Legal

Privacy Policy

Last Updated: May 21, 2026

Mehedi Hasan Shohag ("we," "our," or "us") operates the Slate Notes mobile application (the "App"). We are committed to protecting your privacy and securing your personal and note-taking data.

This Privacy Policy explains how data is collected, used, and safeguarded when you use our App. By downloading and using the App, you agree to the practices outlined in this policy.

1. Data Collection and Usage

We prioritize local-first data architecture. The type of information handled depends entirely on how you interact with the App's features.

A. Local Note Storage & Customization

  • Note Content: All text, lists, and content you write within the App are stored directly in a secure local database (sqflite) on your physical device.
  • App Customization: Your choices regarding note card layouts, patterns, custom fonts, and system themes (Light/Dark mode) are stored strictly on your local device.
  • Access: We have no access to your locally stored notes or UI customization options.

B. Security and Authentication Data

  • 4-Digit PIN & Security Questions: If you choose to lock the App via a 4-Digit PIN, the PIN code and answers to your security recovery questions are hashed and stored locally on your device. This data never leaves your device.
  • Biometric Authentication (Fingerprint): If you enable biometric verification, the authentication process is handled directly by your device's native OS secure subsystem. The App never accesses, views, or collects your fingerprint or biometric data.

C. Cloud Synchronization & Backup (Google Login)

  • Google Authentication: If you opt to use the online backup and synchronization feature, the App authenticates your identity using Google Sign-In. We collect your Google Email Address and a unique User ID token provided by Google to establish and secure your account.
  • Cloud Database Storage: When synchronization is active, your notes are transmitted securely to our cloud database. This data is protected; it is securely isolated and cannot be accessed by any other user. It is retrieved and rendered only when you successfully log into the App using the exact same Google account.

2. Data Transmission and Security

  • Encryption in Transit: All communications between the App and our cloud sync databases are strictly encrypted using industry-standard Transport Layer Security (TLS/HTTPS) protocols.
  • Access Restriction: Your cloud-hosted backup data is structurally isolated via access-control rules. No third parties or other users can query, view, or modify your stored notes.

3. Data Retention and Account Deletion

We believe you should have total control over your digital footprint.

  • Local Data: Uninstalling the App from your mobile device immediately and permanently purges all local SQLite records, customization profiles, and configuration data from your device storage.
  • Cloud Data & Account Deletion: If you have enabled cloud sync via Google Login, you have the right to delete your account at any time directly inside the App's Settings menu, or by contacting us via email at mehedi05739@gmail.com.
  • Scope of Deletion: Upon receiving an account deletion request, your user profile, Google authentication mapping tokens, and all synced cloud notes will be permanently and irreversibly wiped from our production cloud servers within 7 business days.

4. Third-Party Services

The App integrates the following third-party infrastructure components:

  • Google Sign-In API: Used solely to securely authenticate your account identity for the cloud backup system. This interaction is bound by the Google Privacy Policy.

5. Children's Privacy

Our App does not knowingly collect or solicit personal information from children under the age of 13. If you believe a child has initiated a cloud sync account containing personal data, please contact us immediately, and we will take immediate steps to delete that account from our server records.

6. Changes to This Privacy Policy

We may update our Privacy Policy periodically to reflect shifts in Google Play store compliance guidelines or app feature enhancements. We will notify you of any material changes by updating the "Last Updated" date at the top of this page.

7. Contact Us

If you have questions, feedback, or need assistance executing your right to account data deletion, contact us at:

Email: mehedi05739@gmail.com

Developer: Mehedi Hasan Shohag

ℹ️

Google Play Console "Data Safety" Section Help

When filling out the mandatory Data Safety Form inside your Google Play Console, use these exact parameters based on your app's architecture:

  • Data Collection: Mark Yes (because of the Google Sync functionality).
  • Data Encrypted in Transit: Mark Yes (assuming you use standard HTTPS endpoints to communicate with your cloud backend).
  • Account Deletion: Mark Yes, and provide a dedicated account deletion URL in your App's Settings.

Data Declared:

  • Personal Info → Email Address & User IDs: Declare this as Collected, Not Shared, and used for Account Management and App Functionality.
  • App Activity → User-Generated Content: Declare note content as Collected, Not Shared, and used for App Functionality / Cloud Backup.