Dotnote Privacy Policy
Last updated: 2 October 2026 (previous version: 26 September 2026)
This policy explains what happens to your information when you use Dotnote (Android package com.elif.notes), a note-taking app published on Google Play by Adem Batur (Elif Apps) ("we", "us"). Contact: elifapps.studio@gmail.com.
In short
- Your notes stay on your device. Dotnote has no server of its own and no Dotnote account. We never receive your notes, drawings, recordings, photos, videos, files, reminders, settings or profile details.
- Sign in with Google is required to use the Android app. On the first screen you choose a Google account. Google then gives Dotnote that account's name, email address and profile photo address. Dotnote keeps them only on this device and shows them in your Profile. They are not sent to us, and signing in does not create a Dotnote account anywhere. The web version of Dotnote does not ask for sign-in yet.
- Your profile name, phone number and photo stay on this device. The current version does not verify phone numbers: no SMS or code is ever sent.
- Google Drive copy is optional. If you switch it on, your notes go from your device straight into a hidden folder of your own Google Drive. We cannot see or open it.
- The current version shows no ads and sells nothing. Every feature is free. The ad and purchase libraries are part of the app but are not started.
- Nothing is sent to us. We do not run analytics or crash reporting, and we do not sell personal data. The only things that can leave your device are listed in section 3.
1. Data stored only on your device
Everything you create in Dotnote is stored in the app's private storage on your device:
- notes, pages, handwriting and drawings, text, checklists and tables;
- audio clips, videos, photos, GIFs, scanned pages and attached files;
- folders, tags, colours, covers, templates, trash and version history;
- reminders, including the place you pick for a location reminder;
- your Google sign-in: the name, email address and profile photo address of the Google account you signed in with (see 3.1);
- your profile details: the name you confirm, the phone number if you enter one, the profile photo you pick, and the email address of the Google account those details belong to (see 3.2);
- settings, the note/app lock PIN (stored only as a salted hash) and the lock state.
This data is not sent to us or to any third party. It is removed when you delete it in the app (and then from the trash), when you clear the app's storage, or when you uninstall the app. Uninstalling deletes your notes permanently unless you made a backup (Settings → Backup → Export backup file, or the Google Drive copy in Profile). The backup file and the Drive copy contain your notes and media, not your profile details.
If Android's own device backup is switched on for your Google account, Android may also save and restore app data, which can include your notes and profile details. That backup is run by Android and Google under Google's terms; Dotnote does not access it.
2. Permissions and what they are used for
Dotnote asks for a permission only when you use the feature that needs it. You can refuse or withdraw any of them in Android settings; the rest of the app keeps working.
| Permission | Used for | Leaves the device? |
|---|---|---|
| Microphone | Recording audio clips on a page (a recording can go on with the screen off; Android then shows a notification), recording video with sound, dictation | No (dictation: see 3.4) |
| Camera | Taking a photo or video, scanning a document, scanning a QR code to receive notes, taking a profile photo | No |
| Photos and files | You pick items with the Android photo picker or file picker; Dotnote gets only the items you choose and copies them into the note (or, for a profile photo, into its private folder). On Android 12 and older, storage read access may be requested only to open a file you choose | No |
| Notifications, exact alarms, run at startup | Showing reminders on time, also after the device restarts | No |
| Location (approximate and precise, only while the app is open) | Location reminders: the reminder fires when you open the app near the place you chose | No |
| Biometrics | Unlocking locked notes or the app with your fingerprint or face. Android checks the biometric; Dotnote never sees it | No |
| Network access, Wi-Fi state | Sign in with Google, the Google Drive copy, showing your Google profile photo, sending notes to your other device over Wi-Fi, the list of other Elif Apps | Only as described in section 3 |
Dotnote does not ask for background location, contacts, the accounts on your device, call logs, phone state, SMS or your device calendar. Google sign-in uses Google's own account chooser, so Dotnote never needs access to the list of accounts on your device.
