← Back to Derive

Privacy Policy

In force from 7 September 2026

Derive reads your handwriting by sending a picture of the part of the page you are working on to AI companies in the United States. This policy says exactly what we collect, who sees it, how long we keep it, and where the product does not yet do what you might expect.

In force from 7 September 2026. This version replaces the version dated 4 September 2026. The change is that we have started advertising Derive on Meta: section 13.6 says exactly what is sent and what is not, B2.2 and B2.9 say what that means for your rights in the United States, and the short answer is that nothing you write is ever involved, nothing at all is sent about anyone under 18, and nothing at all is sent about an account that existed before this date.

Derive Notes Pty Ltd (ACN 696 859 597) 2/290 Boundary Street, Spring Hill QLD 4000, Australia matt@derivenotes.com

Related documents: Terms of Service, Subprocessors, Cookies, Children and students, AI disclosure.


The short version

Derive is a notebook. You write in it, and we read what you write, because reading your handwriting is the product. To do that we send a picture of the part of the page you are working on, plus the text we have already recognised around it, to AI companies in the United States. That happens every time recognition runs, and you cannot switch it off and still have Derive work. We say that plainly here because it is the single most important thing to understand about us.

Your notebooks live in a database in Sydney, Australia. Your name, email and notes are never sold. We do use your handwriting to train our own recognition models, we explain exactly how in section 7, and you can object. We keep a small amount of money and email data after you delete your account, and section 9 lists exactly what. Outside Europe and the UK, product analytics is switched on by default, and section 13 tells you where to switch it off. The app contains a screen recording capability that would film your handwriting. It is switched off for everyone and nothing in the app can turn it on today.

You must be at least 13 to use Derive, and older in some countries. Section 11 and Part B say which. If you are under 18, some things are turned off for you automatically.

If any of this is not what you want, the honest answer is that Derive may not be the right notebook for you, and you can delete your account from Settings at any time.


Summary table

What we collectWhyWho sees it outside DeriveHow long we keep it
Your email address and nameTo make an account and email you about itSupabase (Sydney), Amazon SES (Sydney), Stripe or Apple if you payUntil you delete your account. Some email and billing records survive: see section 9
Your handwriting, ink, typed text, drawings and uploaded imagesTo run the notebook, and to recognise and check your workOpenRouter, Relace, Modal, DeepInfra, Google, OpenAI, Supabase, Cloudflare in transitUntil you delete it, then up to 30 days. Some derived records last longer: see section 8
AI output about your work: recognised text, verdicts, summaries, practice questions, embeddingsTo show you the answer and to make search workThe AI providers that produced itWith the page, unless listed otherwise in section 8
Your study profile: study level, school year, school or university, degree, country, age bandTo set up the app, to apply the right age and country rules, and to decide what we may email youSupabase, and ROR when you search for a universityUntil you delete your account
Payment and subscription recordsTo sell you a subscription and keep tax recordsStripe, Apple, RevenueCatBilling records survive account deletion: see section 8
Diagnostics: crashes, errors, performance timings, device detailsTo find and fix bugsSentry (United States), Supabase30 days for the timing data, Sentry's own retention for crashes
Product analytics. Screen recording exists in the app but is off for everyone, with no way to turn it on todayTo see which features get usedPostHog (European Union), reached through our own servers which remove your IP addressPostHog's project retention: see section 8
Email delivery, opens and clicksTo know that our email arrived, and whether it was usefulAmazon SES (Sydney)Suppression list is permanent. Click and link records: see section 8
Website visit data and waitlist entriesTo run derivenotes.comVercel, PostHog (United States), Brevo (European Union)30 days to 12 months by cookie: see section 13
That you signed up, started a trial or paid, and a one way hash of your email address if you are 18 or over. Only for accounts created from 7 September 2026To measure whether our ads workMeta (United States), only if you accept analyticsMeta's own retention: see section 13.6

Part A: The core policy

This part applies to everyone, everywhere. Part B adds rights and rules that apply where you live. If Part B gives you something more than Part A, Part B wins.


1. Who we are, and how to reach us

1.1 Derive is made by Derive Notes Pty Ltd, an Australian company, ACN 696 859 597, at 2/290 Boundary Street, Spring Hill QLD 4000, Australia.

1.2 We are the controller of the personal information described here. In plain terms, we decide what is collected and why.

1.3 For anything at all to do with privacy, including a request to see your data, correct it or delete it, email matt@derivenotes.com. That address is read by a person. There is no separate privacy team, because there is no team.

1.4 For general help with the app, support@derivenotes.com reaches the same place.

1.5 If you are in the European Economic Area, the United Kingdom or Switzerland, you can also use our appointed representative, and section B1.9 tells you how.


2. What this policy covers

2.1 This policy covers the Derive app on every platform we ship it: the web app, the Mac and Windows desktop apps, and the iPhone and iPad apps. It covers the website derivenotes.com, including the waitlist and the sign up, cancellation and support pages. It covers the emails we send you.

2.2 It does not cover other companies' services that you choose to connect Derive to. If you connect Derive to Claude using our connector, described in section 5.9, Anthropic's own terms govern what Anthropic then does with what you send it.

2.3 This is the only privacy policy. There is no separate short version that says something different. If you have read a shorter summary elsewhere, this document is the one that binds us.


3. Where your information comes from

Most of what we hold, you gave us. Some of it arrives from somewhere else, and you have a right to know that.

3.1 From you directly. Your email address, your name if you give one, everything you write or draw or upload in the app, the answers you give during set up, anything you type into the tutor, and anything you send us in feedback.

3.2 Derived by us or by our AI providers from what you wrote. Recognised text, the verdict on whether a step is right, summaries, page titles, practice questions, topic labels and mathematical vector representations of your work called embeddings. This is still your personal information. Handwriting identifies a person in much the way a signature does, and we do not pretend otherwise.

3.3 From your device. Your device type, operating system, app version, screen size, refresh rate, time zone and browser language.

3.4 From your network connection. An approximate country, worked out from your IP address at the edge of our hosting network. We do not collect satellite or GPS location.

3.5 From Stripe. If you subscribe on the web or desktop, Stripe tells us your subscription status, your plan, the currency and price, your renewal date, and your card brand, its last four digits and its expiry month. We never receive your full card number.

3.6 From Apple and RevenueCat. If you subscribe inside the iPhone or iPad app, Apple is the seller and RevenueCat relays your purchase and subscription state to us. We never receive your card details.

3.7 From Amazon SES. Whether an email we sent was delivered, bounced or was reported as spam, and whether it was opened or a link in it was clicked. Section 12 explains when we track that and when we do not.

3.8 From Apple or Google when you sign in with them. Your email address and, if the provider supplies it, your name.

3.9 We do not buy personal information from data brokers, and we do not enrich your profile from third party sources.


4. What we collect, in detail

4.1 Account and identity

Your email address, your name if you provide one, an avatar image URL if your sign in provider gives one, and an internal account identifier which is a random code, not anything about you.

You can start using Derive before you give us an email address. When you tap "Get started" we create a real account for you straight away, with no email address attached, so that your notes have somewhere to live. That anonymous account is a full account: it can hold notes, it can generate recognition data and it can even hold a subscription. If you later sign in, that same account becomes your account. If you never sign in, the account and its notes stay in our database. Nothing currently removes abandoned anonymous accounts.

