Derive Notes Pty Ltd (ACN 696 859 597) of Queensland, Australia ("Derive", "we", "us") operates Derive, a canvas-first note-taking app for maths, science, and engineering students. We are the data controller for the personal data described here.
Questions, requests, or complaints: matt@derivenotes.com.
What this policy covers
This policy covers the Derive app on every platform we offer it, the website at derivenotes.com, and any other service that links to this policy.
What we collect
| Data | What it is |
|---|---|
| Account and identity | Email address, display name, avatar, sign-in provider, internal user id |
| Age | Your age or age band, and how we established it |
| Notebook content | Handwriting strokes, drawings, typed text, pages, notebooks |
| AI-derived content | Recognition output, page semantics, embeddings, assistant threads, practice questions, skill attempts |
| Collaboration and presence | Invitations, membership, live cursor and presence signals |
| Uploaded files | Images you place on the canvas, screenshots and recordings you send us |
| Submitted code | Source code and input you run in the app |
| Support and feedback | What you write to us, and anything you attach |
| Device and technical data | Device and operating system details, app version, language, IP address, request logs, and the identifiers our providers assign |
| Diagnostics | Crash reports, performance traces, and replays of sessions that hit an error |
| Product analytics | Which features you use, in the app and on the website |
| Screen recording | A recording of your screen while you use the app, which includes your handwriting |
| Payments | Payment-provider identifiers, subscription and billing status. We do not receive full card numbers |
| Email deliverability | Addresses that bounced or reported us as spam |
| Waitlist and marketing | Email address, and what you choose to tell us |
We work out an approximate location from your IP address, to the level of country and region. We do not collect satellite location from your device.
Why we use it
These are the purposes we collect and use personal data for. This list is complete. If we want a purpose that is not on it, we will add it here and tell you before we start.
- Create your account, sign you in, and keep the account secure.
- Store your notebooks and sync them between your devices.
- Recognise your handwriting, and convert it to text and mathematical notation.
- Answer questions you ask about the work on your page, and mark whether your working is correct.
- Produce page summaries, page titles, practice questions, diagrams, and search indexes, if you turn those features on.
- Read text and code out of images you place on the canvas, if you turn that feature on.
- Run the code you submit, and return its output.
- Share a notebook with the people you invite, and show their cursor and presence to each other.
- Take payment, manage your subscription, and keep the accounting records Australian law requires.
- Train, fine-tune, and evaluate our own handwriting and mathematics recognition models, using the content you create.
- Measure which features you use, if you turn usage analytics on.
- Record your screen while you use the app, if you turn screen recording on.
- Find and fix crashes and performance faults.
- Stop sending email to an address that bounced or reported us as spam.
- Answer your support messages, and investigate the problems you report.
- Send you product news you asked for, and act on your unsubscribe.
- Detect, investigate, and stop fraud, abuse, security incidents, and breaches of our terms.
- Produce aggregated and statistical datasets that do not identify anyone, and use, publish, or sell those datasets.
- Meet our legal obligations, answer lawful requests from authorities, and bring or defend legal claims.
- Transfer your data to a buyer, and let that buyer keep using it for the purposes on this list, if we sell or merge the business. We will tell you before that happens.
Legal bases (EEA, UK, and Switzerland)
| Purposes | Basis |
|---|---|
| 1 to 9 | Contract, Article 6(1)(b) |
| 10, 13, 14, 15, 17, 18, 20 | Legitimate interests, Article 6(1)(f) |
| 5, 6, 11, 12, 16 | Consent, Article 6(1)(a) |
| 9 and 19 | Legal obligation, Article 6(1)(c) |
Our legitimate interests are, in order of the purposes above: building a product that reads student handwriting accurately (10); keeping the app working (13); protecting our sending domain from being blocked (14); answering the people who contact us (15); protecting our users and our service from abuse (17); measuring how the product performs in aggregate (18); and completing a sale of the business (20). We have weighed each against your rights and recorded the assessment. You can object to any of them — see Your rights.
In Australia we collect personal information where it is reasonably necessary for one or more of our functions or activities, under APP 3.2.
