Privacy Policy for noi
Effective date: October 5, 2026
MyAppDesk operates noi. This policy covers the noi app and related services, including shared groups, optional subscriptions and AI features when available. Contact us at noi@myappdesk.dev about this policy or your data.
Data we process
- Account and profile: email address, authentication information, name, optional profile photo and profile details you choose to add. Sign in with Apple may provide an Apple relay address instead of your personal email address. Our authentication provider handles passwords.
- Shared group content: group and member names, invitations, notes, tasks, shopping lists, expenses and settlements, events, places, polls, activity, documents, photos and receipts you or other members add. Financial entries may include names, amounts and who paid or owes money.
- Optional device data: your location when you choose to use a location feature; camera or photo library content when you select it; and a push token if you permit notifications. Saved places or expenses may contain coordinates. When you enable live location sharing, noi sends location updates to your group for the sharing session, including in the background where permitted. You can stop sharing in the app or revoke location permission in device settings.
- Subscription data: your account identifier, covered groups, product, subscription status and renewal dates. The app store that processes your purchase handles payment information; we do not receive your full card details.
- Technical data: information needed for sign-in, security, request delivery and fault diagnosis, such as IP address and service logs. The website hosting this policy has its own privacy notice.
- AI requests, when you choose an AI feature: the text you enter, instructions and relevant context needed to answer your request, OCR text extracted from a receipt or other image, audio transcription, and the generated result. The app may also record credit usage and request diagnostics. It should send only information needed for the requested task.
Why we use data
We use account and group data to provide the service you request, sync content between group members, calculate shared balances, send account emails and deliver notifications you enable. We use subscription data to grant or remove benefits for covered groups and apply limits. We process necessary technical records to keep the service secure and reliable. When you choose an AI feature, we process the request to generate the result, meter credits and prevent abuse. We rely on providing the service you request, our legitimate interests in security and operation, legal obligations, or your device permission where applicable. You can withdraw device permissions in your device settings; that does not affect processing already completed.
AI, photos and audio
AI features are optional. When supported by your device and the feature, noi is designed to perform text recognition and speech transcription on your device and send the resulting text, rather than the original photo or recording, to the AI service. If a feature needs to send the photo or audio itself to a remote provider, the app will explain that before transfer and ask you to continue. You can cancel instead.
AI requests may be handled by OpenAI (Privacy Policy) or Google Gemini (Privacy Policy). The selected provider receives the request data needed to generate a response and processes it under its service terms and privacy notice. The provider may process data in another country and may keep request or security logs under its applicable terms. We do not use your AI request content to train our own general-purpose AI models. We do not store an unsaved AI request or result as group content. We may keep the generated proposal in a private request cache for 24 hours so a retry does not charge credits again; scheduled cleanup removes it shortly after expiry. If you confirm and save a result, the saved content is stored and shared like other content in that group. Service logs and backups may retain limited technical records for security, reliability or legal obligations. Before sending, review this policy and both provider notices to understand applicable processing and retention.
Who can see your content
Members of a group can see content shared with that group, including financial records and activity attributed to members. Profile details are shared according to the choices you make when joining or editing a group. Someone with a valid invitation can join and then see group content. When you choose an AI feature, the relevant request data is also sent to the AI provider described above. Share invitations only with people you trust; avoid uploading content you do not want the group or a service provider to see.
Service providers
We use Supabase for authentication, database and file storage; Resend to deliver account emails; RevenueCat for subscription status; and Apple for App Store purchases, push delivery, Sign in with Apple and Apple Maps features. Using Maps search or directions may send a place query or location to Apple under Apple's privacy policy. On Android, Google handles Google Play purchases, Google sign-in, Firebase Cloud Messaging, Google Maps and device speech recognition where used. Google Maps and ML Kit collect device or installation identifiers, usage events and performance diagnostics to operate and improve their services; Maps also receives IP addresses and map interactions. Speech recognition prefers on-device processing, but the system recognizer may use a remote service on devices without on-device recognition. See Google’s privacy policy. AI features may use OpenAI or Google Gemini. Their privacy notices are linked in this policy. Providers may process data in other countries under applicable safeguards. We do not sell group content or personal data.
Retention and deletion
We keep account and group data while needed to operate the account and groups, and remove it when no longer needed, subject to backups, security records and legal obligations. We do not keep original photos or recordings on noi servers for AI processing by default. If you save an AI result, it becomes group content and follows the retention rules for that content. The AI provider's retention of request data is governed by the provider terms and the details shown in the feature flow. Removing Premium does not delete existing group content. If you leave a group or delete your account, records needed by remaining members, such as expenses and settlements, may need to remain so their shared history and balances stay understandable. Contact noi@myappdesk.dev to request access, correction, export or deletion; we will explain any data that cannot immediately be removed and why.
Your rights and security
You can request account deletion without signing in through the noi account-deletion form. Use the email associated with your noi account. MyAppDesk verifies account ownership before processing the request and confirms the outcome by email. You can also request deletion of specific data without deleting your account; describe that request in the message. The deletion page explains how account data and shared records are handled.
Depending on where you live, you may have rights to access, correct, erase, export or restrict processing of your data, or to object to certain uses. You may complain to your local data protection authority; in Spain, that is the AEPD. We use access controls and encrypted connections, but no online service can guarantee absolute security.
noi is not directed at children who cannot lawfully consent to this kind of service where they live. If you believe a child has used noi without required permission, contact us.
We may update this policy as the app changes. Material changes will be communicated through the app or another appropriate channel; the date above shows the current version.