4.2 Your notes: handwriting, ink and page content

This category deserves its own heading because it is the most sensitive thing we hold.

We collect and store:

  • the raw geometry of every stroke you draw: the coordinates of every point, the pressure, the tilt and the timing,
  • typed text, equations, tables, graphs and diagrams you create,
  • images you upload or photograph, including photographs of textbooks, worksheets and exam papers,
  • source code you write in a code block, and any input you supply to run it,
  • the structure of your notebooks: unit, section and page names, and how pages nest,
  • a rendered picture of every page, stored as a thumbnail so the library can show previews.

We treat everything in this category as content that could contain anything. We do not scan it for sensitive categories, we do not ask you to tell us if a page is sensitive, and we have no way of detecting that a page is about your health, your religion or anyone's private life. Please do not put information into Derive that you would not want handled in the way this policy describes.

4.3 Content the AI produces about your work

  • Recognised text and LaTeX, which is a written record of what you wrote, mistakes included.
  • Whether the tutor judged a step correct or incorrect, and a short label for the kind of error.
  • Summaries, page titles, practice questions, worked solutions and generated diagrams.
  • Topic labels and subject tags.
  • Embeddings, which are long lists of numbers representing the meaning of a piece of your writing. Embeddings are derived personal information. They are not human readable, but they are not anonymous either, and we treat them as personal data.
  • The text of the surrounding lines on a page, captured together as the context the recogniser was given.

4.4 Your study profile

During set up we ask, and store: your study level (high school, university, teacher or self study), your school year if you are at high school, your degree or course if you are at university, your country and region, and one free text answer about what you find hard.

If you are 16 or over and at high school we ask for your school name. If you are at university we ask which institution, using a search that runs against the Research Organization Registry.

If you are under 16, the school and institution fields are hidden from you and any answer already typed is cleared. That is deliberate.

4.5 Your age band

We ask for your month and year of birth on a neutral screen that does not tell you what answer unlocks anything. We work out an age band from it, and we store only the band: under 13, 13 to 15, 16 to 17, or 18 or over. We do not store your date of birth. We also store how we worked the band out, and when.

In one version of the set up flow, answering "University" or "Teacher" is treated as meaning you are 18 or over, and you are not then asked for your birth date. That is an assumption we make from what you told us, not something we have checked.

Not every account is asked. Some accounts created on current releases of the app go through a set up flow that has no age step at all, and for those accounts we hold no age band. On Apple devices we do not currently read the age range Apple can supply. Where we hold no age band, the protections in section 11 that depend on age fall back to the "unknown" rules described there.

4.6 Payments and subscriptions

Your subscription status and tier, your plan and its price, currency and interval, your renewal or expiry date, whether you have cancelled, your Stripe customer and subscription identifiers or your Apple transaction identifier, and your card brand, last four digits and expiry month.

We keep a money ledger of each payment and refund, holding the amount, tax and discount, and a copy of the raw notification our payment providers send us. Those notifications can contain your billing address and your name.

We never hold your full card number, your card security code, or your bank details.

4.7 Email and messaging

Your email address, the messages we sent you and when, whether each one was delivered, bounced or complained about, and, where section 12.6 permits it, whether you opened it and which links you clicked. Click records store a shortened description of your email software. They do not store your IP address.

We also keep a permanent record of every address that has bounced, complained or unsubscribed, so that we never write to it again. That record is deliberately never deleted, because deleting it would let us start mailing you again by accident.

4.8 Diagnostics and performance

Crash reports and error reports, including the technical detail of what went wrong, your account identifier, your app version and your platform. Performance timings such as how long ink takes to appear and how busy the app's main thread is, sampled from about one in ten sessions, recorded against your account identifier.

Error reports carry a trail of the app's recent internal log messages. Today, three of those messages can contain content: an AI generated page title, the raw mathematical expression the app was trying to repair, and the text you typed into search. If an error happens shortly afterwards, that content goes to Sentry with the report.

4.9 Product analytics and screen recording

If product analytics is on for you, we record a fixed list of about eighty named events describing what you did, such as opening a notebook, drawing your first stroke, or seeing the paywall. Those events carry counts, categories and true or false values. They do not carry your notes, your page titles or any free text.

Analytics is identified only by a random code generated on your device. Your account identifier, your name and your email address are never sent to our analytics provider. The link between that random code and your account is kept in our own database in Sydney, so that we can delete your analytics records when you delete your account.

Screen recording is different and much more revealing. The app contains a screen recording capability. If it were switched on, it would record video of the app while you use it, including the canvas, which means your handwriting, and including on screen text, at four frames per second.

It is switched off for everyone. There is no control in the app that turns it on, and it never starts from a regional default. It is deliberately separate from product analytics, so turning analytics on does not start it. If we ever turn it on, it will be opt in, and we will update this policy before we do.

4.10 Support, feedback and screenshots

When you send feedback from inside the app we collect your message, and, if you leave the "include page context" box ticked, the web address you were on, your browser details and a screenshot of what was on your screen at that moment. That screenshot will normally include your handwriting.

That box is ticked by default.

You can also attach files to feedback. We keep them.

4.11 Website and waitlist

If you visit derivenotes.com we set a random visitor identifier that lasts a year, and a campaign record that lasts thirty days recording how you arrived, including any referral code. We set both on your first request, before you have answered the cookie banner, and we use the visitor identifier to decide which version of the homepage headline you see. Section 13.4 sets this out in full.

If you join a waitlist we collect your email address and whatever the form asks for, which on some forms includes your name, your role, your school year, your school and your subjects.

4.12 Code execution

If you run code in Derive, your code and any input you supply are sent to Judge0, reached through RapidAPI, to be executed in a sandbox with no network access. We do not attach your account identifier to that request.


5. How your handwriting is read: AI processing

5.1 The plain fact. Recognising your handwriting is not an add on. It is the product. When recognition runs, we send to an AI company:

  • a rendered picture of the region of the page you were working on,
  • the recognised text of the lines around it,
  • the text of any course or textbook content you have imported onto that page,
  • the question text, if you are on a practice page,
  • and an identifier for the page.

We do not send the raw coordinates of your strokes to any AI provider. We do not send your name, your email address or your account identifier to any AI provider.

5.2 You cannot turn this off and keep using Derive. There is no offline only version. Any earlier statement of ours suggesting AI runs only with your consent, including on our support page and in our App Store listing, was wrong. This document is the correct statement.

5.3 What is optional. Summaries, page titles, practice question generation, page building, diagram generation, search indexing and reading text out of an uploaded image are extras. You can turn them off under Handwriting recognition in Settings. Turning them off does not stop the core recognition described in 5.1.

5.4 Who receives it. Recognition is tried first through OpenRouter, which routes it to one of three named model hosts: Relace, Modal or DeepInfra. If that fails, it goes to Google. If that fails, it goes to OpenAI. Other AI features go to Google or OpenAI directly. Section 6 and the Subprocessors page give the full list.

5.5 Retention at the providers. On the main recognition path we send an instruction with each request telling OpenRouter to refuse any host that would keep or train on the request. On two other paths, image reading and one internal routing step, we do not currently send that instruction and we do not pin which host serves the request. On Google and OpenAI we rely on those companies' standard business terms rather than a per request instruction.

