Last updated: August 29, 2026
This policy describes what "Tee" (the "Service"), operated by Lacher Ventures, LLC and available at teenotes.app, collects and how it is handled. The short version: we store the notes you write so the Service can work, we collect nothing for advertising or analytics, and we tell you plainly below what the operator can and cannot see.
Sign-in data from Google or Apple. Tee uses Google sign-in and
Sign in with Apple only — there are no passwords. When you sign in we receive and
store your email address (with Apple, this may be a private relay address if you
choose "Hide My Email"), your display name (Apple shares it once, at your first
sign-in), and the provider's account identifier for you. We request only the basic
scopes (Google: openid email profile; Apple: name and email); we cannot
see your Gmail, contacts, calendar, iCloud, or anything else in those accounts. The
providers' own use of your data is governed by their privacy policies.
Content you create. Your notes, tags, attachments, note version history, and sharing choices are stored on our server — that is the Service.
Operational records. Server logs record events like sign-ins, sharing grants and revocations, administrative actions, and rejected uploads. Log entries never include the content of your notes. We use a session cookie and a security (CSRF) cookie — both strictly necessary; there are no analytics, no advertising trackers, and no third-party attribution code.
Your content is visible to you and to the specific people you share a note or tag with — sharing is always an explicit action, and the Service is invite-only. Nothing is public. Access rules are enforced on every request, including for images and file downloads.
Your content is stored on infrastructure operated by Lacher Ventures, LLC (a server hosted with DigitalOcean in the United States). Content is protected by access controls, and backups are encrypted before leaving the server (to a key kept off the server) — but stored content is not end-to-end encrypted: the operator is technically able to access it, and does not do so except as required to operate the Service (for example, debugging a fault or investigating abuse) or as required by law. We are working toward optional end-to-end encryption; this policy will be updated when the guarantees change.
Tee has an optional AI suggestion feature (suggested titles and tags). It is currently disabled. If it is enabled in the future: when you explicitly request suggestions for a note, that note's title and text are sent to a third-party AI inference provider to generate the suggestions, and this policy will be updated to name the provider before the feature is turned on. Nothing is ever sent automatically, and suggestions are never applied without your confirmation. Separately from this feature, AI tools are used in developing the Service's software; your stored content is not part of that.
Content stays until you delete it. Deleted notes are recoverable by the administrator for 30 days, then purged permanently, including their attachments. Deleting your account (Account → Delete account) removes your notes, attachments, version history, sessions, files you uploaded to shared notes, and sharing records — immediately and self-service. Server backups are encrypted, made nightly, and roll off after 30 days; deleted data leaves backups on that schedule.
Account → Export downloads a zip of all your notes (as markdown, with tags and timestamps) and attachments at any time. No lock-in is the design.
We do not sell, rent, or share your personal information or content with third parties for their own purposes. The only third parties involved in operating the Service are our infrastructure provider (DigitalOcean, hosting), Google and Apple (sign-in), and — only if enabled as described above — an AI inference provider. Limited disclosures may occur if required by law, in which case we will notify you unless legally prevented.
Wherever you live — and specifically under the GDPR (EU/UK) and the CCPA/CPRA (California) — you can access, correct, export, or delete your data. Export and deletion are self-service inside the Service; for anything else, or to exercise any right, email privacy@lacherventures.com. We do not discriminate for exercising your rights, and we do not sell personal information as defined by the CCPA.
The Service is not directed to children under 13 (16 in the EU/UK) and we do not knowingly collect their data.
Updates to this policy will be reflected in the "Last updated" date above, with in-Service notice for material changes — including before any change to the AI or encryption guarantees described in sections 3 and 4.
Privacy questions and rights requests:
privacy@lacherventures.com
General support:
support@lacherventures.com