Skip to content

Privacy Policy

1. Privacy at a Glance

The following information provides an overview of what happens to your personal data when you visit this website or use the Sidenotes desktop app.

2. Data Controller

Dennis Schneider
Vahlenhorst 20
26127 Oldenburg
Email: [email protected]

3. Data Collection on This Website

3.1 Server Log Files

The hosting provider of this website automatically collects and stores information in server log files that your browser transmits automatically. These include:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname of the accessing device
  • Time of the server request
  • IP address

This data is not merged with other data sources. The basis for data processing is Art. 6(1)(f) GDPR (legitimate interest in the secure operation of this website).

3.2 Cookies and Tracking

This website does not use cookies for tracking or advertising purposes. We do not use analytics tools like Google Analytics.

We may use Umami, a privacy-friendly, open-source analytics tool that operates without cookies and does not collect any personal data. Umami is GDPR-compliant and only records anonymized, aggregated usage data.

4. Purchase and License Activation

Purchase and license activation of Sidenotes is handled through Lemon Squeezy (Lemon Squeezy, LLC), who acts as Merchant of Record. During purchase, the data necessary for payment processing (name, email, payment information) is processed by Lemon Squeezy. Sidenotes itself only receives the data required for license validation (email address, license key). Lemon Squeezy’s privacy policy: lemonsqueezy.com/privacy

5. Data Processing in the Desktop App

5.1 Local-First Architecture

Sidenotes is a local-first desktop application. All notes, recordings, and configuration data are stored exclusively on your device. We do not operate any cloud synchronization and have no access to your content.

5.2 Speech Recognition via Whisper

Sidenotes uses OpenAI Whisper as a local speech recognition model by default. With local transcription, audio processing happens entirely on your device. Audio data never leaves your computer and is not transmitted to our servers or any third party unless you explicitly configure an optional cloud transcription provider via BYOK.

5.3 AI Processing via Bring Your Own Key (BYOK)

For advanced AI features (e.g., summaries, structuring) and optional cloud transcription, you can provide your own API keys for third-party services such as OpenAI, Anthropic, OpenRouter, and Groq. In this case, the relevant text data, and for cloud transcription the relevant audio data, is sent directly from your device to the respective provider. OpenRouter may route requests to downstream model providers such as Anthropic, Mistral, or Gemini, depending on the model you choose.

You can also use Ollama as a local provider. When Ollama runs locally on your device, no external data transfer to Ollama or another third party takes place for those local requests.

Important: Sidenotes does not store a copy of any data sent to third-party providers. Data processing by these providers is subject to their respective privacy policies:

6. Your Rights

You have the right to request free information about your stored personal data, its origin and recipients, and the purpose of data processing at any time, as well as the right to correction, blocking, or deletion of this data. You can contact us at any time regarding this or any other questions about personal data.

You also have the right to lodge a complaint with the competent supervisory authority.

Last updated: May 30, 2026