Your information
Privacy Policy
This policy explains what Reverb collects, why it is needed, which services process it, and the choices available to you.
Mandatory rights under applicable law continue to apply.
1. Operator and scope
Reverb is operated by Kosuke Ota, a sole proprietor in Japan trading as Takotech (the “Operator,” “we,” “us,” or “our”). This policy applies to the Reverb mobile applications, reverbnote.com, cloud storage and search services, subscriptions, and support channels (collectively, the “Service”).
Privacy questions and requests may be sent to support@reverbnote.com. Our business address is disclosed promptly after a request made through that address.
2. Information we collect
| Category | Examples |
|---|---|
| Account and authentication | Email address, password input for email authentication (stored only as a salted password hash), authentication provider identifiers, email-confirmation and password-reset code delivery and verification status, account ID, session and security records. If Apple sign-in is offered and selected, this may include the Apple account identifier and verified email address allowed by the sign-in scope. If Google sign-in is offered and selected, this may include the Google account identifier, email address, display name, and profile image allowed by the sign-in scope. |
| Your records | Note text, selected photos, photo dimensions, timestamps, deletion state, cloud-storage state, and technical representations such as search embeddings. Reverb creates an app-managed JPEG copy for cloud storage and does not upload the picker’s original photo file. |
| Search | Search text and the matching records needed to answer the request. The API and infrastructure may also generate request, security, and error metadata. |
| Subscriptions | Reverb account ID, product and entitlement status, purchase provider, renewal, expiration, and refund state, and transaction references. We do not receive your full card number from an app store. |
| Product analytics | Fixed feature and screen events, app version and build, device type and model, operating system and version, locale, time zone, screen dimensions, and pseudonymous device, session, or account identifiers. |
| Technical and support | IP address, user agent, request and error metadata, security logs, messages you send to support, and optional diagnostics you choose to include. |
3. How we collect information
- Directly from you when you write a note, search, authenticate, purchase, change settings, or contact support.
- Automatically from the application, device, browser, network, and servers when the Service is used.
- From Apple, Google, RevenueCat, and other purchase or authentication providers when they confirm an account, purchase, refund, renewal, or cancellation state.
4. Why we use information
- Save records on the device first and, for authenticated users on the Free or Pro plan, save them to the cloud and restore them on another signed-in device. Multiple devices may use the same account at the same time. Records that have not reached cloud storage remain only on the device where they were created until they are uploaded.
- Authenticate accounts, deliver one-time codes, maintain sessions, and prevent unauthorized access or deletion.
- Generate search indexes and return the original records that match a natural-language search.
- Confirm Reverb Pro access, restore purchases, and provide subscription management.
- Answer support, privacy, billing, security, and legal requests.
- Protect the Service, investigate failures and abuse, and comply with legal obligations.
- Measure product reliability and feature use without using the content of notes or searches as analytics.
Where applicable law requires a legal basis, we rely on performance of our agreement with you, our legitimate interests in securing and improving the Service, your consent for optional analytics or permissions, and compliance with legal obligations.
5. Records, search, and OpenAI
For authenticated cloud storage, record text is stored on Reverb’s cloud services and an app-managed JPEG copy of an attached photo is stored in private Cloudflare R2 storage. Photo access links are limited to 60 seconds. After an account-deletion request is accepted, Reverb does not issue new links to that account's devices, although a link issued immediately beforehand may remain usable until its 60-second expiry. Each attached photo must be accompanied by note text. Photo files are not sent to OpenAI. Record text, including text accompanying a photo, is sent to the OpenAI API to create a search embedding. Search text is also sent to the OpenAI API to create a query embedding. Reverb uses those embeddings together with text search to find the original record; it does not use an AI model to rewrite the record returned to you.
OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Reverb does not opt in. Under OpenAI’s standard API controls, content may be retained in abuse-monitoring logs for up to 30 days unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or a third party from harm.
Before Reverb first sends record text or search text to OpenAI, the app names OpenAI, explains the information and purpose, and asks for your explicit permission. If you decline, you can continue saving, viewing, and deleting records, but AI-powered meaning search remains unavailable. You can review or withdraw this permission in Settings → AI search data. Withdrawal stops new submissions, removes pending indexing work and embeddings held by Reverb, and does not delete content that may already remain temporarily in OpenAI’s abuse-monitoring logs under the conditions above.
6. Service providers and external processing
| Provider | Information and purpose |
|---|---|
| Cloudflare | Website and API delivery, request and security metadata, Workers infrastructure, and private R2 storage for app-managed JPEG copies of attached photos. |
| Discord | Displayed language and server timestamp for accepted public-website thumb-up notifications when the LP interest Discord webhook is enabled. |
| Turso | Authenticated account records, cloud-stored note data, search indexes, deletion state, and the change sequence used to keep signed-in devices up to date. |
| Resend | Email address, email-confirmation and password-reset messages, and delivery status. Passwords are not included in these messages. |
| OpenAI | Record text and search text sent to the API to create embeddings for natural-language retrieval. |
| RevenueCat | Pseudonymous Reverb account ID, products, entitlements, subscription state, and purchase-provider references. |
| PostHog | Pseudonymous feature, screen, device, application, and session analytics when analytics are enabled. |
| Apple and Google | Application distribution, store transactions, and subscription management. Apple and Google also process authentication when their respective sign-in method is selected. Google also processes support correspondence when the Operator uses Gmail to read or reply to a request. |
These providers may process information in Japan, the United States, or other countries where they or their subprocessors operate. We select and manage providers as required by applicable law and use contractual and technical safeguards appropriate to the processing.
