Privacy
Your people
stay yours.
Dotty is a notebook about the people in your life. This page says what happens to what you write in it, in the order that matters — starting with the one choice that decides everything else.
Last updated31 July 2026
The short version
Dotty works with no account at all.
Choose “Only on this device” and your contacts and notes never leave your phone — there is nothing for us to hold, hand over or lose. Only if you choose cloud mode, by signing in to an account, is the same data mirrored to a server in Ireland, encrypted in transit and at rest and reachable only by you.
No trackers, no analytics and no advertising in either mode. Nothing you write is sent to an AI model.
At a glance
Four things, before the detail.
No account needed
Dotty asks for nothing to start. No email, no phone number, no sign-up wall between you and the first person you add.
Encrypted on your device
The database is encrypted with SQLCipher, and its key stays in the phone’s Keychain marked for that device alone. It is left out of iCloud and Android backups.
No trackers, no analytics
There is no analytics SDK, no advertising SDK and no data broker anywhere in the app. This site sets no cookies and counts its visits without identifying anyone.
Yours to take, yours to end
Export everything as one file, photos and attachments included. Delete your account inside the app — no email, no form, no waiting.
Who we are
Dotty is made and published by Basri Kerem Alhan, in Rome, Italy, who is the data controller for it under the GDPR. Everything on this page describes what the app itself does, and it is kept in step with the code rather than written once.
Write to privacy@dottynotes.com about anything on this page — an export, a deletion, or a question about a sentence here. It reaches a person rather than a ticket queue.
The two storage modes
Everything below turns on one choice you make in the app, so it comes first.
Only on this device. No account, no sign-in, nothing of yours on a server. Your people live in an encrypted database on the phone and nowhere else, and we hold no data about you at all — not a name, not an email, not a single note. The one thing that leaves the phone is the purchase, because the App Store takes the money and we never see it.
Synced to your account — cloud mode. Only if you choose this and sign in with Apple or Google is the same database mirrored to our server, so a lost phone is not lost data. Rows and files are encrypted in transit and at rest, and only your account can read them.
Both modes read and write the same encrypted database on the phone; an account adds a mirror rather than moving where the app looks. You can switch either way whenever you like, and switching back to “only on this device” ends by offering to delete the server copy.
What Dotty collects, and why
Nine kinds of data, the same list the App Store shows. Each one is there to make the app work and for nothing else — no advertising, no profiling, no sale to anybody. Where an entry says “with an account”, it applies only if you choose cloud mode; in device-only mode there is no such data anywhere.
Your name and email — with an account
Given by Sign in with Apple or Google so the account has an identity. Apple’s private relay address works fine, and Dotty never sees a password, because there isn’t one.
The people you add
Names, birthdays, cities and anything else you fill in about them. This is the app; it is the reason to have it.
Phone numbers
Numbers you put on a profile so it can dial them, typed by you or brought in from your address book.
Contacts
Only through the system’s own picker, one person at a time, when you tap “Add from Contacts”. Dotty never reads your address book by itself and never uploads it.
Photos and files
Pictures you choose for someone and files you attach to a profile. On device-only they are files in the app’s own folder; with an account they sit in private storage that only your account can open, behind links that expire within the hour.
Everything else you write
Notes, lists, checklists, fields, folders, events, reminders, circles, and where people sit on the map.
A user ID — with an account
The identifier your account carries on our server. Without an account there is no such thing.
Purchase history
The one-time unlock. The App Store or Google Play takes the payment and tells RevenueCat the sale happened; our server records that this account is unlocked. Your card details never come near us.
A device identifier
RevenueCat receives the vendor identifier your phone gives the app, so a purchase can be restored on a new one. It is joined to nothing else and never used for advertising.
And what it never does
No location, no microphone, no camera roll beyond the picture you pick, no advertising identifier, no behavioural profile, and no analytics events of any kind — the app ships with no analytics SDK and no ad SDK to send them.
Nothing you write is sent to an AI model, by us or by anyone else. Search runs on your phone, over rows already in memory.
Your data is never sold, rented or handed to a data broker. There is no version of this app in which that changes without this page changing first.
This website
This section is about the website dottynotes.com — the page you are reading — not the Dotty app. The app ships with no analytics of any kind, and nothing below changes that; what the app does with your data is the whole of the sections above.
The site sets no cookies, which is why there is no cookie banner to click. The language you choose in the footer is remembered in your browser’s local storage, on your device, and that is the only thing the site keeps there. The contact form has no backend — it opens your own mail app, so your message travels from your address to ours and through nothing in between.
