This Privacy Policy explains what information UniNotes ("the App", "we", "us") collects, how it is used, and the choices you have. UniNotes is developed by [Your Name / Urban Techx], based in India.
Notes, subjects, and photos you create in the app — these are stored locally on your device only. UniNotes does not upload the text, photos, or subject organization you create to any server. Exported PDFs are generated entirely on-device.
Onboarding information (if you choose to provide it) — name, email address, and phone number, collected only if you submit them during onboarding. Before this information is stored, it is encrypted server-side (AES-256-GCM) so that even we cannot read it without the corresponding decryption key, which is held in a secured server environment separate from the database itself.
Push notification device token — a token issued by Firebase Cloud Messaging that identifies your device for the purpose of delivering notifications, along with your device's platform (Android/iOS) and a non-identifying hashed profile reference. This is not linked to your name, email, or phone number in a way that is queryable by app staff without the corresponding decryption process described above.
Anonymous usage signals — when a promotional banner is shown or tapped, we record the banner's identifier together with a hashed, non-reversible user reference (not your name, email, or device identifiers) so we can measure how banners perform in aggregate. We do not track your individual browsing or app usage beyond this.
Location-related targeting fields — if provided during onboarding (country, state, city, pincode), used only to decide which promotional banners are relevant to show you. This is coarse, self-reported location data, not GPS-based tracking.
UniNotes displays ads via Google AdMob. We request non-personalized ads only, meaning ad targeting is not based on your individual profile or behavior tracked across other apps. Google's own privacy practices for AdMob apply to this; see Google's Privacy Policy.
Sensitive personal information (name, email, phone) is encrypted before storage using AES-256-GCM with per-field initialization vectors, and decryption keys are held only in a restricted server-side environment. Database-level access controls (Row-Level Security) restrict who and what can read or modify stored data, independent of any application code.
Onboarding information is retained until you request deletion (see Section 7). Device tokens are refreshed automatically by your device and stale tokens are not actively used for delivery. Usage/analytics signals are retained in aggregate form for measuring banner performance.
UniNotes is not directed at children under 18, and we do not knowingly collect personal information from anyone under 18 without verifiable parental consent. If you believe a child has provided personal information to us, contact us at the address below and we will delete it.
Under India's Digital Personal Data Protection Act, 2023, and other applicable law, you may request access to, correction of, or deletion of your personal information. To make a request, email [your contact email]. We will respond within a reasonable time.
In the event of a personal data breach affecting your information, we will notify affected users and the relevant regulatory authority as required by applicable law.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy or your data: [your contact email]