Nest Note icon Nest Note
Try Nest Note
← Back to Nest Note

Privacy Policy

Effective Date: September 24, 2026 · Version 1.0

At Nest Note ("we," "us," or "the application"), we believe your notes, daily thoughts, and personal schedules are strictly private. We engineered Nest Note around a fundamental principle: Local-First Data Ownership. Your notes reside on your own device and are never routed through, processed by, or stored in a proprietary central database operated by Nest Note.

Key Takeaway: We do not operate servers that store, read, analyze, or sell your notes. Your notes live in a private SQLite database on your hardware. If you enable optional cloud sync, your data travels directly between your device and your personal Google Drive account in an isolated app folder.

1. Information We Store and Process

A. Your Notes, Lists, and Personal Content

All notes, subnotes, checklists, dates, repeat rules, and color choices you create are stored in an encrypted/private local SQLite database directly on your hardware:

  • On Web (PWA): Persisted locally inside your browser's IndexedDB storage using WebAssembly SQLite (sql.js).
  • On Native Mobile (iOS & Android): Persisted in a local SQLite database file within the application's private, sandboxed app directory.
  • Zero Server Access: We have no access to your local SQLite database. We cannot view, decrypt, index, or recover your notes.

B. Optional Cloud Sync via Google Drive

If you explicitly connect your Google Account for cloud backup, Nest Note syncs your data directly with Google Drive using Google’s official Identity Services (GIS) and Drive REST API v3:

  • Restricted AppData Scope (drive.appdata): Nest Note requests access strictly to Google Drive's hidden Application Data folder. Nest Note cannot see, read, modify, or delete any of your personal Google Docs, photos, spreadsheets, or other files in Google Drive.
  • Identity Scopes (userinfo.email, userinfo.profile): Used solely to display your active account name, email address, and avatar in the application Settings menu.
  • Zero Intermediary Storage: Note JSON files, page schemas, and sync manifests are exchanged directly between your client application and Google's official endpoints (googleapis.com). No intermediary Nest Note server ever stores or proxies your note content.
  • Authentication Architecture: OAuth 2.0 authorization codes are exchanged for tokens using standard PKCE flow via serverless endpoints. Refresh tokens are stored strictly inside a secure, HttpOnly, SameSite=Lax cookie that cannot be read by browser JavaScript or external scripts. Access tokens are stored strictly in volatile device memory and are never persisted to localStorage.

C. Google API Services User Data Policy Disclosure

Nest Note’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide user-facing features (backing up and synchronizing user-created notes).
  • We never transfer Google user data to third parties, advertising platforms, data brokers, or information resellers.
  • We never use Google user data to train generalized AI/machine learning models.
  • Human individuals do not read your Google user data unless you provide explicit permission for specific diagnostic support or where required by law.

D. Diagnostics & Privacy-First Telemetry

To maintain performance and diagnose runtime stability, Nest Note includes a privacy-preserving telemetry module powered by Google Analytics 4 (GA4):

  • Strict Zero-PII Policy: The telemetry module never logs, transmits, or captures note contents, note titles, page names, or search queries.
  • Aggregated Interaction Events: Tracks operational metrics such as application launches, anonymized error types, feature interaction counts (e.g. note created, calendar viewed), and coarse bucketed counts.
  • Full User Consent & Opt-Out: In compliance with global privacy standards, telemetry honors GA4 Consent Mode. You can disable analytics at any time directly in the application Settings under Preferences → Anonymous Analytics. Disabling analytics immediately updates the consent state to denied and halts all event dispatches.

2. Data Retention, Portability, and Erasure

Because Nest Note operates without central account servers, you maintain sovereign control over your data lifecycle:

  • Local Data Deletion: You can wipe your local data at any time by clearing your browser cache/IndexedDB storage or uninstalling the mobile app. All local SQLite records are destroyed immediately.
  • Cloud Data Deletion: You can disconnect Google Drive sync at any time in Settings. You can permanently delete all synced Nest Note files directly through your Google Drive management console under Settings → Manage Apps → Nest Note → Delete hidden app data.
  • Data Export & Portability: Nest Note supports manual JSON export and backup downloads from the Settings page, allowing you to back up your raw notes and migrate them anywhere without vendor lock-in.

3. Third-Party Infrastructure

We rely solely on industry-standard, secure infrastructure partners to operate the web application and landing page:

  • Netlify: Serves static web assets and hosts serverless authentication endpoints (code-to-token swap) with zero persistent logging of user payload data.
  • Google APIs & Identity Services: Provides optional user authentication and cloud synchronization storage on your own Google Drive.
  • Google Analytics: Provides aggregated, anonymized usage telemetry subject to user consent controls.

4. Cookies and Local Storage

Nest Note uses minimal client storage mechanisms strictly necessary for operation:

  • Functional Storage: localStorage is used strictly for device-local preferences (e.g., active theme, expanded tree states, analytics consent preference).
  • Security Cookie: A single functional, encrypted HttpOnly cookie is used exclusively to maintain your Google Drive OAuth session across app refreshes. We do not use third-party advertising or cross-site tracking cookies.

5. Children's Privacy

Nest Note is not directed to individuals under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us immediately.

6. Your Privacy Rights (GDPR, CCPA, and Global Laws)

Depending on your location, you may have rights under data privacy regulations such as the European General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA):

  • Right of Access & Portability: You can view and export all your data at any time directly through the app.
  • Right to Erasure: You can permanently delete your local and cloud backups at any time without needing our intervention.
  • We Do Not Sell Personal Data: We have never sold, rented, or monetized personal information, and we never will.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect product enhancements or legal obligations. When updates occur, the "Effective Date" at the top of this document will be updated. We encourage you to review this policy periodically.

8. Contact Us

If you have any questions, feedback, or concerns regarding this Privacy Policy or your data security, please contact us at:

Email: privacy@nestnote.app

Nest Note icon Nest Note
  • Privacy Policy
  • Terms of Service
  • Launch App
© 2026 Nest Note. All rights reserved.