Privacy Policy
Easy Table Notes is made by Anatoly Eidelman (the "developer", "we"). This policy explains what the app and the website collect, why, where it is kept and how you can delete it. It is written to be read, not skimmed, and it describes what actually happens rather than everything that could.
1. The short version
- Your tables stay on your device unless you sign in. Signing in is optional.
- If you sign in, your tables are stored in Google Firebase (EU region) so you can open them in the app and at tablemaker.io. Only you, and people you deliberately share a link with, can read them.
- We never read your table contents for advertising, analytics or anything else. Analytics and crash reports contain no cell values, titles or text.
- We send marketing e-mail only if you ticked the box that asks for it. Every such e-mail has an unsubscribe link and you can switch it off in your account at any time.
- You can delete everything by e-mailing [email protected].
2. What we collect and why
| Data | When | Why | Where it lives |
|---|---|---|---|
| Your tables (titles, cells, colours, categories) | Always on the device; in the cloud only after you sign in | To store your work and keep it in sync between the app and the browser | Your device; Google Firebase Firestore, region europe-west (Belgium/Netherlands) |
| Invitations: the e-mail addresses you invite to a table, with their role; your name or e-mail on tables you share | When you share a table with people | To let exactly those people open the table, and to tell them who shared it | Firestore (EU), on the table's record |
| Presence: your name, a colour, and which cell you are on | While you have a synced table open and someone else can see it | To show people editing together where the others are | Firestore (EU); deleted when you close the table |
| Account: e-mail address, display name, profile photo, Google account ID | When you sign in with Google or an e-mail link | To know which tables are yours and to show you as signed in | Google Firebase Authentication and Firestore (EU) |
| Marketing consent record: yes/no, date, the wording you agreed to, where you agreed (app, website, account settings), language | When you tick or untick "Email me product updates" | To prove we had your permission before sending, as the law requires, and to stop the moment you withdraw it | Firestore (EU) |
| Usage analytics: screens opened, features used, app version, device model, country, an app-instance identifier | Android app only. Where the law requires a consent prompt (EU/EEA, UK, Switzerland), only if you consented in it; elsewhere from first launch | To see which features are used and which crash, so we know what to improve | Google Firebase Analytics |
| Crash reports: stack trace, device model, OS version, app version, installation identifier | Android app only, when the app crashes, and only if you consented in the prompt where one is required | To fix crashes | Google Firebase Crashlytics |
| Advertising data: advertising ID, approximate location from IP address, ad interactions | Android app only, while ads are shown (the free version). Handled by Google AdMob according to the choices you make in the consent prompt | To fund the free app | Google AdMob and, where you consented, its ad partners |
| Age group (child / teen / adult) | Android app, once | To show age-appropriate ads and to keep personalised ads away from children | Your device only. Your year of birth is not stored and is never sent anywhere |
The website tablemaker.io does not run analytics or advertising scripts. It uses Firebase Authentication and Firestore, which set the storage entries needed to keep you signed in and to keep your tables available offline in your browser.
3. What we do not do
- We do not sell personal data, and we do not share your tables with anyone unless you turn on link sharing for that table.
- Table contents are never included in analytics, crash reports or e-mails.
- We do not build advertising profiles ourselves. Ads in the app are served by Google AdMob under your consent choices; you can change them any time under Settings → Ad privacy options.
4. Sharing a table with people, and sharing links
You can invite people to a table by e-mail address. The addresses you type are stored on that table so the service knows who may open it; the people you invite see your name (or e-mail) as the person who shared it. While two or more people have a shared table open, each sees the others' name and the cell they are on; that "presence" record is deleted the moment you close the table. You can remove anyone, or change what they may do, at any time from the Share dialog.
When you turn on "Anyone with the link can view" (or "…can edit") for a table, anyone who has that link can open it in a browser or in the app without an invitation. Editors are given an anonymous identity by Firebase so edits can be saved. You can turn sharing off at any time from the same switch; the link then stops working immediately. Please treat a sharing link like a key: whoever you give it to can pass it on.
5. Marketing e-mail
We send product updates and tips by e-mail only if you actively ticked the box "Email me product updates" when signing in, or turned the same switch on in your account settings. The box is never pre-ticked. Each e-mail names the sender and carries an unsubscribe link; you can also turn it off in the account dialog at tablemaker.io or in the app's Settings, or by replying "unsubscribe". Withdrawing consent takes effect immediately and does not affect your account or your tables. This works the way the EU GDPR (article 7) and the Israeli Communications Law (section 30A) require.
Transactional e-mail, such as a sign-in link you requested, is not marketing and does not need this consent.
6. Legal bases (for people in the EU/EEA and UK)
- Storing and syncing your tables and your account: performance of the contract you enter by using the service (GDPR art. 6(1)(b)).
- Marketing e-mail: your consent (art. 6(1)(a)), withdrawable any time.
- Analytics and personalised advertising: your consent given in the app's consent prompt; where no prompt is required by law, our legitimate interest in understanding and funding the app (art. 6(1)(f)).
- Crash reports: our legitimate interest in keeping the app working.
7. Who processes the data
Google LLC and Google Ireland Ltd provide Firebase (Authentication, Firestore, Hosting, Analytics, Crashlytics) and AdMob. Firestore data for this service is stored in Google's europe-west multi-region. Google's own terms and safeguards (including the EU Standard Contractual Clauses for transfers) apply to that processing; see firebase.google.com/support/privacy and policies.google.com/privacy. We use no other processors.
8. How long we keep it
- Tables: until you delete them. A deleted table sits in the bin for 30 days and is then removed; "Delete forever" removes it at once.
- Account and consent record: until you ask us to delete the account.
- Analytics and crash data: retained by Firebase for the period set in the project (at most 14 months for analytics, 90 days for crash reports), then deleted automatically.
9. Your rights, and deleting your account
Wherever you live, you can ask us to see, correct, export or delete the personal data we hold about you, and you can withdraw any consent you gave. People in the EU/EEA, the UK and Israel also have the right to complain to their data-protection authority. To exercise any of these, e-mail [email protected]; we answer within 30 days. To delete your account and everything in it, send the request from the e-mail address of the account to [email protected] with the subject "Delete my account". We delete the account, its consent record and every table stored in the cloud within 30 days and confirm by e-mail; tables on your phone are unaffected until you uninstall the app. If you only want the cloud copies gone, Settings → Sign out in the app keeps everything on the phone, and "Delete forever" in the bin removes a single table from the cloud at once.
You can export any table yourself at any time as CSV, Excel, PDF or an image, from the app or from tablemaker.io.
10. Children
The app asks for an age group once and never shows personalised ads to children. We do not knowingly collect personal data from children under 13 (or the age of consent in your country); signing in and cloud sync are meant for adults. If you believe a child has created an account, e-mail us and we will delete it.
11. Security
All traffic between the app, the browser and Firebase is encrypted (TLS). Access to your tables is enforced by Firestore security rules: a signed-in user can only read and write their own tables, plus tables whose owner turned on link sharing. Nobody at Google or on our side needs your password: sign-in is handled by Google or by a one-time e-mail link.
12. Changes
If we change this policy in a way that matters, we will show a notice in the app or on the website and update the date at the top. Earlier versions are available on request.
13. Contact
Anatoly Eidelman · [email protected] · tablemaker.io