Privacy Policy
Effective 26 September 2026
ccnote.me ("ccnote", "we", "us") is a note-taking service operated by an individual based in Hong Kong. This policy explains what information ccnote collects, how it is used, and the choices you have. If you have questions, email support@ccnote.me.
What we collect
| Information | Where it comes from | Why we need it |
|---|---|---|
| Your name, email address and Google account ID | Google, when you sign in with Google | To create your account, sign you in, and recognise mail you send from that address |
| Your ccnote username | You, at sign-up | It becomes your ccnote email address |
| Emails sent to your ccnote addresses: sender, recipients, subject, body, attachments and technical headers | Whoever sends or copies mail to your address | To turn them into notes. We keep the original message so attachments and formatting are preserved |
| Notes, categories and settings you create in the app | You | To provide the service |
| Your list of trusted and blocked senders | You | To decide which incoming mail is saved straight away, held in Pending, or dropped |
| A delivery log for each incoming email: recipient, sender, subject, size, time and outcome | Our mail handling | To troubleshoot delivery and to protect the service from abuse |
| Session and API-token records, including your browser's user-agent and when a token was last used | Your browser, the ccnote apps and extension | To keep you signed in and let you see and revoke access |
We do not use advertising, analytics or tracking tools, and we do not sell or rent your information. When you view an email in ccnote, remote images are blocked until you choose to load them, so senders can't tell when you open it.
Information from Google
When you sign in with Google we request only the basic openid, email and profile scopes. We use that information only to create and sign in to your ccnote account. We do not access your Gmail, contacts, files or any other Google data.
ccnote's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
- To run ccnote: receive email, save notes, show them to you, and sign you in.
- To keep ccnote secure: check whether incoming mail really comes from the address it claims (using the SPF, DKIM and DMARC results our mail server records), prevent abuse, and investigate problems.
- To contact you about your account or important changes to the service.
We do not read your notes, except when you ask us to help with a specific problem or when required by law.
Who processes your information
We use a small number of service providers who process information on our behalf and only as needed to run ccnote:
- Cloudflare, Inc. hosts the website, apps and API, receives email for ccnote.me, and stores your notes and attachments. Our database and storage are placed in Cloudflare's Asia-Pacific region, although Cloudflare may process data in other locations to deliver the service.
- Google LLC provides the "Sign in with Google" service.
Mail you ask us to forward (for example to support@ccnote.me) is delivered to the operator's mailbox. We may also disclose information if required by law, or to protect the rights, safety or property of ccnote, our users or others.
How long we keep it
- Notes, attachments and original messages are kept until you delete them or delete your account. Notes you move to Trash stay there until you delete them permanently or delete your account.
- Delivery logs are kept for up to 12 months.
- Sign-in sessions expire after 30 days. Unfinished sign-ups expire after 30 minutes.
- When you delete your account, we delete your account, notes, attachments and settings within 30 days. Copies in backups are overwritten on their normal schedule.
Cookies
ccnote uses only cookies that are needed for the service to work: one that keeps you signed in, and short-lived ones used during Google sign-in. We do not use advertising or analytics cookies.
Your choices and rights
You can view, edit, move and delete your notes, and manage trusted senders and API tokens, in the app at any time. Under Hong Kong's Personal Data (Privacy) Ordinance, and similar laws where you live, you may ask to access or correct the personal data we hold about you, or ask us to delete your account. Email support@ccnote.me from the address on your account and we will respond within 40 days.
Security
All connections to ccnote use HTTPS. Session cookies and API tokens are stored only as one-way hashes, emails from unverified senders are held for your approval, and email content is stripped of scripts before it is shown. No service is perfectly secure, so please contact us right away if you believe your account has been compromised.
Children
ccnote is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has created an account, please contact us and we will delete it.
Changes to this policy
We will post any changes on this page and update the effective date. If a change significantly affects how we use your information, we will tell you by email or in the app before it takes effect.
Contact
ccnote.me, Hong Kong
support@ccnote.me