Privacy Policy
Line Notes is a sole proprietorship operated by Nick Griffith ("Line Notes," "we," "our," or "us"), and is the data controller for the personal information described in this policy. We operate the Line Notes stage management platform at linenotes.io. This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data.
By creating an account or using the Line Notes service, you agree to the practices described in this policy. If you do not agree, please discontinue use of the service.
1. Information We Collect
Account Information
When you register for a Line Notes account, we collect:
- Name and email address
- Password (stored as a secure hash via Firebase Authentication, and we never store plaintext passwords)
- Profile information you choose to provide
Production and Usage Data
As you use Line Notes, we store the data you create:
- Line notes: the notes you log during run sessions, including text content, note type, associated cast member, and timestamp
- Cast lists: character-to-actor assignments and related metadata for your productions
- Run session records: session start and end times, page counts, and session-linked notes
- PDF scripts: script files you upload to the platform, stored in Firebase Storage
- Script zones: the annotations and zone boundaries you draw on script pages
- Production settings: production names, join codes, member lists, and role assignments
Billing Information
If you subscribe to a paid plan, payment is processed by Stripe. We never receive or store your full card number, CVC, or expiry date — those go directly to Stripe and are never held on our systems. What we store is limited to:
- A Stripe customer identifier and subscription identifier
- Your plan, subscription status, trial end date, and renewal date
Stripe collects your card details, billing address, and email directly, as an independent controller for its own fraud-prevention and legal obligations. Its practices are described in the Stripe Privacy Policy.
Usage and Technical Data
We automatically collect certain technical information when you use the service:
- Browser type, operating system, and device type
- IP address and approximate geographic location
- Pages visited, features used, and time spent within the app
- Error logs and crash reports
- Authentication events (sign-in timestamps, method used)
Cookies and Local Storage
We use browser cookies and local storage for two distinct purposes:
- Strictly necessary: Firebase Authentication sets a session cookie to keep you signed in, and we use local storage to remember your preferences. These are required for the service to work and are set without asking, because without them there is no service.
- Analytics: if — and only if — you accept when asked, Google Analytics for Firebase sets identifiers that let us count visits and see which features are used. Decline, or simply ignore the request, and these are never set: we do not load the analytics script at all until you have accepted. You can change your mind at any time by clearing this site's data in your browser, which returns you to the unanswered state.
We do not use cookies for cross-site advertising, and we do not allow any third party to use them to build a profile of you across other websites.
2. How We Use Your Information
We use the information we collect to:
- Deliver the service: store and sync your productions, notes, sessions, and scripts across devices in real time
- Authenticate you: verify your identity and enforce role-based access within productions
- Send transactional communications: confirmations, password resets, and service-critical notifications
- Improve the product: analyze aggregate usage patterns to prioritize features and fix bugs
- Ensure security: detect and prevent unauthorized access, abuse, or fraudulent activity
- Comply with legal obligations: respond to lawful requests from government authorities when required
We do not sell your personal data. We do not use your line notes content, scripts, or production data to train machine learning models.
3. Third-Party Services
Line Notes is built on Google Firebase, a platform provided by Google LLC. The following Firebase services process your data on our behalf:
- Firebase Authentication: manages user accounts and sign-in credentials
- Cloud Firestore: stores structured data including notes, cast lists, sessions, and production settings
- Firebase Storage: stores uploaded PDF script files
- Firebase Hosting: serves the Line Notes web application
- Cloud Functions for Firebase: executes server-side logic such as production join flows
Google's privacy practices are described at policies.google.com/privacy. Data processed through Firebase is subject to Google's data processing terms. Firebase stores data in Google Cloud infrastructure; your data is stored in the United States unless we configure otherwise.
We also rely on the following services outside Firebase:
- Stripe (Stripe, Inc.): processes subscription payments. Receives your card details, billing address, and email directly. See the Stripe Privacy Policy.
- Google Analytics for Firebase (Google LLC): measures how the marketing site and the application are used, so we know which features earn their place. Loaded only after you accept analytics cookies, and never before. See Google's privacy policy.
- Formspree (Formspree, Inc.): delivers messages sent through our contact form. Receives the name, email address, organization, and message you type into that form. See the Formspree Privacy Policy.
- Cloudflare (Cloudflare, Inc.): provides DNS for linenotes.io and forwards mail sent to our published
@linenotes.ioaddresses to our own inbox. Mail you send us passes through Cloudflare in transit. See the Cloudflare Privacy Policy.
We do not share your production content — your notes, scripts, cast lists, or session records — with any of these providers. We do not sell your personal data to anyone, and we do not use it for cross-context behavioural advertising.
4. Data Retention
We retain your data for as long as your account is active and for a reasonable period thereafter to allow for account recovery or dispute resolution.
- Account data: retained until you delete your account
- Production data (notes, sessions, cast, scripts): retained as long as the production exists in our system, or until deleted by a production owner or administrator
- Usage logs and analytics: retained in aggregate form for up to 24 months
- Backups: deleted data may persist in encrypted backups for up to 90 days
When you delete your account, we delete or anonymize your personal information within 30 days, subject to our backup retention schedule and any legal obligations to retain certain records.
5. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
Access
You may request a copy of the personal data we hold about you. Most of your data is accessible directly within the Line Notes application.
Correction
You may update your account information at any time through your account settings. If you need to correct data you cannot access directly, contact us and we will assist.
Deletion
You may request deletion of your account and associated personal data at any time. To do so, contact us at privacy@linenotes.io. Note that production data (notes, scripts) owned by a production may be subject to that production's owner's retention choices.
Portability
You may request an export of your personal data in a structured, machine-readable format. Contact us at privacy@linenotes.io to initiate a data export.
Objection and Restriction
You may object to certain processing activities or request that we restrict how we process your data, subject to applicable law.
Opting Out of Non-Essential Communications
You may unsubscribe from marketing emails at any time using the unsubscribe link in any such email. We will still send you transactional messages necessary to operate your account.
6. GDPR: European Users
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following applies:
- Legal basis for processing: We process your data on the basis of contract performance (to deliver the service you signed up for), legitimate interests (to improve and secure the service), and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time.
- Data transfers: Your data is processed in the United States via Google Firebase infrastructure. We rely on Google's Standard Contractual Clauses for transfers of personal data outside the EEA.
- Data Protection Authority: You have the right to lodge a complaint with your local supervisory authority if you believe we have handled your data unlawfully.
To exercise your rights under the GDPR, contact us at privacy@linenotes.io. We will respond within 30 days.
7. CCPA: California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights:
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to opt out of sale: We do not sell personal information. You do not need to opt out.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To submit a CCPA request, email privacy@linenotes.io with "CCPA Request" in the subject line.
8. Data Security
We take reasonable technical and organizational measures to protect your data from unauthorized access, loss, or disclosure. These measures include:
- Encryption in transit (HTTPS/TLS) for all data between your browser and our servers
- Encryption at rest for data stored in Firebase Storage and Firestore
- Role-based access controls enforced both in client code and in Firestore security rules
- Firebase Authentication for secure credential management
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at privacy@linenotes.io.
9. Children's Privacy
Line Notes is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. If you believe a child under 13 has provided us with personal information, contact us at privacy@linenotes.io.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice in the Line Notes application. The "Last updated" date at the top of this page reflects when the policy was last revised. Your continued use of Line Notes after changes take effect constitutes acceptance of the revised policy.