Banora · the voice-notes app
Banora Privacy Policy
Who is responsible
The controller under the EU General Data Protection Regulation (GDPR) is:
Ala Eddine Bannour (sole proprietor)
Schulstraße 20, 13347 Berlin, Germany
Email: hi@banora.dev
No data protection officer is appointed; the thresholds of § 38 BDSG are not met.
Where your thoughts live
Your thoughts, topics, and rooms are stored on your device. Voice is transcribed on your device; the audio is deleted immediately after transcription and never leaves your device. Thoughts dictated via Siri are transcribed by Siri under Apple’s terms before they reach Banora. If iCloud Backup is on — it is on by default and can be turned off in Profile — your thoughts are also mirrored to your own private iCloud, which we cannot access. Our servers store none of your content.
AI sorting with OpenAI — only if you consent
If you consent, the text of a new thought is sent through our relay to OpenAI to choose its topic and title, together with your topic names, short excerpts of similar filed thoughts as examples, and short snippets of your past sorting corrections; groups of related notes are named the same way. Requests also carry the note’s language and your device’s time zone, used to resolve dates like “tomorrow”. These requests carry no user identifier and are sent with storage disabled on our side. Your text is not used to train AI models; OpenAI may retain it for up to approximately 30 days for abuse monitoring. You can withdraw consent at any time in Profile — withdrawing is as easy as consenting, and everything except sorting keeps working. If you turn AI sorting on after having used the App without it, thoughts captured while it was off may also be sent once they are sorted or used as examples. If you do not want that, delete those thoughts before enabling AI sorting.
What shows on your screen
The lock-screen widget shows thought text on the lock screen, visible without unlocking your device. Reminder notifications show a thought’s title or text, following your iOS notification-preview settings.
What our servers store
Account-level records only, never note content: account data (your Apple sign-in identity, your email address (your real one, or Apple’s private-relay address if you chose Hide My Email), consent records, subscription status, usage counter, a count of voice notes awaiting transcription), usage-metering and rate-limit records, sanitized purchase records, and short-lived technical server logs (IP address, an approximate location derived from it, your account ID, connection metadata). Subscription status and purchase confirmations are received from RevenueCat and Apple. Telemetry is off, with no way to enable it in the app. We collect no analytics, show no ads, and do no tracking. Even while AI sorting is off, each capture makes one small content-free call to our servers (the entry’s internal ID; the server records the time) to count your free-tier usage.
Who receives data
- OpenAI — AI sorting; thought text, topic names, excerpts, and short correction snippets; no identifier; USA.
- Supabase — backend hosting; account, metering, and billing metadata, no content; Frankfurt, Germany (EU).
- RevenueCat, Inc. — subscription management; your user ID and purchase data; USA.
- Apple — Sign in with Apple and App Store billing; your iCloud mirror is governed by your own agreement with Apple.
We do not sell personal data.
Transfers outside the EU
OpenAI and RevenueCat process data in the USA. These transfers rest on the EU–US Data Privacy Framework where the recipient is certified, and/or on EU Standard Contractual Clauses. You can request a copy of the applicable safeguards at hi@banora.dev.
Legal bases (Art. 6 GDPR)
Contract performance for account, metering, and subscription state (Art. 6(1)(b)); your consent for AI sorting (Art. 6(1)(a)); legitimate interest for rate limiting, abuse prevention, and server logs (Art. 6(1)(f)); legal obligation for purchase-record retention and consent records (Art. 6(1)(c); § 147 AO; Art. 7(1) GDPR).
Providing personal data is neither statutorily nor contractually required; without account data, the App’s account features simply cannot be provided. We use no automated decision-making with legal or similarly significant effect (Art. 22 GDPR); AI sorting only organizes your notes, and you can change any result.
Deleting, exporting, signing out
Profile → Delete Account & Data deletes your server records and wipes the deleting device and your iCloud copy (its removal completes the next time the App runs with iCloud reachable). Your other signed-in devices wipe their local copies when they next come online with a valid session. Only sanitized purchase records are kept, because tax law requires it (see the table below). Profile → export gives you a machine-readable JSON file of your data. Signing out keeps your data on the device.
Your rights
You have the rights of access, rectification, erasure, restriction, portability, and objection (Art. 15–21 GDPR), and you can withdraw consent at any time (Art. 7(3)). Where we process data on legitimate interest (server logs, rate limiting), you may object at any time (Art. 21 GDPR). Use the in-app export and deletion tools or contact hi@banora.dev. You can complain to a data protection supervisory authority (Art. 77 GDPR); competent for us is the data protection supervisory authority of our German federal state.
Children
AI sorting rests on consent; under Art. 8 GDPR as applied in Germany this requires a minimum age of 16.
Changes to this policy
We update this policy when the app’s data handling changes and indicate the new effective date. Material changes to what leaves your device are presented in the App.
How long data is kept
| Where | What | How long |
|---|---|---|
| Your device | Thoughts, topics, rooms | Until you delete them or delete the app/account |
| Your device | Audio recordings | Deleted immediately after on-device transcription |
| Your private iCloud | Mirror of your thoughts | Until you turn Backup off, delete the data, or delete your account |
| OpenAI | Text submitted for sorting/naming | Up to approximately 30 days (abuse monitoring), then deleted; not used for training |
| Our backend | Usage-metering records | 180 days; deleted immediately upon account deletion |
| Our backend | Rate-limit records | 90 days; deleted immediately upon account deletion |
| Our backend | Telemetry (collection off) | Any rows deleted after 90 days |
| Our backend | Sanitized purchase records (incl. your account ID and the Apple transaction identifier) | 10 years — § 147 AO (German tax law); survive account deletion |
| Our backend | Account data | Until account deletion |
| Our hosting provider (Supabase) | Technical server logs | A short period — currently approximately 7 days |
| RevenueCat / Apple | Subscription and payment records | Per their own policies |