5.6 Where the AI providers are. All of them are in the United States, or serve from a global endpoint that is not pinned to any one country. Part B explains the transfer mechanisms.

5.7 AI gets things wrong. Recognition and tutoring output can be inaccurate. It is study assistance, not advice, and not a marking authority. Always check it. Our AI disclosure says more.

5.8 Age. There is currently no age check on the AI path. A user of any age whose account exists can have their page region sent to the providers named in section 6.

5.9 The Claude connector. If you choose to connect Derive to Claude, using the connector at mcp.derivenotes.com, then Claude can search your notes, list your recent pages, read the full recognised text of a page and download a page image. That sends your notebook content to Anthropic in the United States, under Anthropic's terms, not ours. Nothing is sent unless you set the connection up and ask Claude for it.


6. Who else sees your data: our providers

6.1 The list. The full table of every company that receives personal information from Derive, what each one does, what it receives and where it is, lives on our Subprocessors page. That table is the authoritative list, and it replaces any older list. In summary:

  • Storage, sign in and server code: Supabase, in Australia (AWS Sydney). Cloudflare sits in front of our server gateway and sees every request in transit, including your IP address.
  • Handwriting recognition: OpenRouter, which routes to Relace, Modal or DeepInfra, with Google and then OpenAI as fallbacks. All in the United States, or on a global endpoint.
  • Other AI features: Google and OpenAI. Judge0, reached through RapidAPI, runs code you write. Anthropic, only if you connect Claude yourself.
  • Diagnostics and analytics: Sentry in the United States for crashes and errors, PostHog in the European Union for product analytics, both reached through our own servers which strip your IP address. Sentry's error replays hide all text and exclude the canvas, so your handwriting does not reach Sentry that way.
  • Email: Amazon Web Services Simple Email Service, in Australia.
  • Payment: Stripe on the web and desktop, Apple and RevenueCat inside the iPhone and iPad app.
  • Hosting and lookups: Vercel hosts the website and the app shell and resolves your approximate country. The Research Organization Registry answers university searches during set up, directly from your browser.
  • Website only: PostHog (United States) for website analytics and the homepage headline test, Brevo (European Union) for waitlist and tester email, Vercel for hosting, and Stripe for legacy founding member payments.
  • Advertising measurement: Meta Platforms, in the United States, and only if you accept analytics. It receives that a sign up, trial or payment happened, and a hashed email address only for accounts we know to be 18 or over. It receives nothing at all about an account created before 7 September 2026. Section 13.6 sets out exactly what is sent and what is not.

6.2 Other recipients. We also disclose personal information to our professional advisers, to a buyer or prospective buyer of the business, to you or anyone you ask us to, and to anyone we are legally required to disclose it to.

6.3 We will update the subprocessor list before we start using a new provider that receives your personal information, or as soon as we reasonably can after a routing change.


7. Training our models, and other people's

This section is deliberately prominent, because it is the thing people most want a straight answer about.

7.1 Do other AI companies train on your work?

We do not permit it, but the strength of that varies by path.

On the main recognition path we send an explicit instruction refusing any host that would retain or train on the request. On the image reading path and one internal routing step, we do not currently send that instruction. With Google we use only paid tiers, Vertex AI and the paid Gemini API. On those tiers Google's terms say it does not use prompts or responses to improve its products and does not put them in front of human reviewers. It is Google's free tier, which we do not use, where both of those things happen. With OpenAI we rely on its standard business terms, which for paid business use do not permit training on customer content by default, rather than on a per request setting of ours. We do not control those companies' systems and we cannot guarantee their conduct. See 5.5.

7.2 Do we train our own models on your work?

Yes. Derive builds and ships its own handwriting and mathematics models, and they are trained on real student work, including yours.

Three trained files ship inside the app on your device today: a model that decides which strokes belong together, an older version of the same, and a model that decides whether the tutor should change its verdict. The third was trained on about 74,000 records drawn from about 230 accounts, and it has been in use since 25 August 2026.

7.3 What we collect for training

Four things are collected as you use Derive:

  1. Corrections. When you lasso strokes and tap Recognize, we save the geometry of that page along with what you corrected, as a training example.
  2. Recognition context. Each time recognition runs we save the recognised text of up to thirty two nearby lines, so we can improve which lines the recogniser is shown.
  3. Attempts. Each settled recognition writes a record of the mathematics you wrote, exactly as written, mistakes included, along with a label for the kind of error.
  4. Disagreements. When you tell the tutor it is wrong, we save that as a signal that it was.

7.4 Human review

A person, currently only the founder, looks at real pages of handwriting in a local labelling tool in order to teach the models what a correct grouping looks like. Pages are sampled across many accounts, so a page of yours may be looked at. The labels that come out of that process record only stroke identifiers and how they should be grouped. They do not record your name or the content of the page.

7.5 What we do not do

We do not use your notes to build a profile of you for advertising. We do not sell your notes. We do not disclose your notes to anyone outside the list in section 6.

7.6 Deleting a page does not always remove it from training

This is the honest position, and the old policy got it wrong.

If you delete a page, the page and the ink on it are removed from our live database within 30 days, and the correction records tied to that page go with it. But two kinds of training record survive:

  • The attempt records in 7.3 point three are stored without a link back to the page. Deleting the page does not delete them. They are removed when you delete your whole account.
  • Any training corpus or trained model built before you deleted the page still exists. We do not retrain or discard a model because content was later deleted.

7.7 Objecting to training

You can object to us using your content to train our models at any time by emailing matt@derivenotes.com. We will stop using your content for that purpose from then on. Objecting does not require us to retrain or discard a model or dataset that already exists.

There is no switch for this in the app today, and honouring an objection is currently a manual process.

7.8 One thing we got wrong

A model file that ships inside the app contains a short list of category labels that were taken directly from real pages, such as chapter and exercise headings that students had written. That means small fragments of some users' page headings are distributed inside the app to other users. It is a small amount of text and it is not linked to any name or account, but it should not be there, and the file will be replaced.

7.9 Aggregated statistics

We produce aggregated and statistical information about how Derive is used, which does not identify anyone, and we use it to run the business.


8. How long we keep things

WhatHow long
Your account and your notesWhile your account is open
A page or notebook you deleteRemoved from the live database within 30 days
Correction training recordsRemoved with the page they belong to
Recognition context records30 days
Attempt records and disagreement recordsUntil you delete your account. Nothing removes them earlier
Tutor evaluation records, which hold a picture of handwriting used to test the recogniserNo fixed limit today. These records are not linked to your account by a database constraint, so they are not removed when your account is deleted
Embeddings, semantic summaries and page chunk recordsWith the page they describe
Search query records30 days. The query text itself is encrypted at rest, and if the encryption key is missing we store nothing rather than store it in the clear
Performance timings30 days
Editing behaviour records used to study how people learn180 days
Cross device conflict records90 days
Money records: payments, refunds and the raw payment provider notifications7 years, for Australian tax and accounting purposes
Bounced, complained and unsubscribed addressesKept permanently, so that we never write to that address again. Bounce diagnostics themselves are pruned after 2 years
Email delivery, click and link recordsNo expiry is enforced today, so these records accumulate. They are scrubbed as described in 9.4 when you delete your account
Rate limiting records, which include IP addressesCleared as each short rate limiting window passes
Analytics eventsHeld by PostHog under that project's retention setting
Crash and error reportsHeld by Sentry under that project's retention setting
Aggregated statistics, and models already trainedIndefinitely, because they do not identify anyone. The exception in 7.8 is described there
Website cookiesSet out in section 13.4

Where a period is not fixed above, the rule is that we keep something for as long as the purpose we collected it for still applies. Backups follow their own cycle and are overwritten in turn.


