Privacy Policy
Effective 17 September 2026 · Version 1.1
Properpad is built on a simple idea: what you write is yours. This policy explains, in plain language, what stays on your device, the small amount of technical data we do receive, and the choices you have.
1. About this policy
This Privacy Policy explains how Aavitech LLC ("Aavitech", "we", "us" or "our") handles information in connection with Properpad, our note-taking application for Android and iOS (the "App"), and the web pages on which we publish this policy.
Aavitech LLC is the developer and publisher of the App. To the extent we process any personal data, we are the "controller" for the purposes of the EU and UK General Data Protection Regulation ("GDPR") and the "Data Fiduciary" for the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Please read this policy together with our Terms of Use. By installing or using the App, you acknowledge that you have read this policy. Where the law requires your consent for a particular activity, we ask for it separately and do not rely on this notice alone.
Key terms —
Personal data: information relating to an identified or identifiable individual, including "personal information" as defined by US state privacy laws.
Device data: everything you create or store in the App; it stays on your device and is not collected by us.
Diagnostic data: limited technical information, free of note content, that the App sends to help us keep it stable and improve it.
2. Data that stays on your device
In short: what you write in Properpad is stored on your phone, not with us.
Properpad is built to work offline. Everything you create is saved automatically to a database and file store inside the App's private, sandboxed storage on your device. None of it is transmitted to Aavitech. We operate no server, cloud service or account system that receives it.
| Data | What it includes | Where it lives |
| Note content | Titles, text, headings and formatting, checklists and links | Your device only |
| Organization | Folders, tags, and pinned, archived and trashed states | Your device only |
| Attachments | Photos you take or choose, and voice recordings you make | Your device only |
| Preferences | Theme, list layout and other settings | Your device only |
| App-lock PIN | Never stored as the PIN itself, only as a salted, one-way hash (PBKDF2-HMAC-SHA256) | Your device only |
| Search index | Built locally so search works without a connection | Your device only |
| Biometric data | Fingerprint and face data are held and checked by your device's operating system. The App only learns whether the check succeeded. | Never accessed by the App |
We never receive your notes. So we can't read them, analyze them, use them to train artificial-intelligence models, show you ads based on them, or disclose them to anyone, including in response to a legal request. We don't have them.
Notes you delete move to Trash. They are permanently erased automatically after 30 days, or sooner if you empty the Trash. Uninstalling the App or clearing its storage deletes all of this data from your device, except for any backups or exports you have saved elsewhere.
3. Information we collect
In short: we collect only technical diagnostics and usage statistics that contain no note content, plus anything you choose to email us.
The App uses two services from Google's Firebase platform: one helps us keep Properpad stable, the other shows us which features people use overall. If your version of the App does not include these services, or you have turned them off, the data below is not collected.
3.1 Crash reports: Firebase Crashlytics. When the App crashes or runs into a serious error, Crashlytics sends a report that may include: the technical trace of the error and the name of the operation that failed; device model, operating system and version, App version and build, screen orientation, free memory and disk space, and whether the device appears to be rooted or jailbroken; the date and time of the event; and a random identifier that Firebase generates for this installation of the App.
3.2 Usage statistics: Google Analytics for Firebase. Analytics shows us, in aggregate, how the App is used. It may collect feature events (such as App opened, note created or edited, checklist created, note pinned or archived, search used, attachment added, audio recorded, backup created, export performed — recording only that something happened, never what it contained); automatic events (first open, session start and length, screens viewed, updates, and Android uninstalls); device and context (device model and category, OS version, App version, language, and approximate location worked out from your IP address, which we don't receive); and a random app-instance identifier.
What diagnostics never contain: note titles, text or checklist items; photos, voice recordings or any other attachment content; folder names, tags, file names or search terms; your PIN, its hash, or any biometric data; your name, email address, phone number or contacts; advertising identifiers (we configure Firebase not to collect them); or precise (GPS) location.
3.3 Information you choose to send us. The feedback option in the App opens your own email app with a message addressed to us; nothing is sent unless you send it. If you rate or review the App on the App Store or Google Play, Apple or Google handle the review. If you email us for any reason, we use your details to reply.
