Privacy Policy
Last updated: August 20, 2026
1. Who we are
Apioni is operated by Foo AI Corp. ("Apioni", "we"). We are the data controller for the personal data described in this policy. You can reach us anytime at contact@apioni.com.
2. The short version
You sign in, and your notes are stored on our servers so they follow you across every device you use. They are kept as plain Markdown, we store them only to run the service, and there are no ads and no advertising trackers anywhere in Apioni. You can export or delete your data at any time.
3. What we collect
- Account — when you create an account, we store the email address you sign up with and a password credential (handled by our authentication provider, Supabase — we never see your plaintext password).
- Notes, when cloud sync is on — signing in and syncing stores your note content, note titles, and edit timestamps in our database (hosted by Supabase) so your devices can stay in sync. We store them only to provide the service; we do not sell them and we do not use them for advertising.
- Subscription information — if you subscribe to a paid plan, payment is handled by Polar; your card details never touch our systems. We receive your email address and order record to run your subscription and provide support.
- Analytics — this website uses Cloudflare Web Analytics to count page views and page-load speed. It is cookieless and does not fingerprint you or build a profile across sites. We may also use Plausible, another cookieless tool, for the same purpose.
- Error reports — none. Apioni does not send crash or error reports anywhere. If something breaks, tell us what happened at the support address and we will look into it.
- Local storage — the app uses your browser's local storage for settings like theme and open tabs, and as an offline cache of your notes so you can keep editing without a connection. We do not use tracking cookies.
4. How we use it
- To provide the service: storing and syncing the notes you choose to sync.
- To clean up and answer questions about your notes with AI, when you ask for it — this sends the note text you are working on, or the note excerpts an answer is based on, to our AI provider (see section 5). Notes you keep local are never sent.
- To operate your account and keep it secure.
- To run your subscription and help you when something goes wrong.
- To understand roughly how many people visit the website.
Under the GDPR, our legal bases are: performance of a contract (providing sync and your subscription), our legitimate interests (keeping the product secure and working), and consent where the law requires it. You can withdraw consent at any time.
5. Who processes data for us
- Supabase — database and authentication for accounts and synced notes (note content, titles, edit timestamps, and your account email), hosted on AWS in the United States (us-west-2, Oregon).
- Cloudflare — website hosting, protection, and cookieless page-view analytics.
- Plausible Analytics — cookieless page-view analytics, hosted in the EU. Website only.
- OpenAI — the AI that cleans up notes and answers questions about them. It receives the note text you send for processing, the note excerpts used as evidence for a chat answer, and your search queries. Processed in the United States. OpenAI does not train its models on data sent through its API.
- Polar — subscription payments and billing.
Payments: subscription payments are handled by Polar acting as merchant of record. Your card details never reach us.
6. Security
Synced notes are stored in our database with Supabase and travel over TLS; access is scoped to your account. The website is served over TLS, and billing requests go to Polar over TLS.
7. How long we keep data
Synced notes and your account data are kept for as long as you keep your account. When you delete a note it is removed from sync; when you delete your account, your notes and account data are deleted from our systems within 30 days, except where tax or commerce law requires us to keep purchase records longer. Website analytics are kept only briefly and contain no notes.
8. Your rights
You can ask us to access, correct, export, or delete your personal data by emailing contact@apioni.com. We respond within 30 days. You can also export your notes yourself at any time — they are plain Markdown, and the editor downloads any note as a .md file.
If you are in the EU/EEA or UK, you also have the right to object to or restrict processing, and to lodge a complaint with your local supervisory authority. If you are a California resident: we do not sell your personal information or share it for cross-context behavioral advertising, and we will never discriminate against you for exercising your rights.
9. International transfers
We are based in South Korea, which holds an EU adequacy decision. Your account data and synced notes are stored with Supabase on AWS in the United States (us-west-2, Oregon). Note text you send for AI processing is handled by OpenAI in the United States. Other processors (such as Cloudflare or Polar) may also process data in other regions, including the US; where data leaves your region, we rely on adequacy decisions, Standard Contractual Clauses, or equivalent safeguards.
10. Children
Apioni is not directed at children under 13 (or the higher minimum age in your country). We do not knowingly collect data from children. If you believe we have, email us and we will delete it.
11. Changes
We may update this policy. We'll post the new version here with an updated date.
12. Contact
Questions or requests: contact@apioni.com