Legal & Privacy
Privacy Policy
Last updated: August 2026. This Privacy Policy details how Notum collects, uses, protects, and handles personal data in accordance with the European Union General Data Protection Regulation (GDPR), UK GDPR, and applicable global privacy legislation.
1. Data Controller
The data controller responsible for the processing of your personal data on Notum is:
2. Scope of this Policy
This policy applies to all personal data collected and processed through the Notum website, web application, mobile progressive web app (PWA), cloud synchronization infrastructure, billing workflows, customer support channels, and community deck galleries.
3. Categories of Personal Data Collected
- Account & Authentication Data: Email address, user ID, display name, encrypted password hashes (managed via Supabase Auth), and third-party authentication tokens (such as Google OAuth) if you choose third-party sign-in.
- User Study Content: Flashcard decks, terms, definitions, LaTeX formulas, code snippets, custom tags, collection structures, and uploaded media attachments (images/audio).
- Learning Telemetry & Spaced Repetition Analytics: SuperMemo SM-2 review ratings (Again, Hard, Good, Easy), review completion timestamps, ease factors, memory stability metrics, study streaks, and quiz performance statistics.
- Technical & Device Data: IP address, browser type, operating system, device screen resolution, access timestamps, client error logs, and local service worker cache identifiers.
- Billing & Subscription Metadata: Stripe customer identifier, subscription plan tier (Free or Premium), renewal dates, transaction receipts, and VAT country code. (Note: Complete credit card details are collected and processed directly by Stripe under PCI-DSS Level 1 certification; Notum never receives or stores your raw card numbers or CVV codes.)
- Communications & Support: Inquiries, feedback, and messages submitted via the Support and Contact pages or sent directly to our support inbox.
- Consent & Interface Preferences: Cookie consent records (
notum_cookie_consent_v1) and theme customization settings.
4. Purposes and Legal Bases for Processing (GDPR Art. 6)
- Contract Performance (Art. 6(1)(b) GDPR): Authenticating user accounts, operating the spaced repetition engine, syncing decks across devices, rendering LaTeX math formulas, generating PDF exports, and processing subscription access.
- Legitimate Interests (Art. 6(1)(f) GDPR): Protecting application infrastructure from malicious activity, enforcing rate limits and abuse prevention, diagnosing server errors, optimizing performance, and ensuring platform integrity.
- Legal Compliance (Art. 6(1)(c) GDPR): Fulfilling accounting, tax, and bookkeeping obligations under Danish law (Bogføringsloven) and EU VAT directives.
- Explicit Consent (Art. 6(1)(a) GDPR): Storing non-essential analytical cookies or optional promotional communications, which may be withdrawn at any time via cookie settings.
5. Sub-processors and Third-Party Services
We rely on trusted third-party service providers (sub-processors) who process personal data strictly under data processing agreements compliant with GDPR Art. 28:
- Supabase, Inc. — Managed PostgreSQL database, user authentication, edge functions, and encrypted cloud storage for flashcard media attachments.
- Stripe, Inc. — Payment gateway and recurring subscription management.
- Resend, Inc. — Transactional email delivery service for account verification and password reset links.
- Banking Providers (Revolut / Lunar) — Commercial business banking and settlement accounts.
6. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate data protection safeguards are implemented, including European Commission Standard Contractual Clauses (SCCs), EU-US Data Privacy Framework certifications, or equivalent legal mechanisms.
7. Data Retention and Account Deletion
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Active Accounts: User account data, decks, and review history are retained while your account remains active.
- Account Deletion: If you delete your account via the Account Settings ("Danger Zone"), all associated personal profiles, private flashcard decks, review records, and media attachments are permanently and irrevocably deleted from active databases within 30 days.
- Financial Records: Transaction and invoice records are retained for 5 years as required by the Danish Bookkeeping Act (Bogføringsloven).
8. Technical & Organizational Security Measures
We implement modern security standards to protect your data against unauthorized access, destruction, or disclosure:
- Transport Layer Security (TLS 1.3) encryption across all public endpoints and API traffic.
- Database Row-Level Security (RLS) ensuring strict tenant isolation so users can only access their authorized data.
- AES-256 encryption at rest for persistent storage and backups.
- Secure HTTP-only session cookies and token-based authentication.
9. Your Rights Under GDPR and Global Laws
Under GDPR and applicable privacy legislation, you have the following rights:
- Right of Access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal information.
- Right to Erasure (Art. 17 GDPR): Request deletion of your personal data ("Right to be Forgotten").
- Right to Data Portability (Art. 20 GDPR): Export your decks and cards in structured, machine-readable formats (JSON/CSV).
- Right to Restriction of Processing (Art. 18 GDPR): Request that we restrict data processing under specific conditions.
- Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests.
- Right to Withdraw Consent: Revoke cookie or marketing consent at any time without affecting past lawful processing.
To exercise any of these rights, contact us at [email protected] or via the in-app Support page.
10. Supervisory Authority & Complaints
If you reside in the EU/EEA and believe our data processing infringes your rights, you have the right to lodge a complaint with your local data protection authority. For Denmark, the competent authority is:
Datatilsynet (Danish Data Protection Agency)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Website: www.datatilsynet.dk
11. California & United States Privacy Notice (CCPA / CPRA)
For residents of California and other US states with consumer privacy statutes:
- We do not sell your personal data for monetary or other valuable consideration.
- We do not share your personal data for cross-context behavioral advertising without your express consent.
- You have the right to request disclosure, deletion, and correction of your personal data without facing discriminatory treatment.
12. Children's Privacy
Notum is not intended for use by children under the age of 13 (or under 16 in the European Union without verified parental consent). We do not knowingly collect personal information from children. If you become aware that a child has provided personal data, please contact us for prompt removal.
13. Contact & Inquiries
For any questions regarding this Privacy Policy or data protection practices, please reach out to us at [email protected] or by post at:
Notum · Milrimvej 89, 9981 Jerup, Denmark