MyMissingNote
Home About Get started FAQ Contact
Join the beta
Home About Get started FAQ Contact Join the beta

Privacy policy.

We handle your data with the same care we ask you to handle everyone else's.

Last updated: 12 May 2026

1. Who we are

MyMissingNote ("we", "us", "our") operates the MyMissingNote mobile application and website at mymissingnote.com. We are the data controller for the personal data described in this policy. To contact us about privacy matters, email contact@mymissingnote.com.

2. What data we collect

Account data

When you create an account, we collect your email address and a password (stored as a secure hash). Your email is used to identify your account, send transactional messages, and — if you activate it — to send Proof of Life check-in reminders. We never use it for unrelated marketing without your explicit consent.

Note content

Notes you write — including their titles and body text — are end-to-end encrypted on your device before being transmitted to our servers. We store only the encrypted ciphertext. We cannot read, access, or share the contents of your notes. The encryption key is derived from your password and never leaves your device in plaintext.

Recipients and trusted contacts

When you designate a recipient (someone who will receive a note disclosure), we store their email address and, optionally, their phone number and name. When you invite a registered MyMissingNote user as a trusted contact, we store their email address and the relationship record between your accounts. This data is used solely to deliver note disclosures and to manage vault access.

Proof of Life (POL) configuration

We store your POL settings: the check-in frequency you configure, the timestamps of your last check-in, and the current phase of your POL schedule. This data is used to operate the dead-man switch mechanism that is the core function of the service.

Device and notification data

If you enable push notifications, we store a device push token issued by Apple (APNs) or Google (FCM). This token is used only to send you check-in reminders and account alerts. No note content is ever included in a push notification.

Crash and error data

The app uses Sentry for crash reporting. When the app crashes or encounters an error, Sentry collects a stack trace, your device model and OS version, the app version, and an anonymised user identifier. No note content is included in crash reports.

Website data

When you use our website, our hosting infrastructure (AWS CloudFront) processes standard request logs including IP addresses and browser information. We do not use this data for profiling or tracking. If you join our mailing list or submit the contact form, we collect your name and email address for that specific purpose.

3. End-to-end encryption

Note content is encrypted client-side using a key derived from your password via PBKDF2. This means:

  • We cannot read your notes under any circumstances.
  • If you forget your password, we cannot recover your note content.
  • Law enforcement requests for note content cannot be fulfilled — we do not hold the plaintext.
  • Note content cannot be included in a data export from our systems.

Account metadata (email address, POL state, contact list, timestamps) is not end-to-end encrypted and is accessible to us as described in this policy.

4. How we use your data

  • Account data — to authenticate you and operate your account.
  • Encrypted note data — to store and deliver your notes. We cannot access the content.
  • Recipient data — to deliver note disclosures when your POL escalates.
  • Trusted contact data — to manage vault access between accounts.
  • POL configuration — to operate the check-in and disclosure schedule.
  • Push tokens — to send check-in reminders and account alerts.
  • Crash data — to identify and fix bugs in the app.
  • Website data — for security monitoring and responding to enquiries.

5. Legal basis for processing (GDPR)

  • Contract performance (Art. 6(1)(b)) — processing your account data, notes, and contacts is necessary to provide the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — crash reporting and security logging are necessary for us to maintain a secure, working service.
  • Consent (Art. 6(1)(a)) — push notifications and mailing list communications require your explicit consent, which you can withdraw at any time.

6. Who we share your data with

We do not sell your data. We share it only with the following sub-processors, each bound by a data processing agreement:

  • Amazon Web Services (AWS) — cloud infrastructure for data storage, authentication (Cognito), email delivery (SES), and notifications (SNS). Backend data is stored in the EU (Frankfurt, eu-central-1). AWS processes data under a GDPR-compliant DPA.
  • Sentry — crash reporting. Sentry is a US-based company. Transfers are covered by the EU–US Data Privacy Framework and standard contractual clauses.
  • Apple / Google — push notification delivery via APNs and Firebase Cloud Messaging. No note content is ever included.
  • EmailOctopus — mailing list management for website subscribers. UK-based, covered by the EU adequacy decision for the UK.

We may also disclose data where required by law, court order, or to protect the safety of users — but because note content is end-to-end encrypted, we cannot produce it in response to any such request.

7. International data transfers

Our primary data storage is in the EU (Frankfurt). Crash data processed by Sentry is transferred to the US under the EU–US Data Privacy Framework and standard contractual clauses (SCCs). We do not transfer data to countries without an adequate level of protection unless appropriate safeguards are in place.

8. How long we keep your data

  • Account and app data — retained for as long as your account is active. When you delete your account, your data is marked as deleted and permanently removed from our systems within 90 days.
  • Deleted notes and contacts — when you delete a note or contact within the app, it is marked as deleted and excluded from all app functionality immediately. Physical removal occurs within 90 days.
  • Crash reports — retained in Sentry for 90 days, then automatically deleted.
  • Push tokens — deleted when you disable notifications or delete your account.
  • Website logs — retained for up to 30 days.
  • Mailing list — until you unsubscribe.

9. Your rights

Under GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data. You can delete your account directly in the app, or email us. Note: we cannot recover or delete encrypted note content because we do not hold the decryption key.
  • Restriction — ask us to limit how we process your data.
  • Portability — receive your account metadata in a structured, machine-readable format. Note content cannot be exported from our servers because it is stored only in encrypted form.
  • Object — object to processing based on legitimate interests.
  • Withdraw consent — disable push notifications in your device settings, or unsubscribe from emails using the link in any message we send.

To exercise any of these rights, email contact@mymissingnote.com. We will respond within 30 days.

10. Cookies and local storage

The website does not use tracking cookies or analytics. We store your colour theme preference in your browser's local storage — this never leaves your device. The app uses secure on-device storage (not cookies) for your authentication session and encrypted key material.

11. Supervisory authority

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Dutch data protection authority:

Autoriteit Persoonsgegevens (AP)
autoriteitpersoonsgegevens.nl

12. Changes to this policy

We may update this policy as the product evolves. For material changes, we will notify you by email or via an in-app notice before they take effect. The date at the top of this page always reflects the latest version.

MyMissingNote

Leave nothing unsaid.

Product

  • About
  • FAQ
  • Join the waitlist

Company

  • Contact
  • Privacy policy
  • Terms of service

Community

  • WhatsApp channel

© 2026 MyMissingNote. All rights reserved.  ·  v0.5.0