3. Services that can receive data
3.1 Sign in with Google (required in the Android app)
The Android app asks you to sign in with Google on its first screen, before you can open or write notes. Any Google account can be used, and you need an internet connection for the sign-in. The web version of Dotnote does not ask for sign-in yet.
- What happens: Google's own sign-in screen runs on your device (Google Play services). After you choose an account, Google gives Dotnote the account's name, email address and profile photo address. Dotnote does not receive your Google password, and it cannot see your other Google data. Google's privacy policy applies to the sign-in: https://policies.google.com/privacy.
- What Dotnote does with it: it keeps the name, email address and photo address on the device and shows them in your Profile and on the avatar. It uses the email address to know which Google account is signed in on this device and which account your profile details and the Drive copy belong to. To show your Google profile photo, the app loads the picture from Google's servers.
- What Dotnote does not do: it does not send your name, email, photo or any sign-in token to us. Signing in does not create a Dotnote account anywhere; there is no server of ours that knows you.
- Connection check: to tell "offline" from a sign-in problem, the app may send an empty request to Google's connectivity check (www.gstatic.com/generate_204) when a sign-in fails or Google reports no account on the device. It carries no personal data; like any internet request, it shows your IP address to Google.
- Permissions you give Google for Dotnote: your basic profile (name, email, photo) when you sign in; and, only when you switch on the Drive copy, access to Dotnote's own hidden app folder in your Google Drive (
drive.appdata). Dotnote cannot see or change your other Drive files. - Sign out: Profile → Google account → Sign out. Your notes and profile details stay on the device. Because sign-in is required, Dotnote then shows the sign-in screen again before you can open your notes.
- Delete account: Profile → Google account → Delete account. Dotnote removes its access to your Google account, deletes the name, email address, phone number and photo it kept on the device, and signs you out; the sign-in screen comes back. Your notes are not deleted: they stay on the device until you delete them (see section 7).
- Remove Dotnote's access to your Google account: open https://myaccount.google.com/permissions (Google Account → Security → Your connections to third-party apps & services) → Dotnote → Delete all connections (wording may vary). Your Google account itself is managed by Google and is not affected.
- Delete what Dotnote has from your Google account: see section 7.
3.2 Your profile details (name, phone number, photo)
In Profile you can confirm a name, enter a phone number and pick a profile photo. All three are optional and stored only on your device.
- Name: your Google name is suggested; the name you confirm is shown in your Profile.
- Phone number: if you enter one, it is saved on the device and shown in your Profile. The current version has no phone verification: no SMS and no code are sent, and the number is not sent to us, to Google or to anyone else. If a future version adds verification by SMS, we will update this policy first and say which provider receives the number.
- Profile photo: you pick a picture with the Android photo picker or take one with the camera, then crop it. Dotnote saves only the cropped picture in its private folder on this device. It is not uploaded, and it replaces the Google photo only on this device.
- You can change or clear the name and phone number under Profile → Edit profile, and remove the photo by tapping it → Remove photo.
3.3 Google Drive copy (optional, "Keep a copy in my Google Drive")
If you switch on Profile → Keep a copy in my Google Drive, Dotnote copies your notes, pages, ink, recordings, photos, videos, files, folders and tags into the hidden app data folder of your own Google Drive (permission drive.appdata). It also stores a small file per device with the device name, a random device ID, the time of the last copy and the list and size of the copied notes, so that you can pick which copy to restore.
- When: while it is switched on, automatically when you open the app or leave it (at most every 10 minutes when you leave it, every hour when you open it), and whenever you tap Copy now. Only what changed is sent.
- Where it goes: directly from your device to your Google account, over an encrypted connection (HTTPS). It never passes through a server of ours, and we cannot access it. It counts against your own Google Drive storage, and Google Drive's terms and privacy policy apply to it.
- Restore: Restore from my Google Drive in the same card brings a copy back to this or another device signed in with the same Google account.