7. Analytics choices
Product analytics help us understand whether onboarding, recording, search, purchase, and account-management flows work. Analytics do not intentionally include the content of a note or search. An authenticated user is associated with a pseudonymous Reverb account ID rather than an email address.
Product analytics are off until you separately choose to allow them. This choice is stored per installation and remains after signing out. We do not send earlier activity after you allow analytics, and automatic forwarding from RevenueCat to PostHog is disabled. Declining does not limit any Reverb feature. You can allow or disable analytics later in Reverb Settings. Disabling analytics stops new analytics events from being sent from that installation; it does not automatically erase events sent before the change. Security, authentication, billing, and request logs that are necessary to provide the Service are separate from optional product analytics.
8. Website and cookies
The public website does not set an advertising cookie, run session replay, or collect text through a form. When a visitor presses the thumb-up button, Reverb stores only a daily aggregate count and the displayed language in its database. If the LP interest Discord webhook is enabled, Reverb also sends the displayed language and exact server timestamp for the accepted press to Discord. The aggregate and Discord notification do not include an email address, IP address, user agent, referrer, or device identifier and do not measure unique visitors. Hosting and security providers may still receive ordinary request information such as IP address, user agent, requested URL, and timestamps.
9. Retention and deletion
If Reverb is discontinued, record text, photos, and derived search data in normal production systems will be deleted within 30 days after the announced end date. Backups and provider logs follow their applicable retention or deletion rules. Any information needed for refunds, accounting, or legal obligations is limited to what is necessary and kept separately from record content.
- Account and cloud-stored record data are kept while the account is active and are queued for deletion after an online, verified account-deletion request.
- A deleted record is represented by deletion state needed to prevent an old offline copy from restoring it. That deletion state is removed when the associated Reverb account is deleted.
- After account deletion completes, a minimal receipt containing a keyed hash of the opaque status token, deleted state, key identifier, and timing metadata is kept until the requesting installation confirms that its local purge completed. If that confirmation never arrives, the unlinked receipt may remain so that a device returning after a long offline period can verify the accepted request. It is not used to remotely erase another device and does not contain the Reverb user ID, email address, or note content.
- After account deletion, Reverb keeps only purpose-specific keyed HMAC values derived from server-verified provider identifiers and normalized email addresses to prevent an old authentication-provider callback or one-time-code verification from recreating the account. These replay-prevention values are retained only for the longer of the authentication challenge’s maximum 10-minute lifetime and the period needed to invalidate the Apple credential, and are deleted when that period ends. They do not contain the plaintext provider identifier or email address.
- OpenAI standard API abuse-monitoring logs may retain submitted API content for up to 30 days unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or a third party from harm.
- Technical, analytics, security, support, and deletion records are kept only for the period reasonably necessary for their stated purpose, fraud prevention, dispute handling, or legal compliance.
- Store, payment, accounting, and tax records controlled by Apple, Google, RevenueCat, or another purchase provider are retained under their policies and applicable law.
Other devices are signed out and their account data is locked when they reconnect; their local copies are not remotely erased. To erase a local copy, clear Reverb’s app data with operating-system controls where available, remove Reverb, or erase the device.
Reverb removes the requesting device’s local data for the target account and signs it out only after the server confirms that it durably accepted the request. If Reverb cannot confirm acceptance, the requesting device keeps that local data and lets you check the same request again. Server-side deletion processing continues asynchronously after acceptance and is retried after temporary failures; an accepted account is not returned to active status.
11. Security
Reverb uses measures including device encryption and application-data protection provided by the operating system, separate protection for credentials, encrypted network transport, access controls, user-scoped server authorization, restricted logs, and deletion processing. No transmission or storage system is completely secure, so we cannot guarantee absolute security or uninterrupted recovery.
12. Your choices and rights
- Access and correct account information available in the Service.
- Disable optional product analytics in Settings.
- Delete individual records in the Service.
- Select Delete account in Reverb Settings to delete your account and associated data. If you cannot access the application, submit an external deletion request through Reverb Support.
- Ask for access, correction, deletion, restriction, objection, or portability where available under applicable law.
- Withdraw consent for processing based on consent, without affecting processing that occurred before withdrawal.
For requests made through Support, we may verify your identity before responding. Contact support@reverbnote.com. You may also complain to the data-protection authority available in your jurisdiction.
13. Age limit
Reverb is intended only for people aged 16 or older. We do not knowingly collect personal information from anyone under 16. Contact us if you believe that a person under 16 has provided personal information to Reverb so that we can investigate and delete it as appropriate.
14. Changes and contact
We may update this policy when the Service, providers, or legal requirements change. We will publish the updated date and provide reasonable notice of a material change through the Service, email, or another appropriate method.
Operator: Kosuke Ota (trade name: Takotech). Email: support@reverbnote.com. Support page: Reverb Support.