9. Deleting your account, and what survives

9.1 How to delete. Settings, then Account, then Delete account. There is no form to fill in and nobody to ask.

9.2 A seven day pause. We record the request and wait seven days before doing anything, so that you can change your mind. After that, deletion happens on the next daily run and it cannot be reversed.

9.3 What is destroyed. Your account, your profile, your notebooks, your pages, your ink, your recognised text, your embeddings, your assistant conversations, your attempt and disagreement records, your consent records, your analytics identity, the analytics person and events held at PostHog, and the image files you uploaded.

9.4 What survives, and why. Being straight with you about this matters more than the list being short.

  • Money records. Payments, refunds and the raw notifications from Stripe, Apple and RevenueCat are kept, because Australian tax law requires us to keep records of what we were paid. Those notifications can contain your name and billing address.
  • The email suppression list. Your address stays on it if it ever bounced, complained or unsubscribed. Removing it would let us start mailing you again.
  • Our email activity record. We keep a record of the messages we sent and to whom, as a record of our own business activity. Before deletion, the email event records are scrubbed: your address is replaced with a one way code, and the IP address, device details and clicked links are removed.
  • Feedback you sent us, including the message, the page address, your device details and any screenshot, kept without your account attached to it.
  • A behavioural snapshot taken when a subscription ends, holding counts of pages and activity dates, without your name or email.
  • Records held on lists keyed to your email address, such as founding member, beta access, cancellation request and billing notice records.
  • Some stored files. Page thumbnails, which are pictures of your pages, and feedback screenshots and attachments, are not currently removed when your account is deleted. Only your uploaded image files are.
  • Records held by other companies. We ask PostHog to delete you and, when that succeeds, it does. We do not currently send a deletion request to Sentry or to RevenueCat, and we cancel your Stripe subscription without deleting the Stripe customer record.
  • Tutor evaluation records, which can include a picture of handwriting, are not linked to your account by a database constraint and so are not removed by deletion.

9.5 Cancelling your subscription is a separate thing. Deleting your account cancels a Stripe subscription immediately, and does not refund the rest of the period you paid for. It cannot cancel an Apple subscription. If you subscribed inside the iPhone or iPad app, cancel in iOS Settings, then Apple Account, then Subscriptions, or Apple will keep charging you.

9.6 The copy on your device. Derive keeps a copy of your notebooks on your own device so it works offline. Signing out clears it. Deleting your account does not by itself clear it: sign out, clear the app's storage, or remove the app.

9.7 Under 13. If we learn an account belongs to someone under 13 we lock it, and we keep a record that the account was locked for that reason. We do not currently delete the account automatically. If you email us, we will delete it by hand.

9.8 Time limits. We aim to complete an account deletion within 30 days of the seven day pause ending. Very large accounts can take a few extra days because file deletion runs in batches.


10. Your rights, and how to use them

10.1 Wherever you live, you can ask us to:

  • See what we hold about you.
  • Get a copy of it in a form you can take elsewhere.
  • Correct anything wrong.
  • Delete your account and your data.
  • Object to us using your content to train our models.
  • Stop marketing email, at any time.
  • Complain, to us and to your regulator.

10.2 How. Email matt@derivenotes.com from the address on your account, and say what you want. If you write from another address we will ask you to prove the account is yours, usually by asking you to confirm from the account's own email address or from inside the app. We ask for identity checks only so that nobody else can get your notes.

10.3 How long we take. Within 30 days, and sooner where we can. If your local law gives a shorter deadline, we meet that instead. If a request is genuinely complicated we may take up to a further 30 days and we will tell you why before the first deadline passes.

10.4 What it costs. Nothing. We will not charge you and we will not treat you any differently for asking.

10.5 Deletion and export you can do yourself. Deleting your account is self service in Settings. Settings also has a download of the copy of your notebooks held on your device.

10.6 An honest limitation on access and portability. That download covers your notes as your device holds them. It does not include your profile, your billing records, your consent records, your email history, your recognised text as we store it server side, or your training records. If you want all of that, email us and we will assemble it by hand.

10.7 Complaining. Tell us first if you can, because we can usually fix it faster. You never have to. Part B names the regulator for where you live.


11. Children and young people

Our Children and students page says the same things in a shorter form.

11.1 The minimum age. Derive is not for anyone under 13, anywhere. In some countries you must be older:

  • 18 or over in India, South Africa, Japan and the Republic of Korea.
  • Higher than 13 wherever the law where you live sets a higher age for using a service like Derive without a parent's consent. Part B names the ones we know about, including 14 in Quebec.
  • Derive may not be used from mainland China.

These are rules about who may use Derive. They are not something we check. We do not verify your age, and section 4.5 explains what we do and do not know about it.

11.2 How we ask. We ask for your month and year of birth on a neutral screen during set up, and we store only an age band. See 4.5, which also explains that not every account is asked.

11.3 If you tell us you are under 13. We lock the account and sign you out. See 9.7.

11.4 There is no parental consent process. We do not have a way to obtain, record or verify a parent's or guardian's permission. That is why the minimum age is a hard floor rather than a threshold that a parent could unlock. If you are a parent or guardian and you believe a child under 13 has an account, email matt@derivenotes.com and we will deal with it.

11.5 What is switched off for under 18s.

  • We do not ask anyone under 16 for their school or university, and we clear those fields if they were already filled in.
  • We do not send marketing email to anyone below the marketing age for their country, which ranges from 13 to 20 depending on where you are. If we do not know your age band, we do not send marketing email at all.
  • We do not track opens or clicks in email for anyone under 18, anywhere, and we do not track them where the age band is unknown.
  • In the European Economic Area and the United Kingdom, product analytics is off for anyone under 16 and cannot be switched on. Screen recording is off for everyone, at every age, with no way to turn it on today.
  • Product analytics is always off for anyone recorded as under 13.

11.6 What is not currently age gated. AI processing of handwriting is not age gated, and neither is the Claude connector. See 5.8.

11.7 Schools. Derive is licensed for your own personal study. It is not designed, sold or supported for a school, college or district to adopt on behalf of students. We have no organisation accounts, no teacher dashboards, no class rosters and no way for a school to see, export or delete a student's work. We are not a "school official" under the United States Family Educational Rights and Privacy Act and we do not accept student records from an institution.


12. Email and marketing

12.1 Email you always get. Some email is part of the service and you cannot unsubscribe from it: password resets, security notices, billing and renewal notices, and confirmation of a cancellation. These are not marketing.

12.2 Marketing email. Product news, offers and study tips. You can stop it at any time from the unsubscribe link in any marketing message, or from Settings, or by emailing us. Unsubscribing works without signing in, and works even if the link is old.

12.3 How permission works where you are. The rules differ by country, and we apply the rules of the country we believe you are in.

