Egg by Super Simple

Legal

Privacy Policy

This policy explains how Super Simple websites, apps, and related services, including Egg, handle personal information.

Effective September 13, 2026

1. Who we are

Super Simple is a suite of software products operated by Dialect Agency Inc. DBA Super Simple. Egg is a Super Simple product. In this policy, “Super Simple,” “we,” “us,” and “our” refer to that company. This policy applies to our websites, apps, waitlists, support channels, and related services. A product may provide an additional notice when its data practices differ from this general policy.

2. Information we collect

Information you provide

We collect your email address and name when you create an account, information you include in a support request, feedback you send us, and the credentials you choose for signing in, including passwords, two-factor secrets, and registered passkeys. Passwords are stored only as salted hashes and never in a readable form.

Your notes and files

Egg stores the notes, notebooks, tags, and attachments you create, import, or upload, along with the timestamps and revision markers needed to synchronize them across your devices. We treat this content as yours. We do not read it, mine it, profile it, or use it to train any model.

Encryption

Egg uses HTTPS for data in transit and encrypted storage for data at rest. Account recovery is handled through the sign-in flow. Support will never ask for your password or recovery codes.

Import

Import runs entirely in your browser. Files you select from Evernote, Google Keep, Simplenote, or a folder of documents are parsed on your device and then written through the same interface the editor uses, which is what allows imports into an encrypted account at all. We receive the resulting notes and attachments, not the original export files.

Purchases

Payment providers process purchases and subscriptions. We may receive purchase status, subscription status, and transaction identifiers, but we do not receive your complete payment-card number from those providers.

Website and technical information

When you use our websites or services, we and our infrastructure providers receive IP address, device and browser type, operating system, timestamps, request paths, diagnostic information, and security and audit logs recording events such as sign-in, sign-out, and changes to your account’s security settings. We keep these to operate and defend the service.

The authenticated Egg app carries no advertising trackers. Optional product usage measurement is described below. If you allow it, the public sales page uses Google Analytics 4 to measure page visits, sign-up and plan-selection clicks, log-in clicks, FAQ opens, and whether the pricing section and the end of the page were reached. Those events contain only fixed labels such as the button location or plan name. They never contain account identifiers, note text, search terms, file names, or anything else from your account. Google advertising signals and Google ad personalization are disabled.

If you allowed analytics on the public sales page and then create an account, our server reports that one sign-up happened to Google Analytics. We do this from the server precisely so that the notes app itself stays free of Google Analytics code. The report contains the analytics and advertising identifiers Google had already issued to your browser on the public site, any campaign labels from the link you followed, and fixed labels such as whether you chose to start fresh or to import a library. It does not contain your name, your email address, your account identifier, or anything from inside your account, and it is marked as non-personalized. If you declined analytics, or a Global Privacy Control or Do Not Track signal was present, no identifiers are carried across and no sign-up is reported.

With the same explicit permission, the public sales page also uses the Reddit Pixel to measure page visits and sign-up or plan-selection clicks (reported as Lead events). Reddit may receive browser technical information, the public page URL, and a cookie identifier for advertising attribution. The pixel never loads inside the notes app. When you follow a sign-up link, we carry the Reddit ad click ID and/or pixel cookie identifier with your consent timestamp. The handoff expires after one hour. Once a new account exists, our server sends Reddit one SignUp event through its Conversions API, with the account-creation time, those Reddit identifiers, a fixed sign-up page URL, and an opaque conversion ID to prevent duplicates. We do not send your name, email, internal account ID, note contents, search terms, attachments, or encryption secrets to Reddit. The server report does not include your IP address or user agent. Declining analytics, Global Privacy Control, or Do Not Track prevents this handoff and reporting. We remove the carried identifiers from the sign-up page URL after reading them.

Optional app usage measurement

Share usage data is off by default in Settings > Privacy & diagnostics on each device or browser. If you enable it, Egg sends app activity, feedback and feature-use counts, search success or no-result counts, note recovery, save and sync outcomes, import/export outcomes, and appearance-setting changes through our server to TelemetryDeck. Frequent actions are combined into summaries about every five minutes and when the app goes into the background; individual action times are not included. Summaries can include a library-size range (0, 1–10, 11–50, or 51+ notes), broad startup and sync duration ranges, app version, and platform (web, iOS, or macOS). Local flags help measure first and repeat feature use and return visits after you enable sharing; those flags contain no note content. A random installation identifier is hashed before forwarding; it is not your account identifier. These events contain no note text, titles, tags, search terms, email address, account ID, or report text. TelemetryDeck receives our server's IP address, not yours. Turning sharing off stops future events and clears unsent counts and removes the local installation identifier and usage-history flags. There is no analytics offline queue, session replay, screenshot capture, or cross-device identity. Global Privacy Control and Do Not Track also disable browser usage sharing.

Feedback you choose to send

Bug reports, feature requests, and other feedback are stored in Sentry's user feedback inbox. Submitting the form sends the message you write, your account email for follow-up, its category, and app platform. Your notes, attachments, and screenshots are not automatically included. This voluntary feedback is separate from automatic crash reporting and works whether or not usage sharing is enabled.

Crash reporting and service monitoring

Our websites, apps, and servers use Sentry, an error- and performance-monitoring service operated by Functional Software, Inc., to detect crashes, diagnose errors, and measure the health and performance of the service. When a problem occurs, and during normal use where performance monitoring is enabled, Sentry may receive diagnostic information such as error messages and stack traces; the page, screen, or request involved; recent in-app actions, console output, and network request paths leading up to a problem; device, browser, and operating-system details; app version and release identifiers; IP address; session and installation identifiers; and performance timings. Where session replay is enabled, Sentry may also receive a reconstruction of the interface around the time of an error, with text inputs and media masked by default.

