What lives on your device
Jott is local-first. Everything you write is stored on your own device and is fully usable with no network connection. Your encryption password never leaves your device, and neither do the keys derived from it. We cannot recover it for you — that is a direct consequence of not being able to read your notes.
What the sync server can and cannot see
If you turn on sync, your notes are encrypted on your device and then sent to our sync server, which stores them and passes them between your devices and anyone you share with. It holds them sealed: the server has no key and cannot read a single word, and nor can we.
Encryption hides content, not the existence of content. Being honest about the difference, the server can see:
- Your account — the email address you signed in with, and an identifier from Google if you used Google sign-in.
- Activity metadata — how many notes you have, roughly how large each one is, and when each was created or changed.
- Your sharing graph — which accounts you have shared a note with, though not what the note says.
- Your devices — how many devices are connected, and when each last synced.
- Push tokens — if you use the mobile app, a token from Apple or Google so your phone can be told that something changed. The notification carries no note content.
We use this only to make sync work. We do not profile you with it, and we do not sell or share it.
Signing in
Jott is invite-only. We store the email address of each invited person, and a session cookie once you sign in so that you stay signed in.
If you sign in with Google, we ask Google only for your email address and a stable account identifier — nothing else, no access to your Gmail, Drive, contacts or anything of the kind. Google will know that you signed in to Jott. Signing out revokes the token we hold.
Feedback you send us
The app has a feedback form. It is entirely voluntary, and nothing is sent unless you submit it. When you do, it includes your message, the app version and the platform you are on.
Two attachments are worth understanding, because one is on by default:
- Diagnostic logs are attached by default. They help us reproduce what went wrong and may include fragments of what you were doing at the time. You can untick this before sending.
- Your database is never attached unless you tick it. It is off by default. If you do tick it, you are sending us a copy of your notes in readable form — only do that when we have asked and you are comfortable with it.
Downloads and updates
App downloads and update checks are served through our own portal, which fetches the files on your behalf. Our release host does not see who is downloading. On iPhone, the app is distributed through Apple's TestFlight, which is governed by Apple's privacy policy rather than this one.
Server logs
Our servers keep operational logs — the ordinary record of requests a server makes to stay debuggable — which include IP addresses and are also used to rate-limit abuse. They are kept for a short period and used only to run and repair the service.
What we deliberately do not do
- No analytics or product telemetry. There is no Google Analytics, no Mixpanel, Amplitude, PostHog or similar. The app ships with no analytics library of any kind.
- No crash-reporting service. No Sentry, no Crashlytics. If something crashes, we only learn about it if you tell us.
- No advertising, and no ad identifiers.
- No selling or sharing of personal information with data brokers, advertisers or anyone else.
- No training AI models on your notes. We cannot read them, and we would not do this if we could.
Other companies involved
We keep this list short on purpose, and it is complete:
- Google — only if you choose Google sign-in.
- Apple and Google — to deliver push notifications to mobile devices, and Apple to distribute the iPhone beta.
- Our hosting provider — which stores the encrypted data on our behalf and cannot read it either.
- An email delivery provider — used to send sign-in links to your address when that is switched on.
Keeping and deleting your data
We keep your account and your encrypted notes for as long as your account exists. You can delete individual notes in the app at any time.
While Jott is in alpha there is no self-serve account deletion. Email us and we will delete your account and its data by hand, and confirm when it is done. We would rather say that plainly than advertise a button that does not exist yet. You can also ask us for a copy of what we hold about you.
Children
Jott is not intended for children under 13, and we do not knowingly collect their information.
Changes to this policy
If this policy changes in a way that affects what we collect or who we share it with, we will update the date at the top and tell alpha users directly. Jott is early software under active development, and we would rather over-communicate.
Contact
Questions, deletion requests, or anything else about privacy: ops@robertssoftwarellc.com.