  • In most of the world, including the European Economic Area, the United Kingdom, Canada, Japan, Korea, Singapore and Brazil, we only send marketing email if you have agreed to it.
  • In the United States, we may send marketing email until you tell us to stop.
  • In about thirty countries, if you have actually paid us, we may send you news about the same kind of product, and you can refuse at any time. There is a time limit on that in Canada of two years from your last payment, and in Ireland of one year.
  • In India, we do not send marketing email to anyone under 18 at all, and no permission can change that.

12.4 What our messages say about us. Every message we send, marketing included, comes from noreply@derivenotes.com, so the sending domain identifies us. The message itself does not carry our legal name or postal address. They are in section 1 of this policy. Every marketing message carries an unsubscribe link, and unsubscribing also works from your mail client's own unsubscribe button, because we set the standard one click unsubscribe headers.

12.5 How we asked you. At the moment, completing the sign up screen is treated as agreeing to receive offers, news and updates, because that permission is bundled into the same sentence as agreeing to the Terms and this policy.

12.6 Opens and clicks. We record whether a marketing email was opened, using a small invisible image, and which links were clicked. We do not do either for anyone under 18, or where we do not know your age band.

Today we also track link clicks in service and billing email for adults.

12.7 Unsubscribing today stops more than marketing. If you unsubscribe, our system currently suppresses every message to that address, including billing notices and cancellation confirmations.

12.8 Two sending systems. The app sends through Amazon SES in Sydney. The website's waitlist and tester email sends through Brevo in the European Union. Today they do not share an unsubscribe list, so unsubscribing from one does not necessarily stop the other. Email matt@derivenotes.com and we will remove you from both.

12.9 Push notifications. The app may ask for permission to send notifications. Today we do not store the device token and we cannot send you a push message. Agreeing to notifications is not agreeing to marketing, and we never treat it as such.


13. Analytics, cookies and local storage

Our Cookies page covers the website side of this in more detail.

13.1 In the app

The app is a static application. It sets no cookies at all. It stores things on your device using local storage, including your sign in session, your settings, your theme, your detected country and the random analytics identifier described in 4.9.

13.2 Whether analytics is on

We do not ask you. Whether product analytics runs is decided by where you are:

  • In the European Economic Area and the United Kingdom, it is off until you switch it on in Settings, Account.
  • Everywhere else, it is on by default, and you can switch it off in the same place.
  • If we cannot work out your country, it is off.
  • If your age band is under 13, it is off, everywhere, and it cannot be switched on.
  • Screen recording is off for everyone. There is no control in the app that turns it on, and turning analytics on does not start it. See 4.9.

The app does not show you a notice about this on first run. This policy is where it is disclosed.

13.3 What analytics never contains

The analytics events do not carry your notes, your page titles, your search text or any free text. They carry a random device code, not your account identifier, your name or your email. Your IP address is removed by our own relay before anything reaches PostHog.

Screen recording would be the exception, because it is video of your screen including your handwriting, but it is off for everyone and cannot be turned on today.

13.4 On the website

The website sets these:

NameWhat it is forHow long
"visitor_id"A random identifier used to decide which version of the homepage headline you see12 months
"derive_waitlist_meta"Records how you arrived: campaign, referral code and landing page variant30 days
"derive_site"Remembers which version of the site to show you, when you asked for one30 days
Tester session cookieSigns testers in to a previewSession
PostHog cookiesWebsite analytics, set only after you acceptUp to 12 months
"derive_analytics_consent" (local storage, not a cookie)Remembers whether you said yes or no to analyticsUntil you clear it

We set "visitor_id" and "derive_waitlist_meta" on your first visit, before you answer the cookie banner, and we use "visitor_id" to ask PostHog in the United States which headline to show you. The old cookie notice said nothing analytics related is stored before you answer. That was wrong, and this table is the correction.

13.5 Website analytics identifies you by email. If you join the waitlist, your email address is sent to PostHog as your identifier, and payment events on the website are recorded against your email address and Stripe customer identifier. That is different from the app, which never sends PostHog anything but a random code.

13.6 Advertising measurement. We advertise Derive on Meta, and the Derive web app at web.derivenotes.com carries the Meta pixel. An earlier version of this policy said we ran no advertising at all and named the Meta pixel as something we did not use. That has stopped being true, and this section is the correction rather than a quiet edit.

Who it applies to: accounts created from 7 September 2026. If your account already existed when this version came into force, none of the rest of this section applies to you. Nothing about your account is sent to Meta: not that you signed in, not that you started a trial, not that you paid, and no identifier of any kind, hashed or otherwise. The pixel does not load in your browser while you are signed in, and our servers do not report your payments. We built it this way on purpose. It means the only people described by this section are people who could read it before they decided to sign up, and it is the reason we are not writing to every existing user to announce a change to how their data is used. There is no change to how their data is used.

Where it is, and where it is not. The pixel runs on the web app only. The marketing website carries no advertising tracker, and neither do the Mac and Windows desktop apps or the iPhone and iPad apps. The iPhone and iPad apps still do not track you across other companies' apps or websites, which is why you still see no App Tracking Transparency prompt. There is no Google Analytics, no Google Tag Manager, no TikTok tag, no LinkedIn tag and no session heatmap tool anywhere.

What we tell Meta. That a page was viewed, that an account was created, that a trial was started, and that a payment succeeded, with the amount. Nothing you write reaches Meta: not your notes, not your handwriting, not your page titles, not your search text, not anything you type into the tutor.

Your email address, hashed, and only if you are 18 or over. So that Meta can tell whether an advert led to a sign up, we send a one way cryptographic hash of your email address rather than the address itself. We do this only for accounts whose age band is a declared 18 or over. If you are under 18, if we do not know your age, or if we worked out that you were probably an adult from your study level rather than being told, we send no identifier that could name you, and the measurement stays anonymous. We never send a child's identifiers to an advertising platform.

Only if you accept analytics. The pixel is gated on the same answer as product analytics. Say no, or withdraw later, and it does not load and nothing is sent. If your browser sends a Global Privacy Control signal we treat that as a refusal on its own, whatever else you have chosen: see B2.9.

What it stores on your device. Meta's pixel sets two cookies of its own, "_fbp" and "_fbc", which identify the browser and the advert clicked. We also keep two entries in the web app's local storage, "derive.meta.fbclid" and "derive.meta.eventIds", for up to 90 days, so that a sign up can still be matched to the advert that brought you here and so the same event is not counted twice. We write those only once you have accepted analytics.

The payment event happens without you. A trial is charged seven days after it starts, when no browser of yours is open, so that payment is reported to Meta by our server rather than by your device. It carries the same restrictions as everything above.

Sign ups and trials are reported twice, and counted once. Browsers lose these messages: an ad blocker refuses them, a privacy setting drops them, a tab closes before they are sent. So we send each one from your browser and again from our server, and both copies carry the same reference number, which is how Meta counts them as a single event rather than two. The server copy contains exactly what the browser copy contains and nothing more. In particular our server does not tell Meta your IP address, which is what section 15.1 describes, and it does not tell Meta which browser you use.

13.7 Turning analytics off later. Turning it off stops new collection. It does not delete what was already collected. Email us and we will delete it.


14. Automated decisions and AI transparency

14.1 You are talking to an AI. Derive's recognition, tutoring, summaries, page titles, practice questions and generated diagrams are produced by AI systems. They can be wrong. Our AI disclosure lists each AI feature.