AI features
Reading your handwriting is what Derive does. It recognises your writing, understands the maths, and answers questions about the work on your page. Without that, Derive is a blank canvas, which is not the product we offer. So purposes 3 and 4 are part of using Derive, and there is no version of the app that keeps your content on your device.
What leaves your device
The content the feature needs to produce your result. Depending on the feature, that is your handwriting strokes, the recognised text on the page, images you placed on the canvas, the surrounding page context, and the question you asked.
Who receives it
| Provider | What it does | Country |
|---|---|---|
| Recognition and tutoring | United States | |
| OpenAI | Recognition, tutoring, and embeddings for search | United States |
| OpenRouter | Routes recognition requests to the two hosts below | United States |
| DeepInfra | Runs open-weight recognition models | United States |
| Parasail | Runs open-weight recognition models | United States |
We engage these providers under terms that limit their use of your content to providing the service to us. We do not control their systems, so we cannot guarantee their conduct.
If we add or change an AI provider, we update derivenotes.com/subprocessors and this table.
Optional features
Purposes 5 and 6 are optional. Turn them off in Settings → AI. The core features keep working, and nothing else in the app changes.
Running code
If you run code in the app, the source and any input you supply go to Judge0, reached through RapidAPI, to be executed.
Using your content to improve Derive
We use the content you create to train, fine-tune, and evaluate our own handwriting and mathematics recognition models. That is purpose 10. The content we use is your notebooks, handwriting, typed text, images, questions, and the output the AI produced from them. We do this ourselves, and with contractors working under our instructions.
We also produce aggregated and statistical datasets from that content, which do not identify anyone. That is purpose 18. We use, publish, and sell those datasets.
Handwriting identifies a person the way a signature does. So we do not claim your content in its original form is anonymous.
Our basis is legitimate interests, Article 6(1)(f). You can object at any time by emailing matt@derivenotes.com. Objecting stops further use for this purpose. It does not require us to retrain or discard a model or a dataset we already produced.
If you delete content, we stop using it for this purpose. Models and datasets we already produced are not affected.
Analytics and screen recording
Both are off until you switch them on, and neither is required to use Derive.
Usage analytics records which features you use, such as opening a notebook or creating a page.
Screen recording is a separate switch. It records your screen while you use the app, and that includes your handwriting on the canvas. We ask for it separately because it is more revealing than usage analytics.
Both go to PostHog, in the European Union. They reach it through our own servers, which strip your IP address first. Turn either off in Settings → Account, and recording stops straight away.
Where the law that applies to you sets a minimum age for consenting to this kind of processing, we apply that age.
Crash and performance diagnostics are separate, and these switches do not control them. They go to Sentry, in the United States.
Subprocessors
The full list of providers, what each receives, and which country each processes data in, is at derivenotes.com/subprocessors. We update that page when a provider changes.
We also disclose personal data to our professional advisers, to a buyer of the business under purpose 20, where you ask us to, and where the law requires it.
Where your data goes
Your notebooks, account, files, and AI-derived content are stored with Supabase in Sydney, Australia. They are not stored outside Australia.
Personal data leaves Australia for these purposes only:
| Goes to | Country | Why |
|---|---|---|
| Google, OpenAI, OpenRouter, DeepInfra, Parasail | United States | Purposes 3 to 6 |
| Judge0 via RapidAPI | United States | Purpose 7 |
| Sentry | United States | Purpose 13 |
| PostHog | European Union | Purposes 11 and 12 |
| Amazon Web Services | United States | Purposes 14 and 15 |
| Stripe | United States | Purpose 9 |
| Vercel | United States | Serving the website |
| Brevo | European Union | Purpose 16 |
| Apple | United States | In-app purchases, and your age range if you allow it |
For transfers out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum. For disclosures out of Australia we take the steps APP 8.1 requires.