We count visits without identifying visitors. When a page loads, the site tells our own measurement endpoint — and Cloudflare, which serves the site — the page viewed, the site you came from, the country, the language and the kind of device. No cookies, nothing written to your browser, no fingerprinting: the technical identifier behind these counts is rotated every day, your IP address is used only in passing and never stored, and neither we nor Cloudflare can follow you across days or across other sites.
These aggregates rest on our legitimate interest in knowing whether the site works (Art. 6(1)(f) GDPR), are kept for a few months at most, and are never joined to anything from the app. If you would rather not be counted at all, an ordinary content blocker will do it, and we do not mind — or write to privacy@dottynotes.com.
Who else is involved
Six services, each doing one job, each acting only on our instructions under its own data processing terms. None of them is given your data for its own purposes, and none of them is a data broker.
Supabase
The database and file storage behind an account, hosted in Ireland. Reached only if you choose cloud mode — in device-only mode nothing of yours is ever sent to it.
Apple and Google
Sign-in. They confirm you are you; they are told nothing about what is inside your app.
The App Store and Google Play
Payment for the unlock. They take the money, and neither passes us anything but the fact of the sale.
RevenueCat
Records that the unlock was bought, so it can be restored on a new phone. Used in both modes, because buying something is not a reason to have an account.
Expo
Over-the-air updates. The check tells Expo which platform and app version asked for one; nothing of yours travels with it.
Cloudflare
Serves this website and counts its visits in aggregate — no cookies, no cross-site tracking. It sees nothing of the app.
If that list ever grows, this page changes on the same day.
Where it is kept, and for how long
Only if you choose cloud mode are an account’s rows and files held by Supabase in Ireland, inside the European Union. If you are outside the EU, choosing cloud mode means your data is transferred to and stored there. In device-only mode there is nothing of yours on any server at all.
In cloud mode we keep what is in your account for as long as the account exists. A deleted row leaves a tombstone behind — an identifier and a time, no content — so your other devices learn that it went; those are erased after 90 days. The record of a purchase is kept for as long as the stores’ own rules require.
Data on your phone stays until you delete it or delete the app. Deleting the app takes the database, the photos and the attachments with it, and because the encryption key is marked for that device alone and both data folders are excluded from backups, no readable copy is left behind in iCloud or in a Google backup.
Your rights
Under the GDPR you can ask for a copy of your data, for it to be corrected or erased, for processing to be restricted, for portability, and you can object to processing. Two of those need no asking: Export hands you everything as a single file, photos and attachments included, and Delete account erases it. Both live in the app’s settings.
For anything else write to privacy@dottynotes.com. We answer within 30 days. If you believe your data has been handled badly you can complain to your supervisory authority; in Italy that is the Garante per la protezione dei dati personali.
The legal bases are short. Everything the app needs in order to work is done to perform the agreement you enter by using it (Art. 6(1)(b)). Keeping the service secure and confirming that a purchase is real rests on our legitimate interest (Art. 6(1)(f)). We do not rely on consent, because nothing here is done that would need it — apart from the permissions your phone asks for, Contacts, Photos and notifications, which you grant and can withdraw in your phone’s settings at any time.
Deleting your account and your data
This section is also the web page Google Play asks every app with accounts to publish, so it is written to stand on its own.
In the app. Settings → Account → Delete account. It removes your profile, everyone in it, their blocks, rows, events, reminders, templates, circle memberships and phone numbers, along with every photo and file stored with them, and the record of your purchase. It happens at once and cannot be undone.
If you have already uninstalled. Write to privacy@dottynotes.com from the address you signed in with and ask for deletion. We confirm the account is yours and erase it. An unauthenticated request is never acted on, because that would be a way to delete somebody else’s account.
If you only want some of it gone. Any person, note, list, photo or file goes the moment you delete it in the app, and switching back to “only on this device” ends by offering to delete the server copy while the account itself stays. For anything you would rather we removed for you, write to the same address — we answer within 30 days.
What deletion does not touch is data kept only on your own device, which nobody else can reach. Deleting the app removes that.
Deleting your account does not refund the unlock — refunds are handled by the App Store or Google Play, and we are glad to help you ask.
Children
Dotty is not directed at children under 13, or under the higher age your country sets, and we do not knowingly collect anything from them. There is nothing social in the app: no messaging, no shared content, and nobody else who can see what you write. If you believe a child has given us data through an account, write and it will be erased.
Changes, and how to reach us
If anything here changes in a way that matters, the date at the top of this page moves and the app says so the next time you open it. Nothing new will start being collected without this page saying it first.
Basri Kerem Alhan · Rome, Italy · privacy@dottynotes.com for privacy, hello@dottynotes.com for everything else.