Privacy Policy

Rinora · Last updated: July 22, 2026

This Privacy Policy describes how Rinora ("we", "us", or "the App") handles your information when you use our iOS application. We built Rinora to be privacy-first and local-first: every feature works without an account, your notes live on your device by default, and the data we do collect is the minimum required to provide the AI features you opt into.

The honest summary: Notes you sync to our servers are end-to-end encrypted in transit and at rest, so we cannot read those stored copies. Locally, notes live in your device's app sandbox (protected by your device passcode / Face ID) in plaintext, the same way Apple Notes and most local apps work. When you use AI features (Ask, auto-tagging, summarization, search embeddings, image OCR, scene description), the relevant note text or image is decrypted by our proxy at the moment you invoke the feature and forwarded to the routed AI provider in plaintext. We prefer providers that offer no-training and zero-retention terms for API calls where contractually available; the specific terms vary by provider.

1. Information We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

1.3 Information We Do NOT Collect

2. How We Use Information

2.1 Legal Bases for Processing (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the legal bases on which we process your personal data are:

3. Third-Party Services

Rinora relies on the third-party services below. Each receives only the minimum data necessary.

3.1 Authentication

3.2 Backend and Sync

3.3 AI Providers

Your explicit consent is required before any content reaches an AI provider. AI features are off by default. The App asks for your permission on a dedicated consent screen during onboarding (or, if you are updating from an earlier version, in a one-time prompt on first launch), which identifies each provider by name and explains what is sent. You can grant or withdraw consent at any time in Settings → Privacy → AI features. While AI features are off, the App works fully with on-device processing and none of your content is sent to any AI provider.

When AI features are enabled and you invoke an AI feature, your prompt and the relevant note content are temporarily decrypted in transit on our proxy and forwarded to the AI provider routed to your task. We prefer providers that offer no-training and zero-retention terms for API calls where contractually available; the specific terms vary by provider and may include short-term retention for abuse detection or operational logging. Consult each provider's API data-use policy for current terms. The active set is:

We will update this list before routing any content to an additional provider.

The routing decision is made by our proxy based on your task class, language, and quota; you can see and adjust the routing preference in Settings → AI Model.

What this means in plain English: If you ask Rinora "what did I do yesterday", the question plus the small set of notes the App believes are relevant are sent in plaintext to whichever model is routed. If you use the OCR or scene-description feature on an image, the image bytes are sent in plaintext to the chosen vision model. If you never enable AI features — or turn them off in Settings — your notes are never decrypted off-device.

3.4 Subscriptions and Payments

Rinora offers an optional Premium subscription via Apple In-App Purchase. Available plans:

Prices are shown in the App in your local currency, as set by Apple's regional pricing matrix. Subscriptions automatically renew at the end of each billing period unless cancelled at least 24 hours before the renewal date. Your Apple ID account is charged at the price displayed at purchase.

You can view, change, or cancel your subscription anytime from iPhone Settings → [Your Name] → Subscriptions. Cancelling stops the next renewal; the current period continues until its end date.

All purchases are governed by Apple's Standard EULA for App Store apps and our Terms of Use. Refund requests are handled by Apple per their App Store refund policy.

Payment information: all charges are processed by Apple. We do not collect, store, or have access to your credit card, billing address, or other payment information. Apple sends our backend a signed App Store Server Notification (ASSN v2) when your subscription starts, renews, or ends so we can update your Premium status. See Apple's Privacy Policy for how Apple handles payment data.

4. Encryption and Data Security

5. Local-Only Features

The following features run entirely on your device and never transmit data to any server:

6. Guest Mode

Every feature in Rinora works without signing in. In Guest mode:

7. Data Retention and Deletion

8. Children's Privacy

Rinora is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.

9. Your Rights

Depending on your jurisdiction (EU / UK / California / etc.), you may have the right to:

To exercise any of these rights, email harley510396@gmail.com. Because notes are end-to-end encrypted, your portable data export consists of the plaintext notes you can already see on your device, plus your account metadata.

10. International Data Transfers

Our backend servers (Supabase) are located in the United States. AI providers may operate servers in the United States, the European Union, China, or other regions; the routing decision is made by our proxy per request and may change over time for redundancy and quota.

For users located in the European Economic Area, the United Kingdom, or Switzerland, transfers of personal data to recipients outside those regions are made under one or more of the following transfer mechanisms:

For AI providers based in jurisdictions without an adequacy decision or self-certification (e.g., certain China-based providers), we rely on your explicit consent (Art. 49(1)(a) GDPR) given when you invoke the AI feature, and we route requests to such providers only when no alternative provider is available for your task.

You can request a copy of the relevant safeguards by contacting us at the address below.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be communicated through the App or by email.

12. Data Controller and Contact

The data controller responsible for your personal data under this Privacy Policy is:

Hao Li (sole proprietor, doing business as Rinora)
United States of America
Email: harley510396@gmail.com

For a postal mailing address or to exercise any of the rights described in Section 9, please contact us by email and we will respond within 30 days.

12.1 EU / UK Representative

Rinora is operated from the United States and is not specifically targeted at users in the European Economic Area or the United Kingdom. If you are an EEA or UK resident with a privacy question or request, you may contact us at the email above and we will assist you. We have not currently designated a representative under Article 27 of the GDPR; we will appoint one if and when we begin offering the App with substantial volume to EEA / UK markets.

12.2 California Residents

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA / CPRA), including the right to know what personal information we collect, the right to delete that information, the right to correct inaccurate information, and the right to opt out of the "sale" or "sharing" of personal information. We do not "sell" or "share" your personal information as those terms are defined under the CCPA, and we do not use sensitive personal information (which includes your notes' contents) for purposes other than providing the requested service. To exercise any CCPA right, email us at the address above.

See also our Terms of Use.