How long we keep things
| What | How long |
|---|---|
| Your account and content | While your account is open |
| Your account after you delete it | A grace period in which you can change your mind, then we delete the account and its synced records |
| A notebook or page you delete | Until the next scheduled purge after you delete it |
| Billing records | 7 years, which Australian tax and accounting law requires |
| Bounced and complained email addresses | While we still need them to avoid re-mailing that address |
| Diagnostics | While we still need them to investigate the fault |
| Support messages | While we still need them to answer you and handle any dispute |
| Aggregated and statistical datasets, and the models we trained | Indefinitely, because they do not identify anyone |
Where a period above is not a fixed number, the criterion is the purpose it was collected for. We delete the data when that purpose ends, unless a law requires us to keep it longer. Backups and archives are deleted on their own cycle.
Your rights
Email matt@derivenotes.com to exercise any of these. We answer within the time the law that applies to you allows, and we will not treat you differently for asking.
- Access. Ask what we hold about you.
- Portability. Ask us, and we send you the data you gave us in a machine-readable file. You can also download the data cached on your device at any time, from Settings → Account.
- Correction. Fix anything wrong.
- Erasure. Delete your account and your content, in the app or by email.
- Restriction and objection. Ask us to stop a use, including purpose 10.
- Withdraw consent. For purposes 5, 6, 11, 12, and 16, in Settings or by email, at any time.
The law that applies to you sets the limits and exemptions on these rights.
Australia
We handle personal information under the Australian Privacy Principles in the Privacy Act 1988 (Cth). You can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
European Economic Area, United Kingdom, and Switzerland
Derive Notes Pty Ltd is the controller. The bases are in Legal bases above. You can complain to your local supervisory authority.
California
You can ask what we collect, ask us to delete it, ask us to correct it, and not be treated differently for asking. We do not sell your personal information for money. We do not share personal information for cross-context behavioural advertising.
Children and age
You must be at least 13 to use Derive.
We establish your age at sign-up. On Apple devices we use the age range Apple gives us, with your permission, so you do not have to give us your date of birth. Elsewhere we ask you directly.
Where the law that applies to you sets a higher minimum age for a kind of processing, or requires extra protection below a given age, we apply it.
If we learn an account belongs to someone under 13, we delete it. If you think someone under 13 has an account, tell us at matt@derivenotes.com.
Things you may write in your notes
Derive gives you a blank canvas, so you can write anything on it. Notes can end up holding things privacy law treats as sensitive — health details, religious or political views, or information about other people.
We do not ask for that information, we do not look for it, and we cannot detect it. Content on a page where you use an AI feature is processed like any other content.
Please do not put information into Derive that you would not want processed as this policy describes. If you have written something you want removed, delete the page or the notebook, or email us.
Security
We take reasonable technical and organisational steps to protect personal data. Every table that holds your data has row-level access control, so no account reads another's. Every file store is private, and files are served through links that expire. Analytics and diagnostics traffic goes through our own servers rather than straight to the provider. No system is completely secure, and we cannot guarantee your data is safe from every attack.
Data on your device
Derive is local-first. Your notebooks live in a database inside the app on your device, so it keeps working offline, along with your assistant conversations.
Signing out clears that local data — the notebook cache, the assistant conversations, the pending sync queue, and the analytics identity.
Deleting your account does not by itself erase the copy on your device. It stays until you sign out, clear the app's storage, or remove the app.
Sharing and collaboration
Your notebooks are private by default. What you create is visible to you, and to anyone you invite to a shared notebook.
To invite someone you enter their email address, which tells us whether an account already exists for it. Inside a shared notebook, collaborators see your cursor and presence while you are both there.
If we build a feature that makes content visible more widely, we will describe it in the app before you use it.
Changes
We update this policy when our practices change. The current version is at derivenotes.com/privacy, with a new "Last updated" date.
If we add a purpose to the list above, we tell you before we start using your data for it. Where the law requires your consent for a change, we ask for it.
Contact
Derive Notes Pty Ltd (ACN 696 859 597)
Queensland, Australia
matt@derivenotes.com
Governing law
This policy is governed by the laws of Queensland, Australia, without regard to its conflict-of-laws rules, and subject to any rights you have where you live that cannot be excluded.