Privacy Policy
Effective date: 13 September 2026
Last updated: 15 September 2026
Developer: Zilloris
Contact: support@zilloris.com
App: Note Bolt: Notepad, To-Do List (com.zilloris.notebolt.notepad.notes)
1. Introduction
This Privacy Policy explains how the Note Bolt app for Android (“the app”, “we”, “us”, “our”) handles information. It applies to the app distributed on Google Play under the package name com.zilloris.notebolt.notepad.notes, published by Zilloris.
By installing or using the app you acknowledge the practices described here. If you do not agree with this policy, please do not use the app.
2. Summary
- Your notes stay on your device. The app has no user accounts, and we do not upload, read or store your notes on any server.
- We do not sell personal data, show advertising, or use advertising identifiers.
- The app uses Google Firebase and Google Play services to deliver app settings, occasional announcements, crash reports and app updates. These services receive technical identifiers, device information and, when the app crashes, a crash report. They never receive the content of your notes.
Data at a glance
| Data | Where it is kept | Shared with | Purpose |
|---|---|---|---|
| Notes and their titles, colors, pins, bookmarks, checklists, reminders, archive and trash | On your device only | No one | Core note-taking features |
| Recent searches and app settings (theme, default color, text size, toolbar order, sort order and layout) | On your device only | No one | Remembering your preferences |
| Note lock PIN or pattern | On your device only, as a salted one-way hash | No one | Protecting notes you lock |
| Firebase installation ID and Firebase Cloud Messaging token | Google Firebase | Google, as our service provider | App configuration and announcements |
| Crash reports: the error, the app state and device details at the moment of a crash, and a random Crashlytics installation ID | Google Firebase | Google, as our service provider | Finding and fixing crashes |
| Session and performance data: app version, device model, Android version, network type, and when the app was opened | Google Firebase | Google, as our service provider | Measuring how stable the app is |
| Device and app details sent with requests to these services: device model, Android version, app version, language, and IP address | Google Firebase and Google Play | Google, as our service provider | Delivering the services above |
| A feedback email you choose to send | Your email provider and our support inbox | No one else | Replying to your feedback |
3. Information stored only on your device
Everything you create in the app is saved in the app’s private storage on your device. This includes your notes, note titles, colors, pins, bookmarks, checklists, reminder times, archived notes, notes in Trash, recent searches and your settings.
We have no access to this information and it is not transmitted to us.
- Notes moved to Trash are deleted automatically after 30 days.
- If you set up Note lock, only a salted one-way hash of your PIN or pattern is stored, never the PIN or pattern itself.
- If you unlock notes with your fingerprint or face, Android handles the check. The app only learns whether it succeeded and never receives biometric data.
4. Information processed by Google services
The app includes the following Google services. Google acts as our service provider and processes this information under its own privacy terms: the Google Privacy Policy and Privacy and Security in Firebase.
4.1 Firebase Installations
Creates a random identifier for this installation of the app. Firebase Remote Config, Firebase Cloud Messaging and Firebase Crashlytics use it to work. It is not linked to your name, email address or notes.
4.2 Firebase Cloud Messaging
Lets us send occasional announcements about the app, such as new features or important notices, as notifications. A messaging token for this installation is registered when the app starts. The content of your notes is never sent.
4.3 Firebase Remote Config
Lets us adjust app settings without releasing a new version, for example whether to offer an app update. When the app fetches these settings, which happens when you open it, Google receives the installation identifier and basic device and app details.
4.4 Firebase Crashlytics
When the app crashes, Crashlytics sends us a crash report so we can find and fix the problem. A crash report contains:
- the error and the place in the app’s code where it happened;
- the app version and the state of the app at the moment of the crash;
- device details at that moment: device model, Android version, orientation, and free memory and storage;
- a random Crashlytics installation ID, used to count how many devices a crash affects.
Crashlytics also uses Firebase Sessions to measure how many app sessions end without a crash. For this it records the app version, device model, Android version, network type, and when the app was opened.
Crash reports never contain your notes, note titles, or anything you type. They are sent only from release versions of the app, such as the one on Google Play. The app has no setting to turn crash reporting off.
4.5 Google Play In-App Updates
Checks Google Play for a newer version of the app and, when one is available, offers to install it. This check is handled by the Google Play Store app on your device.
The app also contains Google libraries for account sign-in and cloud storage (Firebase Authentication and Cloud Firestore). The app offers no sign-in or cloud-sync feature, so no account information or notes are sent through them.
5. Information you choose to share
Some features send information off your device, but only when you ask them to:
- Sharing a note. Sharing as text, image or PDF hands the note to the app you pick in the Android share menu, such as a messaging or email app. That app’s privacy policy then applies. A note shared as an image also shows the app name and a QR code that links to the app on Google Play.
