BeeGeeBox · legal
Privacy Policy
Last updated:
Effective date:
In one sentence: your notes live on your own device, they’re encrypted if you choose to sync them, and we can’t read them. The detail is below.
1. Who we are
This Privacy Policy explains how GeneZero Technology Limited (“we”, “us” or “our”) collects, uses, and looks after personal data when you use BeeGeeBox. We are a company incorporated in Hong Kong SAR and we follow the principles of Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) and, where applicable, the EU and UK General Data Protection Regulation (GDPR). Questions? Email [email protected].
2. The short version
- Your notes are stored on your device, in your private Data Vault.
- If you turn on cloud sync, note content is encrypted before it leaves your device, and we hold no keys to decrypt it.
- Unlike your note content, certain metadata (such as your tags and workspace names) is not end-to-end encrypted. It is stored securely on our servers to enable fast cross-device synchronization and in-app searching.
- We don’t sell your data. We don’t advertise to you. We don’t read your notes.
- You can export, back up, or delete your data at any time.
3. What we collect
Here’s every kind of data that can touch our systems:
- Account data — your email address, display name, and an internal user ID, used to sign you in and to keep your data belonging to you.
- Sync metadata — small technical records needed to sync your vault across devices, such as your tags, workspace names, and sync bookkeeping (internal identifiers and timestamps), plus encrypted copies of your actual note content. As explained in sections 2 and 5, this metadata is not end-to-end encrypted.
- Billing data — handled by our third-party payment processor (currently Stripe). We never see or store your payment card details.
- AI chat prompts — only if you use the optional AI chat feature. Your prompt goes directly to the AI provider you configured, using your own API key. We don’t route, log, or see your prompts.
- Usage analytics & diagnostic logs — a deliberately small set of event information today (for example, sign-in or account-deletion events). We plan to expand this over time, in particular to capture error and crash diagnostics, so that we can find and fix problems faster. Analytics never includes the content of your notes.
BeeGeeBox also includes an Anonymous mode you can use without signing in. In Anonymous mode, nothing you create is saved — changes are discarded when you leave it. A related Offline access mode lets you open an existing account on a device without a network connection; while in that mode, features that need online services are unavailable.
4. Why we collect it (Legal Basis)
We use this data for three purposes only:
- To run the service for you (Performance of Contract) — signing you in, syncing your data, and processing your subscription.
- To keep the app reliable and secure (Legitimate Interest) — preventing abuse and ensuring system stability.
- To improve the product (Legitimate Interest) — using only basic, non-personal analytics.
5. Your notes stay private
This is the core of how BeeGeeBox works. Your notes live in an industry-standard encrypted local database inside your Data Vault. The encryption keys are derived on your device from your master password, using strong key derivation functions. Those derived keys stay on your device — we never receive them, and we cannot decrypt your note content. When cloud sync is on, note content is encrypted before it leaves your device — so neither we, nor our cloud infrastructure provider, nor anyone else who happens to see the stored data can read your notes.
For full accuracy: so that you can sign in to an existing account on a new device without entering anything but your master password, we do store a non-reversible verification value derived from that password (used only to confirm it matches) together with a random per-account salt. Neither can be used to reconstruct your master password or to decrypt your notes.
Please note: to allow you to search and organize your vault across devices, metadata such as your tags and workspace names are not end-to-end encrypted and are stored securely on our servers.
6. Who we share data with (Sub-processors)
We only share data with essential service providers:
- Cloud infrastructure (currently Firebase/Google) — used for authentication, and for storing your encrypted, synced data and attachments.
- Payment processor (currently Stripe) — handles payment card processing and billing. We share only what’s needed to charge you.
- AI providers you choose — if you use AI chat, your prompt is sent directly to the provider you configured.
That’s the complete list. We don’t sell, rent, or trade personal data to anyone. We may update our sub-processors as our technical architecture evolves, provided they adhere to strict data protection standards.
7. International Data Transfers
Because our service providers (such as cloud and payment processors) operate globally, your data may be transferred to, and processed in, countries outside of Hong Kong or your home country. Where required by law, we rely on appropriate safeguards — such as standard contractual clauses — to protect your data.
8. How long we keep data & how to delete it
We keep your account data while your account exists. You can delete your account in the app at any time, which removes your account and the data we hold from our servers within 30 days. Like most services, we may keep a minimal administrative record (e.g., your email address, the language you used and account creation date) for legal, tax, and security purposes. That record never contains your notes. Your local Data Vault lives on your device and stays yours to keep, export, or delete.
9. Your rights
Depending on your location, you have the right to request access to, correction of, or deletion of your personal data, as well as the right to restrict processing or request data portability. You can make a request by emailing [email protected]. We’ll respond promptly, and we’ll never charge you to exercise these rights. If you’re in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
10. Security & Breach Notification
We protect your data with industry-standard encryption, secure storage for authentication tokens, and HTTPS encryption for all network traffic. In the unlikely event of a data breach that affects your personal data, we’ll notify you and the relevant authority as required by law, without undue delay.
11. Cookies & Tracking
The BeeGeeBox mobile and desktop applications don’t use cookies or cross-app tracking technologies. Our marketing website may use basic, strictly necessary cookies to function.
12. Children
BeeGeeBox isn’t directed at children, and we don’t knowingly collect personal data from anyone under 13 (or the minimum age of digital consent in your jurisdiction).
13. Changes to this Policy
If we change how we handle your data, we’ll update this page and the “last updated” date, and tell you in the app if the change materially affects your privacy.
14. Contact
Privacy questions or requests? Email [email protected].
15. Prevailing Language
This document is provided in both English and Chinese. In the event of any inconsistency or discrepancy between the English version and the Chinese version, the English version shall prevail.