Notepico
Home Privacy Policy Terms of Service Contact
Notepico

Privacy Policy

NOTEPICO PRIVACY POLICY

Last updated: September 15, 2026

Developer/Operator: yimdev Privacy email: notepico.support@gmail.com

1. Summary

Notepico is a notes application that lets you create, edit, store, and manage notes. Notepico also provides backup to supported cloud storage services. Cloud storage is optional and requires authorization to the selected provider.

Supported cloud services:

  • Google Drive — uses the application data folder (appDataFolder).
  • Microsoft OneDrive — uses an App Folder.
  • Dropbox — uses an App Folder.

Notepico backups are encrypted before they are sent to cloud storage. Notepico also uses Firebase services for certain functions, including app usage analytics, announcements, and notifications.

2. Information We Process

The information processed depends on the features you use.

2.1 Note Data Data you enter into Notepico is processed by the app to provide note-taking functions, including creating, editing, displaying, storing, and deleting notes. Notepico does not use note contents as parameters in custom analytics events.

2.2 Backup Data When you use the backup feature, Notepico creates a backup artifact needed to restore app data. The backup is encrypted before it is sent to your selected cloud service.

2.3 Cloud Account Information When you connect Google Drive, Microsoft OneDrive, or Dropbox, Notepico processes the authorization information required to provide backup and restore functions. This information may be used to connect the cloud service, create backups, upload backups, find and retrieve backups, restore backups, and manage backups through available features. Cloud credentials or access tokens are stored using Android Keystore protected storage. Notepico does not provide a separate Notepico account system requiring a username and password.

3. Google Drive

If you choose Google Drive, Notepico uses the Google Drive application data folder (appDataFolder). Notepico uses the scope https://www.googleapis.com/auth/drive.appdata. This scope is used for application-specific data and does not give Notepico general access to all files in your Google Drive. Notepico uses the application data folder to store and manage Notepico backups. Notepico does not use this access to read or manage documents, photos, videos, or other personal files outside the Notepico application area. Notepico only requests profile information needed by the connection process and does not specifically request the email address as part of backup profile information. Google Drive use remains subject to Google privacy policies and terms.

4. Microsoft OneDrive

If you choose Microsoft OneDrive, Notepico uses the OneDrive App Folder. Notepico requests the Files.ReadWrite.AppFolder permission. This permission provides read and write access to the Notepico application folder. Notepico does not request a permission that provides general access to all OneDrive files. OneDrive is used to create, upload, retrieve, restore, and manage Notepico backups. Basic Microsoft account information required during authentication may be processed to identify the account connection. Microsoft OneDrive use remains subject to Microsoft privacy policies and terms.

5. Dropbox

If you choose Dropbox, Notepico uses a Dropbox App Folder. Notepico uses OAuth 2.0 with PKCE for authentication. The permissions used cover the need to read required account information, read backup metadata, read backup contents, upload backups, and manage Notepico backups. Notepico Dropbox configuration uses an App Folder, so app access is limited to the Notepico application area. Notepico does not use this access to read or manage personal files outside the Notepico App Folder. Dropbox use remains subject to Dropbox privacy policies and terms.

6. Backup Encryption

Notepico encrypts backups before they are sent to cloud storage. Backup encryption uses AES-256-GCM. Key material is protected using Android Keystore. Notepico also provides a Recovery Key mechanism according to the recovery features available in the app. Cloud backups are therefore sent as encrypted backup artifacts. Notepico does not guarantee that any electronic system or transmission is completely free from security risks.

7. Google Analytics for Firebase

Notepico uses Google Analytics for Firebase to understand feature usage, monitor feature use, and improve the app. Notepico has custom usage events related to activities such as note creation, note editing, note deletion, backup creation, backup restoration, cloud backup activity, and theme changes. In custom events created by Notepico, the app does not intentionally send note contents, note titles, Recovery Keys, backup contents, backup file names, or cloud account credentials as parameters. However, the Firebase Analytics SDK may automatically process certain app usage and technical information according to the SDK configuration and Firebase services. Firebase Analytics use may therefore involve processing of certain information by Google under the applicable Google services and policies.

8. Firebase Cloud Firestore

Notepico uses Firebase Cloud Firestore to retrieve and display app announcements. Announcement information may include an announcement identifier, title, message, target, type, action link, minimum app version, creation time, and expiration time. Firestore is used for app announcements and is not the primary storage for users personal note data.

9. Firebase Cloud Messaging

Notepico uses Firebase Cloud Messaging (FCM) to receive app notifications and announcements. The app may use a general notification topic to distribute announcements to subscribed users. Messages may contain information such as a title, message, or action link needed to display an announcement. FCM is used for app notification functions and is not the primary storage for users personal notes.

