Privacy Policy
Effective September 3, 2026
This Privacy Policy explains how CPW Creations (“we,” “us,” or “our”) handles information when you use Sweet Notes, including the website and Android companion app (the “Service”). Sweet Notes lets an account holder schedule messages that are sent through a paired Android phone and its mobile carrier.
Information we collect
- Account information: name, email address, encrypted password credentials, time zone, settings, and policy-acceptance dates.
- Recipient and message information: contact names and phone numbers you choose to add, message text, schedules, rotation lists, delivery status, and attached images or GIFs.
- Device and reliability information: paired-device name, app version, last sync time, sending mode, alarm and background-battery readiness, delivery identifiers, and error details.
- Security information: truncated or one-way hashes derived from IP addresses, sign-in and account activity, password-reset records, and revocable device tokens.
- Subscription information: plan, subscription status, trial and renewal dates, and identifiers that connect your Sweet Notes account to our payment processor. Sweet Notes does not receive or store your complete card or bank-account number.
The Android app requests contact access only so you can select contacts to import. Contacts you do not select are not uploaded. It requests SMS access only when you choose automatic sending. Messages are then submitted through your phone and mobile plan.
How we use information
We use information to provide scheduling and rotation features, sync your paired phone, prevent duplicate sends, apply quiet hours, show delivery history, secure accounts, recover passwords, respond to support requests, maintain backups, and improve reliability. Optional anonymous product analytics and product emails are off unless you enable them in Settings.
How information is shared
We do not sell personal information. We share information only as needed with infrastructure, email, and payment providers that help operate the Service, when you direct the Service to send a message, to comply with law or protect rights and safety, or as part of a business transfer subject to appropriate safeguards. Stripe processes subscription checkout, payment details, invoices, and billing support under its own privacy terms. Your mobile carrier and the recipient’s carrier process messages sent from your phone under their own terms.
Recipient information
Account holders decide which people to add and message. If you enter another person’s information, you represent that you have a lawful reason to use it and will respect that person’s preferences. Sweet Notes is designed for thoughtful person-to-person messages, not unsolicited marketing, purchased lists, harassment, or emergency communications.
Storage, links, and retention
Connections use HTTPS. Passwords, pairing tokens, reset tokens, and delivery-claim tokens are stored as one-way hashes or industry-standard password hashes. Account records are separated by an internal customer identifier, and authenticated queries are restricted to that account.
Images and GIFs used in automatic messages are shared through signed links. You choose a link-retention period in Settings. A person who receives or forwards a valid link can view the attachment until it expires or the underlying file is removed. Operational logs and backups may remain for a limited period after deletion when required for security, recovery, or legal obligations.
Your controls
You can edit or remove contacts, messages, schedules, and rotations; pause sending; choose quiet hours; disable optional analytics and product email; revoke a paired phone; manage your subscription and payment method; download an account-scoped copy of your data; and permanently delete your account from Settings. You may also ask us to help with access, correction, export, or deletion by emailing support@cpwcreations.com.
Account deletion
Deleting an account first cancels any connected Sweet Notes subscription, then removes its contacts, schedules, rotations, delivery records, devices, reset tokens, and stored media from the active Service. De-identified security records and time-limited encrypted backups may persist until their normal expiration. Stripe and CPW Creations may retain transaction, invoice, tax, refund, or dispute records when required for legal, accounting, fraud-prevention, or payment-network obligations. Disconnect or uninstall the Android app if you no longer want it to retain local paired-account data.
Children
Sweet Notes is not directed to children under 13, and we do not knowingly collect personal information from them. Contact us if you believe a child has created an account.
Changes and contact
We may update this Policy as the Service changes. Material changes will be posted here with a new effective date and, when appropriate, communicated in the Service. Questions may be sent to support@cpwcreations.com.