
You may ask us to disclose, correct, stop using or delete the information we hold about you. Contact us at the address below. We will respond in accordance with the law after confirming your identity.
9. Changes to this policy
We may change this policy as needed. When we do, we will announce the changes and when they take effect in the Service.
10. Contact
SOFT-JP
Email: suzuki@soft-jp.net