PRIVACY

Privacy notice

Submissions stay private. We take only what we need.

Android v1 · no-sync build

This notice covers the Android v1 no-sync release build with an empty sync server/key and INTERNET permission removed, and this website. App notes and website submissions are handled separately.

Notes in Android v1

Notes, attachments and app settings are normally stored and processed on your device. This build has no app account sign-up, server sync or payment and does not automatically send notes to the operator's server. OCR images and recognized text are distinct from SDK technical metrics. If you choose sharing, exporting or opening an external link, data may pass to the app or browser you select, whose privacy terms apply.

Photo OCR and Google ML Kit metrics

Photo text is recognized on the device. The Google ML Kit OCR SDK remains bundled and may generate or queue installation-specific identifiers, device/app information, latency, input/output sizes, error codes and SDK events locally for service diagnostics and usage analysis. Its default data handling is described in the Google ML Kit data disclosure.

This no-sync release removes INTERNET permission, blocking the app's own direct network transmission. It does not remove the SDK or metric-generation code; generating local metrics is different from transmitting them off-device. Permission removal alone does not guarantee that transfers through other apps, services or inter-app communication are impossible. User-selected sharing, export and browser actions are separate paths. This blocking statement does not cover older network-enabled builds or sync development builds. The lack of direct network permission does not mean that every kind of data processing or transfer is absent.

Optional features and device permissions

Calendar read permission is requested when you choose to fill a meeting note from your calendar; selected event data becomes part of the note. Reminders are local notifications. App lock uses system biometric or device authentication; the operator does not receive biometric data. You choose system photo/file selection or camera capture to add attachments. Basic note writing remains available if optional permissions are declined. The Bible panel is off by default. App lock does not mean note encryption or server end-to-end encryption.

Keeping and deleting app data

You manage and delete app data on the device. Recovery after deletion, uninstalling or device loss is not guaranteed, and this Android build disables OS automatic app-data backup. Export important data and keep a separate copy. Copies already shared or exported to another app must also be managed there. v1 has no server account or server export service.

What do we store?

Why, and who sees it?

We use it to handle submissions, investigate problems, improve the product and prevent abuse. Submissions are not published, and only staff with database access can read them. Please do not send sensitive note contents, religious affiliation, health information, passwords or other people's personal information. We do not accept attachments. The writing situation you choose (for example Devotion or Journal) is used only to sort submissions, never to identify you or infer anything about you.

How long do we keep it?

A submission expires 90 days after it is received. A periodic cleanup, and the handling of the next submission, delete expired messages, emails and their pending records, so removal happens at the next cleanup after expiry.

Processors and location

We use Cloudflare for web hosting, the submission database and the abuse check (Turnstile). Cloudflare processes data on its global network, so information may be processed outside your country. No automatic notice email is sent at present. This website uses no analytics or advertising trackers, and we do not keep your draft in browser storage.

Access and deletion requests

Use Help & feedback, choose "A question", and give your receipt number and request. Do not resend sensitive text. A receipt number alone does not let anyone read or delete another person's information; staff must verify the request. If you left no email, verification and reply may be limited.

Other versions and changes

This v1 notice does not cover development builds with server sync enabled. Before introducing accounts, sync or payment, we will provide separate information about transferred data, providers, retention and deletion. This notice promises no encryption or server recovery for features not yet introduced.

Operator and contact

Operator: 모멘텀(momentum). Privacy and service contact: support@notpad.io. Effective date: 2026-10-11.

Privacy officer

Representative Kwon Jun-hyuk (권준혁) · support@notpad.io

Site terms · Leave a message