3.4 Update checks. On iOS, the App queries Apple's public App Store lookup service, sending only the App's own identifier and region. On Android, the Play Store app checks for and installs updates through Google's In-App Updates service.
3.5 Information from app stores. Apple and Google give us aggregated, de-identified reports such as download counts, ratings, and crash and performance statistics. We don't receive your name, email address or payment details from them.
4. Device permissions
In short: Properpad asks for a permission only when you use a feature that needs it.
| Permission | Why it's used | When it's requested |
| Camera | To take a photo and attach it to a note | Only when you choose to take a photo |
| Photos & media | To pick an existing image to attach | Only when you choose a photo |
| Microphone | To record voice notes | Only when you start a recording |
| Face ID, Touch ID or fingerprint | To unlock the App when app lock is on | Only when you enable biometric unlock |
| Network access | For update checks and, where included, crash reports and usage statistics | Standard on both platforms; you aren't asked |
You can grant, deny or withdraw any permission at any time in your device's settings. Denying one disables only the feature that needs it; the rest of the App keeps working.
5. When data leaves your device
In short: your content leaves your device only when you send it, or through your device's own features. The service it goes to is responsible for it from there.
5.1 Backups you create. An Properpad backup (a .npbk file) is a complete copy of your notes, folders, tags and attachments, packaged as a standard ZIP archive that is
not encrypted. You choose where to save it. Anyone who gets hold of a backup file can open it and read what's inside. Your app-lock PIN is not included. Once a backup leaves the App, you and the service you chose are responsible for keeping it safe.
5.2 PDF export and sharing. When you export a note as a PDF or share it, the App prepares the file and passes it to your operating system's share sheet. The App deletes its temporary export files automatically.
5.3 Sharing into Properpad. On Android, content you share into Properpad from another app is saved as a new note on your device.
5.4 Home-screen widgets. On Android, an Properpad widget can show the titles of your pinned and recent notes on your home screen. While app lock is on, the App does not give note titles to widgets.
5.5 Links and email. Tapping a link opens it in your browser under that site's own practices. The feedback option opens your email app under its own terms.
5.6 Operating-system backups and device transfers. Android and iOS may include the App's data in their own device backups (such as Google's Android backup or Apple's iCloud Backup) and device-to-device transfers, depending on your settings. Aavitech cannot access them.
6. How we use information
In short: we use it to keep the App working, fix problems, improve features, reply to you and meet our legal obligations. Nothing else. This includes stability and reliability, product improvement, telling you about updates, support, security and integrity, and legal compliance. We do not use information for advertising, profiling, automated decisions, or to train artificial-intelligence models, and we do not sell it.
7. Legal bases for processing
Where the law requires a legal basis for using personal data: for crash reporting and usage statistics, our legitimate interest in a stable, secure App or your consent where the law requires it (in India, always your consent, which you can withdraw at any time); for replying to you, our legitimate interest or the data you provided voluntarily; for legal compliance, compliance with applicable law.
8. Sharing & disclosure
In short: we don't sell your data. We share limited diagnostic data only with the providers who process it for us — Google, through Firebase, under contract terms that limit how it may be used. We may also disclose limited information where the law, a court order or a valid request from a public authority requires it; as part of a merger, acquisition or sale of assets; or at your direction. We do not sell, rent or trade personal data, and we do not "share" it for cross-context behavioral advertising.
9. Third-party services
In short: Firebase Crashlytics and Google Analytics for Firebase (crash reports and usage statistics), Google Play In-App Updates on Android, and Apple's App Store lookup service on iOS, are the only outside services the App uses. It contains no advertising SDKs, social-media SDKs or data brokers. These pages load no third-party scripts, fonts or trackers, and set no cookies.
10. International transfers
Aavitech is based in India. Google processes Firebase data in the United States and other countries where Google and its sub-processors operate. Transfers from the EEA, UK or Switzerland are protected by appropriate safeguards such as Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Transfers of data about users in India follow the DPDP Act.