10. Camera and ML Kit

Notepico uses camera permission when you actively use features that require the camera, such as QR/barcode scanning or text recognition. Notepico uses Android CameraX, Google ML Kit Barcode Scanning, and Google ML Kit Text Recognition. Image processing for scanning is performed through ML Kit components on the device according to the app implementation. Notepico has no app code that uploads camera images to a Notepico server to perform scanning. Camera permission is only required for features that use the camera.

11. Notifications

Notepico may request Android notification permission to display app announcements or notifications. If notification permission is not granted, certain notification functions may be unavailable. The permission is not required for basic note-taking functions that do not use notifications.

12. Technical and Usage Information

Certain technical or usage information may be processed through the app and third-party services used by Notepico to operate app functions, maintain security and stability, understand feature usage, identify and fix issues, provide announcements, provide notifications, and improve the user experience. Notepico does not intentionally include note contents in custom analytics events.

13. Sharing with Service Providers

Notepico may process or provide information to third-party service providers when necessary to provide features you use. Google is used for Google Drive, Firebase Analytics, Firebase Cloud Firestore, and Firebase Cloud Messaging. Microsoft is used for Microsoft authentication and Microsoft OneDrive. Dropbox is used for Dropbox authentication and storing and managing backups through the Dropbox App Folder. These providers process information according to their services and applicable terms. Notepico does not sell users personal data. Notepico does not use user data for targeted advertising by Notepico.

14. Use for AI

Notepico does not use note contents or backup contents as a dataset to train AI models owned by Notepico. This statement applies only to Notepico own use of data and is not a statement about the data processing policies of individual third-party providers.

15. Security

Notepico applies technical protections including AES-256-GCM backup encryption, Android Keystore protection for key material, Android Keystore protected storage for cloud credentials, OAuth for supported cloud authentication, PKCE and state verification in Dropbox authentication, and application folders with limited access scopes on supported cloud services. Although these measures are intended to help protect data, no electronic storage or transmission system can be guaranteed to be completely secure.

16. Data Storage and Retention

Local Notepico data remains on the device until it is deleted by the user or removed through an app operation. Created cloud backups may remain on the selected cloud service until the user deletes the backup, the backup is deleted through an available management feature, the backup is deleted through the relevant cloud service, or the backup is deleted as part of a backup management operation. Disconnecting a cloud account does not by itself guarantee deletion of all previously stored backups. Data held by third-party services is also subject to their storage, deletion, and retention mechanisms.

17. Disconnecting Cloud Services

Users can stop using cloud backup through the cloud features available in Notepico. After a connection is disconnected, Notepico cannot use those connection credentials for cloud operations until the user reconnects the service and provides the required authorization. Users may also revoke app authorization through their Google, Microsoft, or Dropbox account settings. Revoking authorization does not automatically mean that previously stored backups will be deleted.

18. Notepico Account

The version of Notepico covered by this Privacy Policy does not provide a separate Notepico account system requiring users to create an account with a username and password. Google, Microsoft, or Dropbox accounts used for cloud features are accounts held with the respective providers. Those accounts are subject to the providers respective policies and terms. If Notepico adds a user account system in the future, this Privacy Policy will be updated to explain account data processing, retention, and deletion.

19. Children Privacy

Notepico is not specifically directed to children. We do not knowingly ask children to provide personal information that is not necessary to operate the app. If you become aware of inappropriate processing of a childs personal information, you may contact us using the privacy contact below.

20. User Rights and Choices

Depending on the laws applicable to you, you may have rights concerning personal data, including the right to receive information about processing, request access to certain information, request correction, request deletion where applicable, withdraw certain permissions or authorizations, stop using cloud services, and contact us about privacy matters. For data stored in Google Drive, Microsoft OneDrive, or Dropbox, some data management is controlled by the respective cloud account and provider.

21. Changes to This Privacy Policy

We may update this Privacy Policy when there are changes to Notepico features, third-party services, data processing practices, legal requirements, or platform requirements. The Last updated date will be changed when an update is made. If changes are material, we may provide notice through the app or another appropriate method.

22. Privacy Contact

For questions, requests, or complaints regarding privacy and Notepico data processing, contact: Developer/Operator: yimdev Privacy email: notepico.support@gmail.com App name: Notepico

23. Consent and Permissions Information

Certain Notepico features require user permissions or authorization. Camera access is required when using scanning features. Notification permission is used to display app notifications. Google authorization is required when you choose Google Drive. Microsoft authorization is required when you choose OneDrive. Dropbox authorization is required when you choose Dropbox. Notepico uses these permissions and authorizations to provide the related functions described in this Privacy Policy. Users can deny or revoke certain permissions through device settings or the relevant service account settings, although doing so may make certain features unavailable.

© 2026 Notepico. All rights reserved.