At Nest Note ("we," "us," or "the application"), we believe your notes, daily thoughts, and personal schedules are strictly private. We engineered Nest Note around a fundamental principle: Local-First Data Ownership. Your notes reside on your own device and are never routed through, processed by, or stored in a proprietary central database operated by Nest Note.
1. Information We Store and Process
A. Your Notes, Lists, and Personal Content
All notes, subnotes, checklists, dates, repeat rules, and color choices you create are stored in an encrypted/private local SQLite database directly on your hardware:
- On Web (PWA): Persisted locally inside your browser's IndexedDB storage using WebAssembly SQLite (sql.js).
- On Native Mobile (iOS & Android): Persisted in a local SQLite database file within the application's private, sandboxed app directory.
- Zero Server Access: We have no access to your local SQLite database. We cannot view, decrypt, index, or recover your notes.
B. Optional Cloud Sync via Google Drive
If you explicitly connect your Google Account for cloud backup, Nest Note syncs your data directly with Google Drive using Google’s official Identity Services (GIS) and Drive REST API v3:
- Restricted AppData Scope (
drive.appdata): Nest Note requests access strictly to Google Drive's hidden Application Data folder. Nest Note cannot see, read, modify, or delete any of your personal Google Docs, photos, spreadsheets, or other files in Google Drive. - Identity Scopes (
userinfo.email,userinfo.profile): Used solely to display your active account name, email address, and avatar in the application Settings menu. - Zero Intermediary Storage: Note JSON files, page schemas, and sync manifests are exchanged directly between your client application and Google's official endpoints (
googleapis.com). No intermediary Nest Note server ever stores or proxies your note content. - Authentication Architecture: OAuth 2.0 authorization codes are exchanged for tokens using standard PKCE flow via serverless endpoints. Refresh tokens are stored strictly inside a secure,
HttpOnly,SameSite=Laxcookie that cannot be read by browser JavaScript or external scripts. Access tokens are stored strictly in volatile device memory and are never persisted tolocalStorage.
C. Google API Services User Data Policy Disclosure
Nest Note’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide user-facing features (backing up and synchronizing user-created notes).
- We never transfer Google user data to third parties, advertising platforms, data brokers, or information resellers.
- We never use Google user data to train generalized AI/machine learning models.
- Human individuals do not read your Google user data unless you provide explicit permission for specific diagnostic support or where required by law.
D. Diagnostics & Privacy-First Telemetry
To maintain performance and diagnose runtime stability, Nest Note includes a privacy-preserving telemetry module powered by Google Analytics 4 (GA4):
- Strict Zero-PII Policy: The telemetry module never logs, transmits, or captures note contents, note titles, page names, or search queries.
- Aggregated Interaction Events: Tracks operational metrics such as application launches, anonymized error types, feature interaction counts (e.g. note created, calendar viewed), and coarse bucketed counts.
- Full User Consent & Opt-Out: In compliance with global privacy standards, telemetry honors GA4 Consent Mode. You can disable analytics at any time directly in the application Settings under Preferences → Anonymous Analytics. Disabling analytics immediately updates the consent state to
deniedand halts all event dispatches.
2. Data Retention, Portability, and Erasure
Because Nest Note operates without central account servers, you maintain sovereign control over your data lifecycle:
- Local Data Deletion: You can wipe your local data at any time by clearing your browser cache/IndexedDB storage or uninstalling the mobile app. All local SQLite records are destroyed immediately.
- Cloud Data Deletion: You can disconnect Google Drive sync at any time in Settings. You can permanently delete all synced Nest Note files directly through your Google Drive management console under Settings → Manage Apps → Nest Note → Delete hidden app data.
- Data Export & Portability: Nest Note supports manual JSON export and backup downloads from the Settings page, allowing you to back up your raw notes and migrate them anywhere without vendor lock-in.
3. Third-Party Infrastructure
We rely solely on industry-standard, secure infrastructure partners to operate the web application and landing page:
- Netlify: Serves static web assets and hosts serverless authentication endpoints (code-to-token swap) with zero persistent logging of user payload data.
- Google APIs & Identity Services: Provides optional user authentication and cloud synchronization storage on your own Google Drive.
- Google Analytics: Provides aggregated, anonymized usage telemetry subject to user consent controls.
4. Cookies and Local Storage
Nest Note uses minimal client storage mechanisms strictly necessary for operation:
- Functional Storage:
localStorageis used strictly for device-local preferences (e.g., active theme, expanded tree states, analytics consent preference). - Security Cookie: A single functional, encrypted
HttpOnlycookie is used exclusively to maintain your Google Drive OAuth session across app refreshes. We do not use third-party advertising or cross-site tracking cookies.
5. Children's Privacy
Nest Note is not directed to individuals under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us immediately.
6. Your Privacy Rights (GDPR, CCPA, and Global Laws)
Depending on your location, you may have rights under data privacy regulations such as the European General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA):
- Right of Access & Portability: You can view and export all your data at any time directly through the app.
- Right to Erasure: You can permanently delete your local and cloud backups at any time without needing our intervention.
- We Do Not Sell Personal Data: We have never sold, rented, or monetized personal information, and we never will.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect product enhancements or legal obligations. When updates occur, the "Effective Date" at the top of this document will be updated. We encourage you to review this policy periodically.
8. Contact Us
If you have any questions, feedback, or concerns regarding this Privacy Policy or your data security, please contact us at:
Email: privacy@nestnote.app