We configure this reporting to minimize personal information. We do not attach your name, email address, or account identifier to crash reports, and note content is protected by encrypted storage and HTTPS, so it cannot appear in them. Browser error reports are currently relayed through our own servers rather than sent directly to Sentry, so Sentry does not receive your IP address from the web app. Crash reporting is diagnostics, not advertising, and it is never used for marketing or profiling.

3. Cookies and similar technologies

We use cookies and browser storage to make the product work. A session cookie keeps you signed in. Local storage on your device holds the offline copy of your notes, your search index, and your preferences, which is what lets Egg open and stay usable without a connection.

On the public sales page, Google Analytics and the Reddit Pixel are off until you choose “Allow analytics.” If you allow it, Google Analytics and Reddit may set first-party measurement cookies and receive technical information such as your IP address, browser and device type, approximate location, referring page, page path, and the limited interaction events described above. Your choice is stored in your browser on the public-site domain. A Global Privacy Control or Do Not Track signal keeps analytics off without showing the choice prompt. Neither Google Analytics nor the Reddit Pixel loads in the authenticated notes app. If you allowed analytics and then follow a link to create an account, the identifiers in those cookies are added to the link so that the sign-up described above can be reported from our server rather than by a script running alongside your notes.

Clearing site data in your browser removes the local copy. Anything already synchronized to your account remains in your account. We honor legally required opt-out signals, including a recognized Global Privacy Control signal, when one applies to our practices.

4. How we use information

  • Provide, maintain, synchronize, and improve the product and the features you request.
  • Authenticate you and protect your account, including two-factor and passkey verification.
  • Respond to support requests and send service messages you asked for or that we are required to send.
  • Understand service performance, diagnose errors, and keep the service available.
  • Protect users, products, and services from fraud, abuse, and security threats.
  • Comply with law, enforce our terms, and establish or defend legal claims.

Where European or UK data protection law applies, our legal bases may include performance of a contract, legitimate interests in operating and securing our services, consent, and compliance with legal obligations. You may withdraw consent where processing depends on it.

5. Features you switch on

Some features send information somewhere it would not otherwise go. Each one is off until you choose it.

Transcription

Audio is transcribed only when you ask for a transcript of a specific file. That file is processed for that purpose and the resulting text is stored with your note.

Assistant connections

You can connect an AI assistant to your account through our connector. Connecting requires you to approve the request on a screen that states plainly what the connection can and cannot do, and you can revoke it at any time from your settings. A connected assistant acts within your account only. The connector has no ability to reach any outside network on your behalf.

Embedded media

A note can embed media from a small allowlist of players. Loading one of those embeds contacts that provider directly from your browser, and that provider’s own privacy practices then apply to that request.

6. How we disclose information

We may disclose information:

  • To vendors that help us host, store, secure, support, communicate about, and measure the public website, including our hosting provider, our object storage provider, our transactional email provider, our error- and performance-monitoring and feedback provider (Sentry), TelemetryDeck when you enable usage sharing, and Google Analytics and Reddit when you allow website measurement, subject to contractual restrictions where required.
  • To payment providers when needed for a purchase or subscription.
  • When you direct us to share, export, synchronize, or connect information.
  • When reasonably necessary to comply with law, protect rights or safety, or investigate misuse.
  • As part of a merger, financing, acquisition, reorganization, or sale of all or part of our business.

We do not sell personal information and we do not share it for cross-context behavioral advertising. If that ever changes, we will update this policy and provide any legally required choices before doing so.

7. Retention and deletion

Notes you delete go to trash and are recoverable by you for 30 days, after which they are purged. Deleting your account removes your notes, notebooks, tags, and attachments from the live service; backups and logs age out on their own schedule. We keep other personal information only as long as reasonably necessary for the purposes described here, including providing the product, meeting legal and accounting obligations, resolving disputes, and protecting the service.

You can export everything you have at any time as a portable archive, and you do not need our help or permission to do it.

8. Security

Notes are encrypted in transit and at rest. Attachment bytes move directly between your browser and our storage provider using short-lived signed links rather than passing through our API. Accounts support two-factor authentication and passkeys.

We use reasonable administrative, technical, and organizational safeguards appropriate to the information we handle. No storage or transmission method is completely secure.

9. International processing

We and our vendors may process information in the United States and other countries. Where required, we use appropriate safeguards for international transfers. Local privacy protections may differ from those where you live.

10. Your privacy choices and rights

Depending on where you live, you may have rights to access, know about, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a decision. You may also opt out of any marketing email by using the unsubscribe link in the message. We will not discriminate against you for exercising a privacy right.

California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service. We do not sell personal information or share it for cross-context behavioral advertising. Authorized agents may submit requests where permitted by law. We may need to verify a request before acting on it.

The fastest route to access and deletion is the product itself. Export gives you a complete copy of your content in one click, and account deletion in settings removes it. To make a formal request, or to ask us something export and deletion do not cover, email support@eggnotes.app.

11. Children

Egg is a general-audience product. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it as appropriate.

12. Changes

We may update this policy when our products, practices, or legal obligations change. We will post the revised policy here, update the effective date, and provide additional notice when required.

13. Contact

Privacy questions and requests: support@eggnotes.app

Dialect Agency Inc. DBA Super Simple
350 Northern Blvd, STE 324-1171
Albany, NY 12204-1000
United States