14.2 What is decided automatically. Three things in Derive are decided by software without a person involved:

  • which of your strokes belong together as one piece of work,
  • what your handwriting says,
  • and whether the tutor should change its mind about whether a step is right.

The third of these uses a model we trained, which looks at your handwriting for that step, the recent history of verdicts on that page and how the page has been labelled.

14.3 What follows from it. Nothing legal, financial or contractual. A verdict is a study aid. It does not go to a school, it is not a grade, and no one else sees it. You can always tell the tutor it is wrong, and we record when you do.

14.4 We do not make solely automated decisions that have a legal effect on you, or an effect that is similarly significant. We do not use automated processing to decide whether to sell you a subscription, what price you pay, or whether to close your account.

14.5 Marking AI output. Derive does not currently attach a machine readable marker to AI generated text, diagrams or images, and that marking does not travel with an export. This policy and the AI disclosure are how we tell you which parts of the app are AI generated.


15. Security

15.1 What we actually do.

  • Every table of user data has row level access rules, so one account cannot read another's.
  • All file storage is private and scoped to your own account folder. Files are served through links that expire.
  • Analytics and crash reporting are routed through our own servers, which strip your IP address before anything goes to those companies.
  • Payment webhooks are rejected unless they are correctly signed.
  • Search query text stored for diagnostics is encrypted at rest, and if the key is missing we store nothing rather than store it in the clear.
  • Every response carries strict transport security and a restrictive content policy.
  • Crash replays hide all text and deliberately exclude the canvas, so your handwriting never reaches Sentry that way.

15.2 One current exception to 15.1. A cache of search query vectors is readable by any signed in account. It holds no names or account identifiers, and it does not hold the text of the queries, only a code derived from them and the vector. It is still an exception to the first bullet above, so we are naming it rather than leaving the bullet as an unqualified claim.

15.3 What we cannot promise. No system is completely secure. We cannot guarantee your data is safe from every attack.

15.4 Your part. Use a password you do not use anywhere else. If you share a device, sign out.


16. If something goes wrong: security incidents

16.1 If personal information we hold is lost, or accessed or disclosed without authorisation, we will assess what happened promptly.

16.2 Where the law requires it, and in any event where we think there is a real risk of serious harm to you, we will tell you, and we will tell the relevant regulator. We will do that within the time your law allows, which is 72 hours to the regulator in the European Economic Area, the United Kingdom, Korea and several other places, and as soon as practicable and within 30 days of becoming aware in Australia.

16.3 We will tell you what happened, what information was involved, what we are doing about it, and what you can do.


17. Changes to this policy

17.1 If we want to use your personal information for a new purpose, we will add it to this policy and tell you before we start. Where the law requires your consent for the new purpose, we will ask.

17.2 For anything material, we will tell you by email or in the app, and not only by changing the date at the top.

17.3 This version replaces the version dated 4 September 2026, which replaced the version dated 20 August 2026. Earlier versions are not published on the website. If you want a copy of one, email matt@derivenotes.com.


Part B: Where you live

Part B adds to Part A. It never takes anything away.


B1. European Economic Area, United Kingdom and Switzerland

B1.1 Who is responsible. Derive Notes Pty Ltd is the controller. We are established in Australia and we offer Derive to people in the EEA, the UK and Switzerland, so the GDPR, the UK GDPR and the Swiss FADP apply to us directly.

B1.2 Our legal bases.

What we doLegal basis
Run your account, sync your notes, store your filesContract, Article 6(1)(b)
Recognise your handwriting, answer questions about your page, generate embeddings and search indexes for your own notesContract, Article 6(1)(b). This is the service, not an extra
Optional AI features: summaries, titles, practice questions, page building, diagrams, reading text out of an imageContract, Article 6(1)(b), with a switch in Settings that turns them off
Take payment, keep tax recordsContract, and legal obligation, Article 6(1)(c)
Send service, billing and security emailContract
Send marketing emailConsent, Article 6(1)(a), or the customer exemption in the ePrivacy rules where it applies
Measure whether marketing email was opened or clickedConsent, Article 6(1)(a)
Product analytics, and screen recording if we ever switch it onConsent, Article 6(1)(a)
Crash and error reporting, and performance measurementLegitimate interests, Article 6(1)(f): keeping the app working
Prevent abuse, apply rate limits, control AI spendLegitimate interests, Article 6(1)(f)
Train our own handwriting and mathematics modelsLegitimate interests, Article 6(1)(f). See section 7, and your right to object in B1.5
Aggregated statistics about how Derive is usedLegitimate interests, Article 6(1)(f)
Transfer to a buyer of the businessLegitimate interests, Article 6(1)(f)

B1.3 Special category data. We do not deliberately collect data revealing health, religion, politics, sex life, race or trade union membership. You could write any of those things on a page, and we cannot detect it. We do not use anything on your pages to infer them.

B1.4 Your rights. Access, rectification, erasure, restriction, portability, objection, the right not to be subject to solely automated decisions with legal or similarly significant effects, and the right to withdraw consent at any time without affecting what was lawful before. Section 10 tells you how. We will answer within one month, extendable by two months for genuinely complex requests, and we will tell you before the first month is up if we need longer.

B1.5 Objecting to model training. You have an unconditional right to object under Article 21 because the basis is legitimate interests. Email us and we will stop. See 7.7 for what that does and does not undo.

B1.6 International transfers. Your notes, account and files are stored in Australia. Australia has no adequacy decision. From Australia, we disclose to the recipients in section 6, most of whom are in the United States. For those transfers we rely on the data processing terms each provider offers as part of its standard customer agreement, which for the major providers incorporate the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. We have not signed separately negotiated transfer agreements with every provider on the list. If you want to know which providers are covered and how, email matt@derivenotes.com.

B1.7 Children. In the EEA and the UK, product analytics is off for anyone under 16 and cannot be switched on, because a child under 16 cannot give that consent themselves and we have no way to obtain a parent's. Screen recording is off for everyone, at every age, with no way to turn it on today. We treat 16 as the threshold across the EEA rather than trying to apply each country's lower age, which is the more protective choice.

The AI processing described in section 5 is not age gated. We rely on the contract basis for it. See 5.8.

B1.8 Complaining. You can complain to the supervisory authority in your country. In Ireland that is the Data Protection Commission, in Germany the authority for your Land, and in the UK the Information Commissioner's Office at ico.org.uk. In Switzerland it is the Federal Data Protection and Information Commissioner.

B1.9 Our representatives.

  • European Union representative, Article 27: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria.
  • United Kingdom representative, Article 27: Prighter Ltd, 20 Mortlake High Street, London SW14 8JN, United Kingdom.
  • Reaching them: app.prighter.com/portal/13725773241, which routes you to the right one.

Writing to a representative is an extra route. It does not shorten any deadline and it does not replace your other rights.

B1.10 What we do not have. We have not appointed a Data Protection Officer. We are not required to: we are a small company, our core activity is providing a notebook rather than large scale monitoring, and we do not process special category data on a large scale.


B2. United States

B2.1 Who this applies to. Everyone in the United States. Some parts apply only in named states.

