What we collect when you use CiNotes, which outside services touch your uploaded material to build your notes, and what we delete once your order is done.
Effective date: 26 August 2026
We collect your email, an optional Calculator ID, and whatever you upload. Your upload is sent to our CDN, to an AI provider (OpenRouter, routing to Google Gemini) to build your notes, and delivered by email through Resend. Stripe handles payment — we never see your card. After delivery, we delete your uploaded files and the entire working folder used to build your order. We keep order metadata (email, Calculator ID, charge amount, timestamps) but not the content of your notes. We've also enabled zero data retention (ZDR) on our OpenRouter account, which OpenRouter enforces with the Gemini models it routes to — so your document isn't logged, retained, or used to train models at any point in the pipeline, not just after we delete our own copy.
To build your notes, your uploaded PDF or text passes through a few systems along the way:
We do not send your uploaded material, email address, or Calculator ID to our website-analytics or advertising-measurement tools.
After your order is delivered — or if it fails for any reason — our system deletes your uploaded files from the CDN and deletes the entire working folder used to process your order. This happens on every code path, including failures, not just successful deliveries. The generated ZIP file itself isn't kept anywhere on our end. The copy attached to your delivery email is the only copy that exists once processing finishes; we can't re-send it if you lose it, because we don't have it anymore. This is on top of, not instead of, the zero data retention (ZDR) we've enabled on the AI leg (Section 2) — so retention is minimized end to end: nothing sticks around at the CDN, at the AI provider, or in our own working storage.
In our orders database, we keep: your email address, your Calculator ID, your Reference Code (an internal number identifying your order), the order's status, the amount charged, the Stripe payment intent ID, timestamps for when the order was placed and completed, our internal cost for processing it, and a pair of random keys used to generate activation files for your bundle. Those keys are not derived from anything about you or your calculator — we keep them because without them we could never issue you a replacement activation file or add a second calculator. We do not keep the content of your notes or PDFs.
Stripe processes your payment directly. CiNotes never receives, sees, or stores your card number or other payment credentials.
We use Umami (cloud.umami.is) to see aggregate traffic to the site — for example, which pages get visited. We also use the Google Ads tag on marketing pages and checkout-success pages to measure whether an ad leads to a purchase. For a confirmed paid order, that tag receives the purchase amount, currency, and a random internal transaction ID so repeat page loads are not counted twice. It does not receive your email, Calculator ID, payment credentials, or uploaded material. We configure the tag for restricted data processing and disable ad-personalization signals.
Many CiNotes customers are students who may be under 18.
To ask what data we have on an order, or to request anything else related to your privacy, email [email protected].
We take reasonable steps to protect the data described above, including deleting your uploaded material as soon as it's no longer needed. No method of storage or transmission is perfectly secure, and we can't guarantee absolute security.
We may update this policy from time to time. If we do, we'll update the effective date above.
Questions about this policy? Email [email protected].