
My Notes
Android
Productivité
Tâches
Listes
Rappels


Privacy Policy — My Notes
Last updated: August 11, 2026
Publisher / data controller: Digiwave
Contact: crew@digiwavelab.com
Apps covered: My Notes, in both its distributions:
- Google Play version (package com.digiwave.mynotes);
- F-Droid version (package com.digiwave.mynotes.free), free and fully unlocked, with no Google dependency.
This single policy covers both versions. They share the same code and architecture (no server, same local and end-to-end encryption principles); the few differences between the two distributions — Google Drive sync and the in-app purchase, both exclusive to the Google Play version — are explicitly flagged wherever they appear.
In short
--------
- My Notes has no server. Digiwave does not operate any database, user account, analytics, or advertising service. Nothing you write in the app passes through our systems, for the simple reason that we don't have any.
- Your notes stay on your device, in a local encrypted database.
- Sync between devices is optional. If you enable it, your notes are end-to-end encrypted with a password only you know, before being sent to the cloud service of your choice (Google Drive, Dropbox, OneDrive, pCloud, or your own WebDAV server). Neither Digiwave nor these providers can read the content of your notes.
- The "full unlock" purchase (Google Play version only) is handled entirely by Google Play Billing. Digiwave does not receive or store any payment information. The F-Droid version, meanwhile, is free and fully unlocked upon installation: the concept of a purchase does not apply to it.
- No advertising, no tracker, no audience-analytics tool, and no third-party measurement SDK is built into the app.
The rest of this document details these points precisely, in line with the GDPR (European Union), the CCPA/CPRA (California), and Google Play's Data Safety requirements.
1. No account, no My Notes server
---------------------------------
My Notes does not offer account creation with Digiwave and does not communicate with any backend server that we operate.
The app functions as a local notebook. The only network exchanges it makes are:
- with Google Play servers (billing — Google Play version only);
- with the cloud service you explicitly choose to enable for sync (Dropbox, OneDrive, pCloud, or a WebDAV server you configure yourself, on both versions; Google Drive additionally on the Google Play version only);
- with the website whose link you paste into a note, solely to generate a preview (title/image).
Outside of these three cases, all initiated by you, the app transmits nothing.
2. Data processed, and why
--------------------------
2.1 Content of your notes (text, lists, images, files, audio recordings, links)
----------------------------------------------------------------------
- Local storage: stored in an encrypted SQLite database on your device (AES encryption via SQLCipher/SQLite3MC), with a key randomly generated on the device and kept in the system's secure keystore (Android Keystore). This key never leaves the device.
- Cloud sync (optional): if you enable sync, each note, tag, attachment, and reminder is individually encrypted (AES-256-GCM, key derived via PBKDF2 with 150,000 iterations) using a sync password that you set. This password is never transmitted to Digiwave or to the cloud provider: it never leaves your devices. The chosen cloud provider only stores encrypted blocks that are unreadable without this password (so-called "end-to-end" / zero-knowledge encryption).
- Digiwave has no technical means of accessing the content of your notes, synced or not.
2.2 Cloud storage provider account (optional)
---------------------------------------------
If you connect a Dropbox, OneDrive, pCloud (both versions), or Google Drive account (Google Play version only — absent from the F-Droid version, which has no dependency on any Google service) to sync your notes, the app:
- uses the provider's official authentication mechanism (OAuth 2.0);
- retrieves only the email address associated with that account, in order to display it in the app's settings (to show you which account is connected);
- for Google Drive specifically, only accesses a private application folder ("App Data"), invisible and inaccessible from your regular Google Drive space — the app has no access to any other file in your Drive;
- stores the access token and email address locally, in the system's secure keystore. This information is never sent to Digiwave.
If you use WebDAV, the connection credentials (server address, username, password) are stored locally in the same way and transmitted only to the server you have configured.
2.3 "Full unlock" in-app purchase (Google Play Billing — Google Play version only)
----------------------------------------------------------------------
- This section only applies to the Google Play version. The F-Droid version is distributed free of charge, fully unlocked upon installation, and offers no in-app purchase.
- On the Google Play version, the purchase is a non-consumable product managed entirely by Google Play Billing (com.android.vending.BILLING).
