This policy explains what data the Notes app ("the app", "we") collects, how it is used, and the choices you have. It covers both the Android and iOS ("NotesFlow") versions of the app; sections below note where the two platforms differ. Notes is developed and maintained by an individual developer. If you have questions, contact therahulpahuja@gmail.com.
Note content — titles, text, tags, categories, images, drawings, file attachments, and voice recordings you create — is stored locally on your device in the app's own database. We do not upload your note content to our servers, and we do not sell your data to anyone. On iOS, note titles and content are additionally encrypted at rest using a key stored in the device's Keychain. This key is included in encrypted backups and travels with your data if you move to a new device, so your notes remain readable after a backup restore or device upgrade. In the rare case a note can't be decrypted on a given device, the app tells you clearly rather than showing unreadable text.
Note content only leaves your device in the following cases, all of which you control:
Android: Signing in uses Google Sign-In (via Firebase Authentication). We receive your Google account's name, email address, and profile photo to identify your account within the app. We do not receive your Google password.
iOS: Sign in with Apple or Google is optional. It prefills a local profile (name, email) shown within the app — that information is stored on your device and is never transmitted to our servers. Signing out deletes the locally saved profile. As described in Section 3, your account identifier (not your name or email) is sent to Amplitude and Firebase Analytics once you're signed in, to associate app-usage events with your account.
| Data | Purpose | Service used |
|---|---|---|
| Name, email, profile photo (Android via Google Sign-In; iOS via Sign in with Apple or Google — on iOS this stays local to your device and is never transmitted to our servers) | Sign-in and identifying your account | Firebase Authentication |
| App usage events (e.g. note created, feature used, search performed) and note metadata flags (e.g. whether a note has a title, image, or reminder — never the note's actual text or images) | Understanding feature usage to improve the app | Firebase Analytics |
| App usage and screen-view events (e.g. note created, opened, shared, formatted, locked/unlocked; settings changed; searches performed — search text is never included, only its length), plus your account ID and basic device/app information (app version, device model, OS version) attached as user properties. Never the note's actual text or images. | Product analytics — understanding how features are used across the app | Amplitude |
| Crash logs and diagnostic data | Finding and fixing bugs | Firebase Crashlytics |
| Push notification token — linked to your account ID on Android; on iOS this is registered but not currently used to deliver anything, since reminder and save-confirmation notifications there are scheduled locally on your device | Delivering reminders and notifications to your device | Firebase Cloud Messaging |
| Feature flag values (no personal data) | Rolling out and toggling features remotely without an app update | Firebase Remote Config |
| Account ID, email, and message text — only if you submit feedback or a feature request while signed in (Android) | Reviewing feedback and feature requests | Firebase Realtime Database |
| Message text only, submitted anonymously — no account ID, email, or device identifier attached (iOS "Request a Feature" / "Raise an Issue") | Reviewing feedback and feature requests | Firebase Realtime Database |
| Error category, a short internal context label, and a brief error message — never your note content — submitted anonymously (iOS) | Finding and fixing app errors | Firebase Realtime Database, Amplitude |
| Note or meeting transcript text — only when you enable a cloud AI feature (see Section 1; Android only, no equivalent exists on iOS) | Generating AI sort suggestions or meeting summaries | Google Generative AI (Gemini API) |
Android
Speech-to-text is performed using Android's built-in speech recognition service on your device or through your device's default assistant/TTS service — audio is not sent to our servers for this purpose.
iOS
Speech-to-text uses Apple's on-device speech recognition when your selected language supports it. For a language without on-device support, Apple's speech-recognition servers process the audio instead, subject to Apple's Privacy Policy — audio is never sent to our own servers either way. Reminder and save-confirmation notifications are scheduled locally on your device.
We do not sell your personal data. Data described above is shared only with the service providers necessary to operate the app — Google/Firebase (authentication on Android, analytics, crash reporting, push notification registration, remote config, database), Amplitude (product analytics; see Amplitude's Privacy Policy), Apple (on-device intelligence and, for some languages, server-based speech recognition, on iOS), and, only when you opt in on Android, Google's Generative AI API. These providers process data on our behalf under their own security and privacy commitments.
Notes remain on your device until you delete them or uninstall the app. To request deletion of account-linked data we hold (such as feedback submitted while signed in on Android, or your push notification token), email therahulpahuja@gmail.com from the account in question and we will remove it. Feedback, feature requests, and error reports submitted from iOS are anonymous and aren't linked to any account we could look them up by.
Notes is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
We rely on our processors' security infrastructure — Firebase and Amplitude (encryption in transit, access-controlled cloud storage) — to protect the data described above. On iOS, note titles and content are additionally encrypted at rest using a key stored in the device's Keychain, which travels with encrypted backups and device migrations so your notes remain readable afterward. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
This policy is subject to change as the app evolves. We may update it from time to time without individual notice, so please check back periodically — material changes will be reflected by updating the effective date above.
Questions about this policy or your data? Email therahulpahuja@gmail.com.