- Delete the copy: switch the copy off in Profile, then open Google Drive on the web → Settings (gear icon) → Manage apps → Dotnote → Options → Delete hidden app data. Removing Dotnote's access (3.1) stops new copies but does not delete the copy that is already there.
In the current version the Drive copy is part of the Pro plan, which every user has for free.
3.4 Text recognition and document scanning (Google ML Kit)
Recognising text in photos and scanned pages, and reading QR codes, happens on your device with Google ML Kit. Your images and the recognised text are not uploaded. Like all ML Kit apps, the library may send Google technical diagnostics: device model and Android version, app package name and version, performance metrics (such as processing time), API settings and a per-installation identifier that is not meant to identify you. Google uses them to maintain the library. See the Google Privacy Policy: https://policies.google.com/privacy.
3.5 Dictation
Dictation uses the speech-recognition service installed on your device (usually Google's). Depending on your device and settings, that service may process your voice on the provider's servers under its own privacy policy. Dotnote only receives the resulting text and stores it in your note. Dictation only runs while you have it switched on.
3.6 Sending notes to another device (QR code and Wi-Fi)
When you choose to send notes or folders, Dotnote opens a temporary transfer on your local Wi-Fi network and shows a QR code containing a one-time link. The receiving device downloads the notes directly from your device; nothing passes through a server of ours or anyone else's. The link works only during that transfer. The transfer uses your local network without extra encryption, so use it on a network you trust. Locked notes are sent unlocked so the other device can open them.
3.7 Sharing, exporting, printing, links
When you share or export a note (PDF, Word, Markdown, image, .elifnote and others), print it, or open a link, the data goes to the app, printer or website you choose, under that party's own policy.
3.8 Other Elif Apps list
Dotnote may download a small public list of other Elif Apps from our website elifapps.com (hosted by Cloudflare) about once a day. The request contains no personal data; like any web request it reveals your IP address to Cloudflare, which hosts the file. See https://www.cloudflare.com/privacypolicy/.
3.9 Advertising (Google AdMob): not in the current version
The current version shows no ads. The Google Mobile Ads SDK is part of the app, but Dotnote does not start it, so no ad is requested or shown. A future free version may show ads; we will update this policy before that version is released. Then no ads will be shown on the first launch, while you write or draw, or to users of a paid plan or "Remove ads". When ads are shown, the Google Mobile Ads SDK may collect and share with Google:
- your IP address (which may be used to estimate your approximate location);
- the advertising ID, app set ID and similar device identifiers;
- ad interactions (app launches, taps, ad views);
- diagnostics (ad load times, performance).
This data is used for advertising, measurement, analytics and fraud prevention. In the EEA, the UK and Switzerland, Google's consent form (User Messaging Platform) will ask for your choice before personalised ads, and you will be able to change it in Dotnote under Settings → Privacy options (ads). You can reset or delete your advertising ID in Android settings (Settings → Privacy → Ads). More: https://policies.google.com/technologies/partner-sites and https://policies.google.com/privacy.
3.10 Purchases (Google Play Billing and RevenueCat): not in the current version
Nothing can be bought in the current version; RevenueCat is not contacted. When paid plans (such as Pro) or "Remove ads" are offered in a future version, they will be paid through Google Play, and we will never see your card or payment details. To confirm a purchase and unlock it on your devices, the app will use RevenueCat, which receives the purchase information: product, purchase token and order ID, purchase and renewal dates, price and currency, store country, and a random app-user ID created by RevenueCat (not your name or email). RevenueCat processes this data on our behalf. See https://www.revenuecat.com/privacy and the Google Privacy Policy.
4. What we do not do
- No Dotnote account, and no server of ours that stores your content or your profile. Signing in with Google is required in the Android app, but it uses your Google account; it does not create an account with us.
- We do not collect phone numbers and do not send SMS.
- No analytics or crash reporting of our own; no tracking across other companies' apps by us.
- We do not sell or rent personal data.
