Privacy
Updated 2026-10-01
Galactus provides Noter.
Notes on your device
Noter stores your notes as files on your device.
Local search runs on your device.
The iOS app stores downloaded notes, drafts, and recovery copies in its protected app storage.
Exporting a note sends a copy to the app or location you choose.
Account and sync
Galactus sign-in uses your email address and account ID.
The sync service stores your account ID, vault IDs, device public keys, storage use, and encrypted file data.
Vault names are stored as plaintext account metadata visible to the sync service.
These records support sign-in, device access, sync, and account storage limits.
Your device encrypts note and file contents before it uploads them.
The sync service does not receive your vault password or the keys that decrypt your notes.
Service requests also expose network information, such as your IP address, to the service providers that receive them.
Storage and recovery
Convex stores the sync records and encrypted files.
Separate encrypted recovery archives are stored in Vercel Blob.
Committed sync history and recovery archives have no automatic expiry in the first iOS release.
Moving a note to Trash does not remove its history or recovery copies.
Signing out does not delete local notes or drafts.
Deleting the app removes its local storage, but does not delete the server copies.
Tracking and beta feedback
The Noter iOS app has no advertising or tracking SDK.
The app does not send note content to advertising services.
Apple handles TestFlight installation, crash reports, and feedback under its own privacy terms.
Feedback that you send can include the text and screenshots that you choose to share.
Your data
You can export notes from the app.
You can delete a synced vault in Settings in the iPhone app or in Settings → Sync in the Mac app.
You can delete your Galactus account in Settings in the iPhone app.
This deletes your Noter account record, synced vaults, history, and stored encrypted files from the sync service.
Convex backups keep a copy for up to seven days. Recovery archives keep a copy until they are deleted.
To request access, correction, or deletion of account data, email team@galactus.dev.
A server deletion request must also cover stored history and recovery archives.