- The app only receives the purchase status (purchased / not purchased) from Google Play, which it records locally (a simple true/false flag in the device's secure keystore) to unlock features.
- Digiwave does not receive, see, or store any payment data (card number, billing details, etc.): this information stays between you and Google. See Google's privacy policy (https://policies.google.com/privacy) and the Google Play Terms (https://play.google.com/intl/en/about/play-terms/).
- No receipt verification is performed on a third-party server: My Notes relies on the status returned by the Google Play API on the device.
2.4 Device permissions
----------------------
- Camera
* Purpose : Take a photo to insert into a note
* Transmission : Stays on the device, unless you enable sync (encrypted, see 2.1)
- Microphone
* Purpose : Record a voice note
* Transmission : Same as above
- Notifications
* Purpose : Display the reminders you schedule
* Transmission : None (100% local notifications, generated on the device)
- Exact alarms / start at boot
* Purpose : Trigger reminders at the scheduled time, including after the phone restarts
* Transmission : None
- Ignore battery optimization (optional)
* Purpose : Improve reliability of background sync and reminders
* Transmission : None
None of these permissions are used to collect data for tracking, profiling, or advertising purposes.
2.5 Link previews
-----------------
When you paste a URL into a note, your device connects directly to the site in question to retrieve its title and a preview image. This request originates from your device, not from a Digiwave server: the visited site may therefore see your device's IP address and a generic technical header (user-agent), just as with any regular web browsing. Digiwave neither collects nor sees this request. This feature is only triggered by a voluntary action on your part (adding a link).
2.6 Technical device identifier
-------------------------------
To resolve conflicts between devices during sync, the app generates a random identifier unique to each installation (UUID), unrelated to your identity, serial number, or advertising identifier. This identifier is encrypted before being stored in your personal cloud space, just like your notes.
2.7 Invitation / profile sharing between devices
------------------------------------------------
The invitation feature (link or QR code to connect another device to the same profile) is encrypted locally with your sync password and exchanged directly between your devices (native system sharing or QR code scanning): it never passes through any Digiwave server.
2.8 What My Notes never collects
--------------------------------
- No advertising or advertising SDK (no AAID/IDFA advertising identifier is used).
- No audience-analytics or behavioral-measurement tool (no Firebase Analytics, Google Analytics, Mixpanel, etc.).
- No tracking across other apps or third-party websites.
- No access to your contacts, location, call log, or SMS — the app requests none of these permissions.
- No crash logs sent to a third-party service (no Crashlytics/Sentry).
3. Legal basis for processing (GDPR, Art. 6)
--------------------------------------------
- Performance of the requested service: local storage of your notes, encryption, reminders — necessary for the very operation of the app you installed.
- Consent: enabling cloud sync, camera/microphone/notification permissions — each is triggered by an explicit action on your part and can be revoked at any time (in the app's settings or your Android system settings).
- Performance of a contract: processing of the purchase via Google Play (Google Play version only), governed by the Google Play Terms.
If you are a California resident, this processing is carried out for the "business purpose" of providing the service you requested, without any sale or sharing of your personal information.
4. Data recipients and transfers outside the European Union
-----------------------------------------------------------
Digiwave does not share any data with third parties for commercial, advertising, or resale purposes. The only possible recipients are those that you choose to enable:
- Google Play (Google Ireland Ltd / Google LLC) — Google Play version only
* Role : Built-in billing
* What it receives : Purchase status; payment data handled by Google
* Privacy policy : policies.google.com/privacy
- Google Drive (if enabled) — Google Play version only
* Role : Optional cloud storage of your choice
* What it receives : Encrypted data blocks (unreadable without your password); your Google email address
* Privacy policy : policies.google.com/privacy
- Dropbox (if enabled) — both versions
* Role : Same as above
* What it receives : Same as above
* Privacy policy : dropbox.com/privacy
- Microsoft OneDrive (if enabled) — both versions
* Role : Same as above
* What it receives : Same as above
* Privacy policy : privacy.microsoft.com
- pCloud (if enabled) — both versions
* Role : Same as above
* What it receives : Same as above
* Privacy policy : pcloud.com/privacy-policy
- Your own WebDAV server (if enabled) — both versions
* Role : Server you configure yourself
* What it receives : Encrypted data blocks
* Privacy policy : Depends on your own server/host
As these providers may be established in, or host data in, countries outside the European Union (notably the United States), the corresponding transfers rely on each provider's own safeguards (standard contractual clauses, certification under the EU-U.S. Data Privacy Framework, etc.). Since the data they receive is end-to-end encrypted with a key they do not hold, they have no technical access to the content of your notes.