5. Legal bases (EEA/UK) and Turkish law (KVKK)
Where the GDPR, UK GDPR or the Turkish Personal Data Protection Law No. 6698 (KVKK) applies, the processing described above relies on: performing the service you ask for (Google sign-in, the Drive copy and the transfers you start, which run on your device and in your own Google account; purchases, when offered), your consent (personalised ads, when offered, collected through the consent form), and legitimate interests (keeping the app and its libraries working, fraud prevention, non-personalised ads when offered). Google (and, when purchases are offered, RevenueCat) may process data outside your country, including in the United States, under their own safeguards.
6. How long data is kept
- Content and profile details on your device: until you delete or change them, clear the app's storage or uninstall the app.
- Google sign-in: until you sign out or remove Dotnote's access in your Google account.
- Google Drive copy: until you delete it from your Drive (see 3.3).
- ML Kit diagnostics: according to Google's retention policies.
- When offered in a future version: RevenueCat purchase records as long as needed to provide your purchases and meet legal (for example tax) obligations; AdMob data according to Google's retention policies.
7. Your choices and rights, and data deletion
The Android app requires Sign in with Google, but signing in does not create an account with us. Dotnote has no server, so there is no Dotnote account for us to delete, and we hold no copy of your notes, your profile or your Google sign-in. Everything Dotnote has about you is on your device and, only if you switched on the Drive copy, in your own Google Drive. To delete your data:
- Delete account in the app: Profile → Google account → Delete account (see 3.1). It removes Dotnote's access to your Google account and the profile details on the device, and signs you out. Your notes stay until you delete them (next point).
- Notes: delete them in the app and empty the trash.
- Profile details: Profile → Edit profile to change or clear the name and phone number; tap the photo → Remove photo.
- Google sign-in: Profile → Google account → Sign out (Dotnote then shows the sign-in screen again; your notes stay on the device until you delete them), and remove Dotnote's access at https://myaccount.google.com/permissions (see 3.1).
- Google Drive copy: delete it as described in 3.3.
- Everything on the device at once: Android Settings → Apps → Dotnote → Storage → Clear storage (delete app data), or uninstall the app. This removes your notes, media, profile details, the Google sign-in details kept by Dotnote and settings. Export a backup first if you want to keep your notes.
- Without the app (for example after you uninstalled it): remove Dotnote's access at https://myaccount.google.com/permissions and delete the Drive copy on the Google Drive website as described in 3.3. Uninstalling has already removed everything Dotnote kept on the device. You can also write to elifapps.studio@gmail.com from any address; since we hold no data about you, we will confirm that and explain these steps.
- Ads (when offered): change consent in Settings → Privacy options (ads); reset or delete the advertising ID in Android settings; a paid plan or "Remove ads" turns ads off.
- Purchase data (when purchases are offered): email elifapps.studio@gmail.com from any address with your Google Play order ID (starts with "GPA.") and we will ask RevenueCat to delete the related records, except what we must keep by law.
- You may request access to, correction or deletion of personal data we control, object to processing, or complain to your data protection authority (in Türkiye: KVKK Kurumu). Write to elifapps.studio@gmail.com; we answer within 30 days.
8. Children
Dotnote is not directed at children under 13 and we do not knowingly collect personal data from children. If you believe a child has provided personal data through the app, contact us and we will delete what we can.
9. Security
Your content and profile details are kept in the app's private storage, which other apps cannot read. Locked notes are protected by a PIN or biometrics. Connections to Google (sign-in, Google Drive, ML Kit) use encryption (HTTPS/TLS). The Wi-Fi transfer between your devices stays on your local network and is not encrypted (see 3.6). No method of storage or transfer is completely secure; keep backups of important notes.
10. Changes
We will update this page when the app's handling of data changes and change the date at the top. Important changes will also be shown in the app or in the store listing.
11. Contact
Data controller (KVKK / GDPR): Adem Batur, an individual developer in Türkiye who publishes apps as Elif Apps.
Adem Batur (Elif Apps) — elifapps.studio@gmail.com