Just Notes Privacy Policy
Effective July 12, 2026
Just Notes is a note-taking application developed by Brian Yeh. This policy explains the data Just Notes accesses, why it is used, how it is protected, and how you can request deletion.
Notes and Google Drive
Notes are stored locally on your device by default. If you choose Google Drive sync, Just Notes uploads and reads your backup in the private appDataFolder of your own Google Drive account for sync and restore. The developer does not use note content for advertising, analytics, profiling, or sale. Deleting the app does not automatically delete a backup stored in your Google Drive account.
Google Sign-In and account ownership
Google Sign-In provides a Google account identifier and may provide a verified email address. The backend uses the account identifier to bind subscription entitlements to the correct account. A verified email is processed ephemerally and may be transformed with HMAC-SHA-256 for limited security, reviewer-access, or deletion purposes. Raw email addresses and Google ID tokens are not intentionally stored in application logs.
Google Play Billing and Premium
When you use Premium, Just Notes processes Google Play purchase history and subscription state. The backend receives a purchase token transiently, stores only a keyed hash and encrypted purchase token ciphertext, verifies the purchase with the Google Play Developer API, records acknowledgement and entitlement state in Firestore, and processes Real-time Developer Notifications (RTDN). Raw purchase tokens are not stored. RTDN deduplication records expire after 30 days.
Just Notes may process an app-generated device identifier inside a Drive sync snapshot so updates from the same installation can be reconciled. The app does not use the Android Advertising ID and contains no advertising SDK.
Security
Data in transit uses HTTPS/TLS. Purchase-token ciphertext is protected by Google Cloud KMS. Backend access uses service identities and least-privilege IAM. Sensitive tokens, Google subjects, email addresses, ciphertext, and ID tokens are excluded from normal application logging.
Service providers and sale of data
Google, Google Play, Google Cloud, and GitHub process data as service providers under their own terms. Just Notes does not sell personal data and does not share data for advertising.
Retention and deletion
Entitlement and subscription records are retained while needed to provide Premium, prevent fraud, comply with legal obligations, or complete a deletion request. Reviewer grants expire at their configured time. After an eligible deletion, the backend keeps only a one-way hashed coordination guard for up to 15 minutes so an already-running billing update cannot recreate deleted records; Firestore TTL then removes it. Security and delivery-deduplication records follow their configured retention period.
You can request deletion at the Just Notes account-deletion page. Active Google Play subscriptions must be canceled separately and may need to reach expiry before backend subscription records can be deleted safely. Local notes remain under your device control, and Drive backups remain under your Google account control.
Contact
Questions or deletion support: yeh.shibang@gmail.com