ATOMIC NOTES
Privacy Policy
Last updated: 29 September 2026
This policy explains how the Atomic Notes Android app, its sync server and this website handle your information. Atomic Notes is built and operated by Ashutosh Sharma, who publishes as DevBehindYou (“we”, “us”).
The short version
- Your notes are saved on your phone first. When you sync, they go to a folder in your own Google Drive.
- Our server never stores your note titles, text or checklist items.
- There is no analytics, no crash reporting, no advertising and no AI in the app.
- We never sell your data, and we never use it to train AI models.
Information we collect
To run your account and sync, our server keeps:
- Your Google account ID, email address and name, from Google sign-in, and the username you choose.
- Your Atomic Energy and Atomic Coin balances, and a record of how they changed.
- Metadata for each note: its ID, whether it is a note or a checklist, the pinned and deleted flags, timestamps, and the ID of its file in your Google Drive.
- Your Google access and refresh tokens, encrypted with AES-256-GCM before they are stored.
- A short log of account and security events, such as sign-ins.
- Which in-app announcements you have read or dismissed.
We do not collect your note content, contacts, location, advertising IDs, analytics or crash reports. Our hosting provider processes standard request data, such as IP addresses, to deliver the app's server and this website. This website sets no tracking or advertising cookies.
How we use Google user data
Atomic Notes asks Google for these permissions, and uses each one only as described:
- openid, email and profile: to sign you in, create your account, and show your name and email in the app.
- drive.file: to create a
My-Atomic-Notesfolder in your Google Drive, and to create, read, update and delete the note files Atomic Notes makes there, so your notes sync between your devices. This permission only covers files the app created. Atomic Notes cannot see any other file in your Drive.
We use Google user data only to provide and improve these features for you. We do not sell it, use it for advertising, or use it to train artificial-intelligence or machine-learning models. We do not transfer it to anyone except as needed to run the service (see “Service providers” below), for security, or to comply with the law. No person reads your Google data unless you ask for help and give permission, it is needed to investigate abuse or a security problem, or the law requires it.
Atomic Notes' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The end-to-end vault
If you turn on Encryption, the app derives a key on your phone from a 6-word recovery phrase and encrypts every note with AES-256-GCM before it leaves the device. Your Drive and our server then hold only ciphertext. The phrase and the key never leave your phone, so we cannot recover vault notes if you lose the phrase. With the vault off, note content is stored as plain text in your own Drive and passes through our server on its way there, without being stored.
Where data is stored and how it is protected
- Note content: on your phone, and in your own Google Drive when you sync.
- Account data: in our database (MongoDB Atlas), used by our server on Vercel (Mumbai, India region).
- All traffic between the app and the server uses HTTPS.
- In the app, the session and vault key are kept in Android's secure storage.
How long we keep it
- Account and balance data: for as long as your account exists.
- Security event log: 30 days.
- Records of deleted notes and of each sync: 30 days.
Your choices
- Turn cloud sync off in Settings. Your notes then stay on your phone only.
- Use Settings > Danger Zone to delete the cloud copies (this deletes the note files from your Drive and their metadata from our server) or the notes on your phone.
- Remove Atomic Notes' access to your Google account at any time at myaccount.google.com/permissions.
- To delete your account, or to get a copy of the data we hold about you, contact us (below). We delete account data within 30 days of a verified request.
Service providers
- Google: sign-in and Google Drive storage.
- Vercel: hosting for the server and this website.
- MongoDB Atlas: the database for account data.
If you choose to support the project, the payment is handled by the platform you use, under its own policies. We only use the account email you send us to add your supporter reward.
Children
Atomic Notes is not directed at children under 13, and we do not knowingly collect their information.
Changes to this policy
We will update the date at the top when this policy changes, and announce significant changes in the app's notification center.
Contact
Questions or requests: reach the developer through github.com/DevBehindYou. The app's source code, including how it handles data, is public to read at Atomic-Notes-App-V0.2.