Revisión de seguridad
Premios y Certificaciones
Sobre la app
GoodNotes is assessed as a low-risk, highly essential productivity application for students and young adults aged 10-18, earning a high safety rating of 4 out of 5. It is the premier digital note-taking application designed specifically for iOS, transforming the iPad into an indispensable tool for academic success. For parents and educators, GoodNotes offers a powerful blend of functional utility and robust safety controls, making it a trustworthy platform for their children’s educational journey. Its core function is to empower users to create, organize, and manage handwritten or typed notes, documents, and study materials in a paperless, searchable digital format. I. Data Privacy, Tracking, and GDPR Compliance: Understanding the Tracking Present Status The app is flagged with a Tracking present status in its data policies, which necessitates a transparent review of its practices.
It is important to understand that in the context of GoodNotes, Tracking present does not imply the sharing of sensitive personal data for advertising or sales. Instead, it refers to the collection of anonymized usage data and limited, essential personal information required for account function and service improvement, all handled under strict legal frameworks. * No Selling or Renting of Data: GoodNotes maintains a core privacy principle: We never sell or rent your data or notebook content to third parties. This commitment eliminates the primary privacy concern for many parents, as the child's academic work and personal notes are not monetized or misused for targeted marketing. * Notebook Content Privacy: Critically, GoodNotes explicitly states, We don't access or collect data from your notebooks or documents without your permission. The user’s notes, documents, and any highly personal information contained within them remain private. Any data used for AI features (such as handwriting recognition, spellcheck, and word complete) that are based on their proprietary Machine Learning (ML) model runs entirely on the device, meaning the content is never sent to Goodnotes’ servers or third parties for this processing. * Anonymous Statistical Data Collection: The limited data that is collected is largely anonymous statistical data, such as crash frequency, feature usage, and technical performance metrics, which is used solely to enhance and stabilize the application (to improve our services and meet legal obligations). This data is anonymized using unique identifiers that are linked to user accounts but do not contain personally identifiable information (PII).
This is a standard and necessary practice for app maintenance and is fully compliant with modern data protection standards. * Collection of Personal Data: GoodNotes collects basic personal data (name, email, country) when a user registers for an account. If a user chooses to use the cloud sync feature, their name, account ID, email address, and usage metrics (like the time a note was accessed) are disclosed to manage the sync process, but the content itself remains under the privacy rules stated above. * Third-Party Data Sharing: Data may be shared with specific, identified Service Providers (agents, contractors, or vendors) for essential functions like customer support, cloud infrastructure (AWS), analytics (Google Analytics, Data Dog), and secure payment processing. GoodNotes adheres to the highest standards of data protection, implementing a Data Processing Agreement (DPA) with its processors to ensure they comply with the stringent requirements of the EU General Data Protection Regulation (GDPR), UK GDPR, and the California Consumer Privacy Act (CCPA). All data sharing is subject to these legal frameworks. * AI Feature Consent and Retention: For advanced features like Ask Goodnotes (which leverages an external Large Language Model via Amazon Bedrock), Goodnotes takes extra precautions. Users are opted-out by default, and data is only collected if the user provides explicit consent to share their conversation history. Even when consent is given, this conversation history is only retained for a maximum of 30 days.
This level of granular control and limited retention demonstrates a strong commitment to user privacy in the rapidly evolving area of in-app AI.II. Academic Features and On-Device Security GoodNotes is more than a low-risk app; it is a powerful academic tool whose features enhance a student’s ability to learn and organize complex information efficiently. * Digital Organization: The app allows students to import PDFs, annotate them, and create hyperlinked notebooks, effectively digitizing their entire school workload. The powerful search function makes all handwriting, typed text, and imported PDF text searchable, drastically reducing study time and improving information retrieval. This feature is particularly beneficial for students in the 10-18 age range who are transitioning to more complex, volume-heavy academic content. * Robust Cloud Backup and Data Integrity: GoodNotes offers a highly reliable cloud sync system via Apple’s CloudKit, ensuring that all notes are automatically and securely backed up to the user's iCloud, and can also be manually backed up to other services like Dropbox, Google Drive, or OneDrive. All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or greater, safeguarding the data from unauthorized access on the servers. Furthermore, the robust backup system ensures that even if a note is accidentally deleted, it can be recovered from the Trash Bin (which the app does not automatically empty), providing an extra layer of peace of mind for parents regarding their child's schoolwork.
The use of Apple's CloudKit technology is also highlighted for its superior stability and security control over the data sync process. * Security for Educational Institutions (Goodnotes Classroom): For school-wide deployments, the Goodnotes Classroom system adheres to even stricter data controller/processor standards. The educational Institution is the data controller, responsible for gaining parental consent, while Goodnotes acts as the data processor under a Data Processing Agreement (DPA). This arrangement guarantees that the processing of student data complies with the strictest standards of the GDPR, including the use of EU Standard Contractual Clauses for any data transferred outside of the UK or EEA, thereby offering maximum security and accountability for minors' data. This is a critical assurance for schools and parents concerned about enterprise-level student data protection.III. Summary of Low-Risk Profile for Parents GoodNotes’ high safety rating of 4/5 for the 10-18 age group is solidified by its transparency and its intentional design choices: it is a single-purpose, ad-free productivity tool with no social components, no external links, and in-app purchases limited to the core product/subscription, eliminating many common digital dangers. Its *Tracking present* status is entirely centered on necessary operational analytics and secure, permission-based use of highly protected, temporary data for optional AI features, all while ensuring that the core notebook content remains private and encrypted.
This combination of powerful educational utility, strict privacy adherence, and robust security architecture makes GoodNotes an exceptionally safe digital investment for a student's academic life, giving them a reliable tool to achieve success.
Criterios de Selección
Nuestra evaluación se basa en una revisión de cuatro pilares centrales: privacidad, adecuación a la edad, valor educativo y ausencia de publicidad. También consideramos premios y certificaciones.