Jot Privacy Policy
Effective date: July 29, 2026
Last updated: July 29, 2026
This Privacy Policy applies to the iOS and iPadOS versions of Jot (also known as 拾记, and referred to as “Jot,” the “App,” “we,” or “us”). It explains what information we process, why we process it, how we protect and delete it, and how you can contact us.
1. Information We Process
1.1 Account and authentication information
When you sign in with an email verification code, we process:
- Your email address;
- A user identifier created for your account;
- A random installation identifier created for the current App installation;
- Login sessions, verification results, and security state needed to authenticate you.
The random installation identifier is used for authentication, session management, and abuse prevention. It is not used for advertising or cross-app tracking. Login tokens are stored in secure storage on your device.
1.2 Content you create or upload
To provide recording, synchronization, search, and image features, we process:
- The text of Memos you create;
- Tags, recorded dates and times, and related editing state;
- Images you actively select from your photo library and upload;
- Technical metadata needed to manage images, such as file type, dimensions, size, and checksum.
Jot does not access your photo library unless you choose an image or use a save-to-photos feature. Jot does not request camera or microphone access.
1.3 Information stored locally on your device
The following information is primarily stored on your device:
- Preferences such as language, appearance, first day of the week, and export quality;
- Whether link confirmation and the Face ID lock are enabled;
- Your login session and random installation identifier.
Face ID authentication is performed on your device by Apple’s LocalAuthentication framework. We do not receive, store, or upload your facial image, Face ID template, or other biometric data. We only receive system results such as authentication success, failure, or cancellation.
1.4 Network and operational information
When the App connects to our services, we and our infrastructure providers may process limited technical information needed to deliver network requests, protect the service, diagnose failures, and prevent abuse. This may include an IP address, request time, request path, response status, and error type.
The App currently does not integrate third-party advertising SDKs, does not use information for targeted advertising, and does not track you across apps or websites.
2. How We Use Information
We process information only to:
- Create and maintain your account;
- Send and verify login codes;
- Store, synchronize, search, and display your Memos, tags, and images across your devices;
- Provide image upload, receipt-image generation, save, and system sharing features;
- Provide the optional local Face ID privacy lock;
- Maintain security, limit abuse, diagnose failures, and improve service reliability;
- Process account deletion requests and respond to support or privacy requests;
- Comply with applicable legal obligations.
We do not sell your personal information. We do not use your Memos or images for advertising, user profiling, or training generative artificial intelligence models.
3. Device Permissions
Jot may request the following system permissions:
- Photo library read access: Only to let you choose images to attach to a Memo;
- Photo library add access: Only to save a receipt image you create to the system photo library;
- Face ID access: Only for the optional local privacy lock that you enable.
Each permission is used only for the corresponding feature. You may decline a permission and can change it later in system settings. Declining a permission affects only the feature that depends on it.
4. Storage and Service Providers
Jot’s online services use Cloudflare infrastructure, including Workers, D1, and R2:
- Account user identifiers, Memos, tags, and related records are stored in D1;
- Images you actively upload are stored in a private R2 bucket;
- Images are not exposed through public storage addresses. Image access requires authentication and an ownership check.
Cloudflare acts as an infrastructure provider and may process relevant data across its global network under its terms and privacy policy. Because the service is delivered through a global network, your information may be processed outside your country or region. We take reasonable steps to require appropriate protection from our service providers.
We disclose information only:
- To providers that supply hosting, storage, networking, or authentication capabilities needed by the App;
- To comply with applicable law, a court order, or a lawful request from an authorized public body;
- To protect the rights, safety, and property of users, the public, the App, or others;
- With your explicit consent.
We do not sell or rent your information to data brokers, advertising networks, or unrelated third parties.
5. Retention and Deletion
We retain your account and content for as long as needed to provide Jot and maintain your account.
- When you delete an individual Memo, it is immediately hidden from the normal interface and query results. Some soft-deletion records may remain until account deletion is completed to maintain synchronization consistency and related storage records;
- When an image is removed from an active Memo, we schedule deletion of the corresponding private storage object. If the initial deletion fails, the system retries it;
- You can request account deletion in Settings → Account → Delete account;
- After you submit an account deletion request, the account enters a 14-day cancellation period. During this period, you can sign in and explicitly cancel the deletion;
- After the cancellation period ends, we delete the account, Memos, tags, associated records, and private images, and schedule deletion of the identity account;
- Limited residual copies may remain for a reasonable period in restricted backups, disaster-recovery systems, or security records, or where retention is legally required. Such copies expire under the applicable backup cycle or are deleted when legally permitted.
We may retain specific information where required by law or where necessary to establish, exercise, or defend legal claims.
6. Your Choices and Rights
You can:
- View and edit your own Memos and tags in the App;
- Delete individual Memos;
- Manage photo and Face ID permissions in system settings;
- Sign out in the App;
- Request deletion of your account and associated data in the App;
- Cancel account deletion during the 14-day cancellation period;
- Contact us to request access, correction, deletion, or information about data we hold about you.
Depending on the law where you live, you may have additional data protection rights. We may need to verify your identity before completing a request involving account data.
7. Children’s Privacy
Jot is not designed specifically for children. We do not knowingly collect personal information from children below the applicable age in their location. If you believe a child has provided personal information without appropriate parental or guardian consent, contact us so that we can investigate and take appropriate action.
8. Security
We use reasonable technical and organizational safeguards, including:
- HTTPS encryption for data in transit;
- Short-lived access tokens and a PKCE authentication flow;
- System secure storage for session credentials;
- Authentication and ownership checks for private images;
- Restricted server-side resource access and abuse protection for write operations;
- An optional local Face ID privacy lock.
No method of transmission or storage can be guaranteed to be completely secure. If a security incident requires notice under applicable law, we will take the required steps.
9. External Links
Memos may contain external links that you enter. If you choose to open an external website, that site processes information under its own privacy policy. This Privacy Policy does not apply to third-party websites or services.
10. Changes to This Policy
We may update this Privacy Policy when our features, data practices, or legal obligations change. We will update the “Last updated” date at the top of this page. If a change materially affects your rights or how we process information, we will provide additional notice through a reasonable method.
11. Contact Us
For questions, comments, or requests concerning this Privacy Policy or our processing of personal information, contact:
Privacy contact email: contact@meoware.app
We will respond to reasonable requests within the period required by applicable law.