5. Retention period
-------------------
- On your device: your notes are kept for as long as the app is installed and you do not delete them. Fully uninstalling the app deletes the local database and its encryption key.
- In your personal cloud: your encrypted notes are kept for as long as you do not delete them and you keep the application folder in your cloud account. Deleted items (notes, tags) are kept in an encrypted "trash" for 60 days (to allow syncing across several devices) before being automatically and permanently purged.
- Purchase status (Google Play version only): kept locally until the app is uninstalled or explicitly restored via Google Play.
Digiwave retains none of this data on its side, since none of it is transmitted to us.
6. Security
-----------
- Encrypted local database (SQLite3MC/SQLCipher, random key generated on the device).
- Keys and authentication tokens stored in the operating system's secure keystore (Android Keystore via flutter_secure_storage).
- End-to-end encryption (AES-256-GCM, PBKDF2/HMAC-SHA256 key derivation, 150,000 iterations) for any data synced to the cloud.
- OAuth 2.0 authentication with PKCE for connecting to cloud providers.
- Integrity verification (SHA-256 hash) of synced files and images.
No system is infallible, but My Notes' architecture is designed so that, by construction, neither Digiwave nor the cloud providers have access to the plaintext content of your notes.
7. Your rights
--------------
European Union / European Economic Area residents (GDPR)
--------------------------------------------------------
You have the right to access, rectify, erase, restrict, object to, and port your data. In practice, since almost all of your data is stored on your own device and in your own cloud account, you already exercise these rights directly:
- Access / portability: all your notes can be viewed and exported directly from the app.
- Rectification / erasure: edit or delete your notes in the app; the deletion propagates to your cloud storage at the next sync.
- Complete erasure: uninstall the app and/or delete the application folder in your cloud account (Google Drive, Dropbox, OneDrive, pCloud) or on your WebDAV server.
For any question, or to exercise these rights regarding the rare data we might hold indirectly (e.g., email exchanges with support), contact crew@digiwavelab.com. You also have the right to lodge a complaint with the French Data Protection Authority (CNIL) — cnil.fr (https://www.cnil.fr/) — or with the data protection authority of your EU country of residence.
California residents (CCPA/CPRA)
--------------------------------
Digiwave does not sell or "share" (within the meaning of the CCPA) any personal information, and does not collect any for advertising purposes. California residents have the same rights of access, deletion, and portability described above; there is no "opt-out of sale" mechanism because no sale takes place.
Other jurisdictions (Canada – PIPEDA, Brazil – LGPD, United Kingdom – UK GDPR, etc.)
----------------------------------------------------------------------
The same principles apply: no data is collected beyond what is strictly necessary for the app's local operation and for facilitating, at your request, encrypted synchronization with the cloud service of your choice. Canadian residents may contact the Office of the Privacy Commissioner of Canada if they have concerns about our compliance with PIPEDA.
8. Children
-----------
My Notes is not specifically directed at children and does not target this audience. The app does not knowingly or unknowingly collect any personally identifying data that would reveal whether a user is a minor, since no sign-up or personal data collection is required to use it. In line with COPPA (United States) and the GDPR, we do not knowingly collect data from children under 13 (or the applicable digital-consent age in the EU). If you believe a child has provided us with personal data (for example, via a support email), please contact us so we can delete it.
9. Changes to this policy
-------------------------
This policy may be updated, in particular as the app's features evolve (for example, the addition of a new cloud storage provider). The date of the last update appears at the top of this document. In the event of a substantial change, we will inform you via the app's release notes, on both Google Play and F-Droid.
10. Contact
-----------
For any question regarding this privacy policy or the processing of your data:
Digiwave
crew@digiwavelab.com