B2.2 We do not sell your personal information for money. We do share a limited amount of it for cross context behavioural advertising, which is a thing California's law calls "sharing" even though no money changes hands. It is what section 13.6 describes: telling Meta that a sign up, trial or payment happened, and sending a hashed email address for users we know to be 18 or over, so we can tell whether an advert worked. It applies only to accounts created from 7 September 2026, so if your account is older than this policy we share nothing about you at all. We share nothing for advertising about anyone under 18 or of unknown age, and we never share your notes with anybody for advertising. You can switch it off: refuse or withdraw analytics consent, or send a Global Privacy Control signal.

B2.3 Sensitive information. We do not collect government identifiers, financial account numbers, precise location, biometric identifiers, health information, or information about race, religion, sexual orientation or union membership. We do collect information from users we know to be minors, which several states treat as sensitive, and section 11 says what we do about it.

B2.4 Your rights across the United States. Depending on your state, you can ask us to tell you what we collect and why, give you a copy, correct it, delete it, and stop selling or sharing it or using it for targeted advertising or profiling. We do not sell it and we do not profile you, so those two are already satisfied. Sharing for cross context behavioural advertising does now happen, it is described in 13.6, and you can stop it yourself at any time by refusing or withdrawing analytics consent, by sending a Global Privacy Control signal, or by emailing us and asking.

B2.5 How to ask, and how long we take. Email matt@derivenotes.com. We will confirm within 10 days and answer within 45 days. If we need longer we may take another 45 days and we will tell you why.

B2.6 Appeals. If we refuse your request, you can appeal by replying to our decision and writing "appeal" in the subject line. We will answer an appeal within 45 days with our reasons. If we refuse the appeal we will tell you how to complain to your state Attorney General.

B2.7 Someone acting for you. You can use an authorised agent. We will ask for written proof that you appointed them, and we may ask you to confirm it directly.

B2.8 We will not treat you differently for exercising any of these rights. We do not offer financial incentives in exchange for your data.

B2.9 Universal opt out signals. We detect Global Privacy Control. If your browser sends it, we treat it as an instruction not to share your personal information for cross context behavioural advertising, and the Meta pixel described in 13.6 does not load. We honour it whatever else you have chosen, and we do not ask you to confirm. Earlier versions of this policy said we did not read the signal, on the ground that we shared nothing and so it would have switched nothing off. Once we started sharing, that stopped being an acceptable answer. The signal does not switch off our own product analytics, which is first party, is not disclosed to any advertising network and does not follow you between sites.

B2.10 California: the CCPA and CPRA disclosures

Categories we collect. In the twelve months before this policy took effect, we collected the following categories, using the statutory labels.

Statutory categoryWhat that means for DeriveWhere it came fromWhy we collect itWho we disclose it toSold or shared?
IdentifiersEmail address, name, account identifier, device analytics code, IP address, Stripe and Apple customer identifiersYou, your device, Stripe, Apple, RevenueCatTo run your account, take payment, email you, prevent abuseSupabase, Amazon SES, Stripe, Apple, RevenueCat, Sentry, Vercel, Cloudflare, and Meta as described in 13.6Shared, but only this: a hashed email address for users we know to be 18 or over, and the fact of a sign up, trial or payment. Never sold.
Customer records (Cal. Civ. Code 1798.80)Name and email held with a payment recordYou and StripeBilling and tax recordsSupabase, StripeNo
Commercial informationSubscription and plan history, payments, refunds, cancellations, promotion codes usedYou, Stripe, Apple, RevenueCatTo sell and support a subscriptionSupabase, Stripe, RevenueCat, AppleNo
Internet and network activityApp feature usage events, website page views after consent, email opens and clicks where permitted, search behaviourYour device, your browser, Amazon SESTo understand and improve the product, and to measure emailPostHog, Amazon SES, VercelNo
Geolocation data, approximate onlyCountry and region worked out from IP address, time zone and languageYour network connection and deviceTo price in your currency, to apply the right consent and age rulesSupabase, VercelNo
Professional or employment informationIf you tell us you are a teacherYouTo set the app up for youSupabaseNo
Education informationStudy level, school year, school name, university, degreeYou, and ROR for the university lookupTo set the app up for you and to personalise itSupabase, RORNo
Audio, electronic, visual or similar informationYour handwriting and ink, rendered page images, page thumbnails, uploaded and photographed images, feedback screenshotsYouTo run the notebook, recognise your work and answer your questionsSupabase, OpenRouter, Relace, Modal, DeepInfra, Google, OpenAI, and Anthropic if you connect ClaudeNo
InferencesRecognised text, verdicts on your work, error type labels, topic labels, embeddings, and a churn snapshot when a subscription endsDerived by us and our AI providers from your contentTo tutor you, to make search work, to improve the modelsSupabase, Google, OpenAINo
Sensitive personal informationPersonal information collected from a user we know to be under 18YouOnly to apply protections: to switch things offSupabaseNo, and never used to infer characteristics

Your California rights. Know, delete, correct, opt out of sharing for cross context behavioural advertising (which does arise, and which 13.6 and B2.9 tell you how to switch off), opt out of sale (which does not arise), limit the use of sensitive personal information (which we already limit to protection only), and not be retaliated against. Two ways to ask: email matt@derivenotes.com, or use the deletion control in Settings, Account.

When California applies to us. The CCPA applies to businesses over a revenue or volume threshold. We may be under it today. We answer California requests anyway, because refusing a student's request on a technicality is not a position worth defending.

B2.11 New York

New York's Child Data Protection Act applies to us with no size threshold once we know a user is under 18. If you are a New York user under 18, we process your personal data only as far as it is strictly necessary to provide Derive, and we do not use it for advertising. If you are 13 to 17 you can consent for yourself where consent is needed. If you are under 13 the account is not permitted at all: see 11.1.

B2.12 Connecticut

Connecticut's law applies to us with no consumer minimum, because we process personal data collected from a known child, which Connecticut treats as sensitive data. If you are a Connecticut user we do not sell your personal data, do not use it for targeted advertising, and do not profile you in a way that produces legal or similarly significant effects. If you are 13 to 17 we do not use your data for targeted advertising and we do not sell it.

Large language models. We use content you create to train our own handwriting and mathematics recognition models, as section 7 explains. We do not sell personal data to anyone for the purpose of training a large language model.

B2.13 Texas, Virginia, Colorado, Oregon, Montana, Delaware, New Jersey, Minnesota, Maryland, Nebraska, New Hampshire, Rhode Island, Iowa, Indiana, Kentucky, Tennessee, Utah, Florida

If you live in one of these states, section B2.4 sets out your rights, B2.5 sets out how to ask, and B2.6 sets out how to appeal. We do not sell personal data in any state. We do share a limited amount for advertising measurement, described in 13.6, for adults who have accepted analytics, and B2.9 explains the universal opt out signal we honour. We never do so for anyone under 18 or of unknown age.

B2.14 Children in the United States

The Children's Online Privacy Protection Act applies to information collected from a child under 13. Derive is not for under 13s, we ask for a birth date on a neutral screen, and we lock an account that tells us it belongs to someone under 13. We do not knowingly collect personal information from a child under 13. If you believe we have, email matt@derivenotes.com and we will delete it. See 4.5 and 9.7, which describe the two places this is currently weaker than it should be.


B3. Australia

B3.1 We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and this policy is our APP 1 privacy policy.

B3.2 Collection. We collect personal information where it is reasonably necessary for our functions and activities, which are running a notebook app and the business around it.

B3.3 Access and correction. APP 12 and APP 13. Email matt@derivenotes.com. We will respond within 30 days. We do not charge for access.