11. Data retention
Notes, attachments and settings stay on your device until you delete them or uninstall the App. Notes in Trash are permanently deleted after 30 days. Crash reports are kept up to 90 days, usage statistics up to 14 months at the event level. Feedback and support emails are kept as long as needed, usually no more than 24 months. Backups and exports you create are kept wherever you keep them; we have no control over these files.
12. Security
In short: your notes are protected by your device's security, and the parts of the App that talk to us never handle them. Notes and attachments live in the App's private, sandboxed storage. Your app-lock PIN is never stored, only a salted PBKDF2-HMAC-SHA256 hash. Widgets receive no note titles while app lock is on. Network requests use HTTPS (TLS).
App lock is a privacy screen, not encryption. It stops casual access to the App, but does not encrypt the note database and cannot protect your data from someone with full access to your unlocked device, a compromised device, or anyone holding your backup files. If you forget your PIN, we cannot recover or reset it, because we never receive it.
No method of storage or transmission is completely secure. You are responsible for securing your device and protecting any backups you create.
13. Your choices & controls
You can turn off usage statistics and crash reporting at any time in Settings › Privacy. You can grant or withdraw camera, photo, microphone and biometric access in your device settings. You can delete notes, remove attachments and empty the Trash at any time. Uninstalling the App or clearing its storage deletes all App data and resets the diagnostic identifiers. You can remove Properpad widgets from your home screen, and manage device backups in your device settings.
14. Your privacy rights
Because the App needs no account and we never receive your notes, almost all of your data is already in your hands.
India (DPDP Act 2023, IT Act 2000): you may request a summary of personal data we process about you, have it corrected or erased, withdraw consent at any time, have grievances addressed by our Grievance Officer and, failing that, complain to the Data Protection Board of India, and nominate another person to exercise your rights if you die or become incapacitated.
EEA, UK and Switzerland (GDPR/UK GDPR/FADP): you may access, correct, erase, restrict and port your personal data, object to processing based on legitimate interests, withdraw consent, and complain to your local data-protection authority.
United States (CCPA/CPRA and other state laws): in the past 12 months we have collected identifiers (random app-instance and installation identifiers, plus your email if you contact us), internet/network activity (in-App feature events and crash data), and approximate geolocation. We do not sell or share personal information. You may have the right to know, access, delete and correct your personal information, opt out of sale/sharing/targeted advertising (we do none of these), and be free from discrimination for exercising your rights.
Everywhere else: you can contact us with questions or requests, and we will respond as applicable law requires, including Brazil's LGPD, Canada's PIPEDA and Australia's Privacy Act where they apply.
To make a request, email
[email protected] with the subject "Privacy request". We may need to verify your request. We respond within the time the law allows, usually within 30 days.
15. Children
Properpad is a general-audience productivity app. It is not directed at children under 13, and we do not knowingly collect personal data from children under 13, or the higher minimum age that applies in your country. Under India's DPDP Act, anyone under 18 is a child and should use the App only with the consent and supervision of a parent or lawful guardian. We do not track, monitor or target advertising at children. If you believe a child has given us personal data without the right consent, contact us and we will delete it.
16. Future features
We may later add features such as note reminders, optional cloud sync, accounts or AI assistance. If a new feature would send note content off your device, we will update this policy before it launches and ask for your explicit consent before any of your note content is uploaded.
17. Changes to this policy
We may update this policy from time to time, for example when we add features, change service providers, or when the law changes. We will post the updated version at this address and change the version and date at the top. If a change is material, we will give reasonable notice in advance. This policy is governed by the laws of India, and the courts at Ahmedabad, Gujarat, India have jurisdiction, subject to any mandatory rights you have under the laws of the country where you live.
If you have a question, request or complaint about this policy or your personal data, contact us. Our Grievance Officer, appointed under the Information Technology Act, 2000 and the DPDP Act, can be reached at the same address.
Data Fiduciary & Publisher:
Aavitech LLC
Email:
[email protected]
Location: Ahmedabad, Gujarat, India
Response time: acknowledged within 7 days, resolved within 30