- Export. Export writes a backup file of your notes to a location you choose. The file is not encrypted and can be read by anything that can open it. The app warns you before including locked notes.
- Import. Import reads a backup file you select and adds its notes to the app. The file is not sent anywhere.
- Rating and feedback. If you give the app 1 to 3 stars, your email app opens a message to support@zilloris.com. The draft contains your star rating, the app version, your device model and Android version, and you can edit or delete any of it before sending. If you give 4 or 5 stars, the Google Play Store opens so you can leave a review.
- Share app. Opens the Android share menu with a link to the app on Google Play.
6. Permissions the app uses
| Permission | Why the app needs it |
|---|---|
| Internet access and network state | To use Firebase Remote Config, Firebase Cloud Messaging, Firebase Crashlytics and Google Play In-App Updates. Never used to upload your notes. |
| Post notifications | To show reminders you set and occasional announcements. On Android 13 and later, Android asks for your permission first, the first time you set a reminder. |
| Schedule exact alarms | To deliver a reminder at the exact time you chose. |
| Run at startup (receive boot completed) | To restore your scheduled reminders after the device restarts. |
| Use biometrics | Optional. To unlock locked notes with your fingerprint or face through Android. The app never receives biometric data. |
The app does not request access to your contacts, location, camera, microphone, call logs, SMS, or the photos and files on your device. The only exceptions are files you choose yourself when you export or import a backup.
7. How we use information
- To provide the app’s features: saving notes, reminders, widgets, Note lock, sharing and export.
- To deliver announcements and adjust app configuration.
- To offer app updates.
- To find and fix crashes and measure how stable the app is.
- To read and respond to feedback you send us.
We do not use information for advertising, we do not build profiles of you, and we do not make automated decisions that affect you.
8. Sharing and disclosure
We do not sell, rent or trade personal data. Information is shared only in these cases:
- With Google, as the service provider for the Firebase and Google Play services described in section 4.
- When required by law, for example in response to a valid legal request. Because your notes never leave your device, we have no notes to disclose.
- In a business transfer, such as a merger or sale of the app. Any successor must honor this policy.
9. Data retention and deletion
- Notes and settings stay on your device until you delete them. Notes in Trash are deleted permanently after 30 days, and you can empty Trash sooner.
- Uninstalling the app, or clearing its storage in Android Settings, permanently removes all of the app’s data from your device.
- Firebase identifiers and related technical data are retained by Google under its own retention practices. Uninstalling the app or clearing its data creates a new identifier the next time the app is used.
- Crash reports, including their Crashlytics installation IDs, are kept by Firebase Crashlytics for 90 days and then deleted automatically.
- Feedback emails are kept only as long as needed to handle your request, then deleted. You can ask us to delete them at any time.
- If Android backup is turned on, Android may include the app’s data in your device backup stored in your Google account. You manage and delete those backups in your device and Google account settings.
Identifiers and crash reports are random and not linked to your name or email address, so we cannot find the ones that belong to you from a request. They are deleted as described above. To ask about or request deletion of any other information we hold, such as a feedback email, write to support@zilloris.com. We will respond within 30 days.
10. Security
We take reasonable measures to protect information:
- App data is kept in Android’s app-private storage, which other apps cannot read.
- Note lock secrets are stored only as salted one-way hashes.
- The app’s communication with Google services is encrypted in transit (HTTPS).
The app does not encrypt notes itself. Protect your device with a screen lock, and store exported backup files somewhere safe, because they are plain, unencrypted files. No method of storage or transmission is completely secure.
11. Children’s privacy
The app is a general-audience productivity app and is not directed at children under 13, or under the minimum age required in your country. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, for example in a feedback email, contact us and we will delete it.
12. Your rights and choices
- Notifications. Turn off reminders or announcements at any time in Android Settings > Apps > Note Bolt > Notifications.
- Deletion. Delete individual notes in the app, or clear the app’s storage or uninstall it to remove everything from your device.
- Access, correction and deletion. Depending on where you live, including the European Economic Area, the United Kingdom and some US states, you may have the right to request access to, correction of or deletion of your personal data, or to object to or restrict its processing. Contact us to exercise these rights.
- Complaints. You also have the right to lodge a complaint with your local data protection authority.
Where the law requires a legal basis for processing, we rely on our legitimate interest in operating, configuring, updating and fixing the app, including crash reporting, and on your consent for notifications where it is required.
13. International data transfers
Google may process the information described in section 4 on servers in countries other than your own, including the United States. Google provides safeguards for these transfers as described in its privacy terms.
14. Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be published at the same web address, shown in the app under Privacy policy, and marked with a new “Last updated” date. If a change significantly affects how information is handled, we will highlight it in the app or in the Google Play release notes.
15. Contact us
If you have questions about this Privacy Policy or your data, contact:
Developer: Zilloris
Email: support@zilloris.com