B3.4 Overseas disclosure. We disclose personal information overseas to the recipients in section 6, in the United States and the European Union. Before we disclose, we take the steps APP 8.1 requires to satisfy ourselves that the recipient will handle the information consistently with the Australian Privacy Principles. Our database, our server code and our email sending all sit in Australia, in AWS Sydney.

B3.5 Notifiable data breaches. If an eligible data breach occurs we will assess it and, where required, notify you and the Office of the Australian Information Commissioner under Part IIIC of the Privacy Act. See section 16.

B3.6 Marketing. We comply with the Spam Act 2003 (Cth). Every commercial message comes from noreply@derivenotes.com and lets you unsubscribe. See 12.4 for what the footer does and does not currently carry.

B3.7 Complaints. Tell us first. If you are not satisfied, complain to the OAIC at oaic.gov.au or 1300 363 992.

B3.8 Automated decisions. From 10 December 2026 Australian privacy policies must describe personal information used in automated decision making. Section 14 does that. We will keep it current.


B4. Canada, including Quebec

B4.1 We handle personal information in accordance with PIPEDA, and, if you are in Quebec, with Quebec's Law 25.

B4.2 Consent. We rely on your consent, express or implied depending on how sensitive the information is. Your notes are sensitive, and section 5 explains what happens to them.

B4.3 Marketing. Canada's Anti-Spam Legislation requires express or implied consent before we send you commercial email, and requires each message to name us and give our mailing address. See 12.4 and 12.5, which are honest about where we currently fall short.

Where we rely on the implied consent of an existing business relationship, that consent lasts for two years from your last payment.

B4.4 Quebec: privacy by default. Law 25 requires the highest privacy settings by default for a technological product. Today, product analytics is on by default outside Europe, including in Canada. You can switch it off in Settings, Account.

B4.5 Quebec: automated decisions. If a decision about you is made only by automated processing, you can ask to be told, to make representations, and to have a person review it. Section 14 describes the three automated processes in Derive, none of which has a legal or similarly significant effect. You can still email us for a human review of any verdict.

B4.6 Quebec: minors. Derive is not for anyone under 14 in Quebec, because we would need a parent's consent that we have no way to obtain. See 11.4.

B4.7 Complaining. The Office of the Privacy Commissioner of Canada at priv.gc.ca, or the Commission d'accès à l'information du Québec.


B5. Brazil

B5.1 The Lei Geral de Proteção de Dados applies to us because we offer Derive to people in Brazil.

B5.2 Your rights. Confirmation that we process your data, access, correction, anonymisation or deletion of unnecessary data, portability, information about who we share with, information about the consequences of refusing consent, and withdrawal of consent. Email matt@derivenotes.com. We will answer within 15 days.

B5.3 Legal bases. Performance of a contract for running the app and recognising your work, legal obligation for tax records, consent for marketing and for analytics, and legitimate interests for diagnostics, abuse prevention and model training.

B5.4 Children and adolescents. Under the LGPD, processing a child's data requires the specific and prominent consent of a parent or guardian, and processing an adolescent's data must be in their best interests. We have no parental consent mechanism. Our minimum age is 13. Product analytics is on by default in Brazil unless your age band is under 13, and you can switch it off in Settings, Account.

B5.5 Complaining. The Autoridade Nacional de Proteção de Dados, gov.br/anpd. We have not appointed a representative in Brazil. Our contact point is matt@derivenotes.com.


B6. India

B6.1 The position, stated plainly. India's Digital Personal Data Protection Act 2023 requires verifiable parental consent before processing the personal data of anyone under 18, and prohibits behavioural tracking and targeted advertising directed at anyone under 18, with no way to consent around it.

B6.2 You must be 18 or over. We have no verifiable parental consent mechanism. Derive is therefore only for people in India who are 18 or over. If you are under 18 in India, you may not use Derive. We do not check this at sign up.

B6.3 Marketing. We do not send marketing email to any user in India we know to be under 18, and no permission changes that.

B6.4 Contact. Our contact point for Indian users is matt@derivenotes.com.


B7. Japan

B7.1 The Act on the Protection of Personal Information applies to us because we offer Derive to people in Japan.

B7.2 Cross border transfer. Section 6 and the Subprocessors page name every company that receives your information and the country each is in. The main recipients are in the United States. We rely on your agreement to this policy, given at sign up, together with the contractual terms we have with those companies, and we provide the country information so that your agreement is informed.

B7.3 You must be 18 or over. The 2026 amendment to the APPI requires the consent of a guardian for anyone under 16. We have no guardian consent mechanism. Derive is therefore only for people in Japan who are 18 or over. We do not check this at sign up.

B7.4 Your rights. Disclosure, correction, suspension of use and deletion. Email matt@derivenotes.com.

B7.5 Complaining. The Personal Information Protection Commission, ppc.go.jp.


B8. Republic of Korea

B8.1 The Personal Information Protection Act applies to us because we offer Derive to people in Korea.

B8.2 Cross border transfer. PIPA requires separate, itemised consent for transferring your personal information overseas. Section 6 and the Subprocessors page name each recipient, what it receives and where it is. Derive does not currently show a separate Korea specific consent screen before the first transfer. This policy is where the transfer is disclosed.

B8.3 You must be 18 or over. PIPA requires the consent of a legal representative for anyone under 14, and we have no mechanism for that. Derive is only for people in Korea who are 18 or over. We do not check this at sign up.

B8.4 Marketing. Korean law requires prior consent, a subject line marked as advertising, our contact details in the message, and re-confirmation of consent every two years. It also prohibits sending advertising between 21:00 and 08:00 without separate consent. Our email system does not currently apply Korea specific send windows, subject marking or re-confirmation. If you are in Korea and receive marketing email from us that does not meet these rules, unsubscribe from the link in the message or email matt@derivenotes.com.

B8.5 Complaining. The Personal Information Protection Commission, pipc.go.kr.


B9. Everywhere else

B9.1 New Zealand. The Privacy Act 2020 applies. Since 1 May 2026, IPP 3A requires us to tell you when we collect your information from a source other than you. Section 3 does that: it lists every indirect source we use. You can complain to the Office of the Privacy Commissioner at privacy.org.nz.

B9.2 Singapore. The Personal Data Protection Act applies. We rely on your consent, and you can withdraw it. Our contact point for PDPA purposes is matt@derivenotes.com. Under the PDPC's guidance on children's data we would need a parent's consent below 13, which is why our minimum age is 13. Commercial email sent without your prior consent must be marked, and section 12 explains how permission works.

B9.3 South Africa. POPIA prohibits processing a child's personal information, meaning anyone under 18, without the consent of a competent person. We have no such mechanism. Derive is therefore only for people in South Africa who are 18 or over. We do not check this at sign up.

B9.4 Mainland China. Derive may not be used from mainland China. We do not offer it there and we have no representative there.

B9.5 Nigeria, Kenya, Saudi Arabia and the United Arab Emirates. Each of these countries requires a local representative or a specific legal basis for sending personal information abroad. We have neither. We do not currently restrict sign up by country, so if you use Derive from one of them you should know that we have no local presence and that your information goes to the countries named in section 6.

B9.6 Anywhere not named. Section 10 gives you the same core rights everywhere. If your local law gives you more, tell us what it is and we will apply it.