Totus Secure Notes · Firebase Hosting · Built 2026-07-27

Privacy Policy — Totus Secure Notes

Effective date: June 19, 2026

Last updated: July 18, 2026

App name: Totus Secure Notes

Developer: Totus Life (totuslife7@gmail.com)

Package / Bundle ID: com.totuslife.TotusSecureNotes

Public URL: https://totus--notes.web.app/privacy

Summary

Totus Secure Notes is a local-first, encrypted notes app. Your note content is stored on your device and is not uploaded to our servers. We do not operate a cloud account system for your notes.

This Privacy Policy comprehensively discloses how the app accesses, collects, uses, handles, and shares data, as required by Google Play User Data policies and applicable privacy laws.

Related policies: Terms · Data deletion · Permissions · Data safety summary

1. Developer contact

FieldValue
DeveloperTotus Life
AppTotus Secure Notes
Emailtotuslife7@gmail.com
GitHubhttps://github.com/totuslife7-arch/totus-secure-notes

For privacy inquiries, email totuslife7@gmail.com. We aim to respond within 3–5 business days.

2. Information we do not collect

We do not collect, store, or sell on our own servers:

Your encrypted vault exists only on your device unless you export or share an encrypted backup file.

We do not sell personal or sensitive user data.

3. Data stored on your device

DataPurposeEncrypted
Note vaultApp functionalityYes (AES-256-GCM; Argon2id + envelope v1.2.4+)
Master password verifierUnlock vaultYes (hashed verifier only)
Biometric unlock preferenceConvenienceDevice secure store
Trip plans, addresses, GPS logsMileage reimbursementYes
Maps API keys (Pro, optional)Route planningSecureStore
IAP entitlementsPro / Template Studio / Template AI accessSecureStore
Template AI model weights (Pro, optional)On-device field suggestionsLocal file (not bundled in APK)
Voice memo recordings (optional)Encrypted note attachmentsYes (vault attachment store)
.totus web vault export (optional)Read-only desktop viewerEncrypted bundle; user-controlled
App settings & audit logSecurity & preferencesYes (audit log encrypted)

You are responsible for your device passcode, backups, and exported .enc files.

4. Third-party services

4.1 App stores

Google Play and Apple App Store process downloads, updates, and purchases under their own privacy policies.

4.2 In-app purchases

Purchases are processed by Google Play Billing and Apple StoreKit. We receive purchase status and product identifiers on your device only. Payment card data is handled by the store. See Ads & monetization policy.

4.3 Advertising (free tier)

v1.2.18: Banner ads are disabled until production AdMob App IDs are configured. When enabled, the free tier may show banner ads via Google AdMob. AdMob may collect device/advertising identifiers and ad interaction data per Google’s policies. Pro and paid tiers remove ads.

You can limit ad personalization in Android Settings → Google → Ads, or iOS Limit Ad Tracking.

4.4 Firebase (Google)

ServiceDataPurpose
HostingNone from app usersPublic policy pages
FirestorePolicy version metadata onlyIn-app “check for updates”
AnalyticsScreen names, aggregated usageApp improvement — no note content
CrashlyticsCrash stack traces, device modelStability — no note content

See Google Privacy Policy.

4.5 Location and maps (optional)

Denying location permission disables GPS mileage; notes still work.

4.6 Template AI (Pro Lifetime, optional)

Template AI integrates a third-party open-source language model (SmolLM2-360M) downloaded from Hugging Face (~240 MB) after you provide in-app consent. Inference runs on-device only via llama.rn. Text you submit for AI assist is processed locally and is not sent to Totus Life or Hugging Face at inference time. We use the model only to suggest template fields or note formatting; you must review every suggestion before saving. You may delete the model file in Settings → Totus Assist.

Full details: On-device AI policy · [Technical documentation](./ON_DEVICE_AI.md)

4.7 Web vault viewer (optional)

You may export a .totus bundle from Settings for use with the read-only web vault viewer at /vault. Decryption happens in your browser only. We do not receive or host your vault contents. Delete exported bundles when no longer needed.

4.8 Google Play Integrity (optional, future)

We may use Google Play Integrity API on-device to verify app licensing. Integrity verdicts (e.g. LICENSED, PLAY_RECOGNIZED) are used locally to protect paid features. We do not upload integrity tokens to Totus Life servers.

5. Prominent disclosures (in-app)

Per Google Play requirements, the app shows runtime permission dialogs before accessing:

Ads and IAP are disclosed in Settings and store listings. See Permissions policy.

6. Encryption and security

Notes use AES-256-GCM with Argon2id key derivation and envelope encryption (v1.2.4+). We cannot decrypt your vault without your master password. See Security policy.

7. Export, import, and sharing

When you export a vault or use system share sheets, data leaves the app under your control. Exported files remain encrypted unless you decrypt them elsewhere.

.totus bundles for the web vault viewer contain encrypted notes and templates. Treat them like sensitive backups. The web viewer decrypts locally in your browser and does not upload contents to Totus Life.

8. Children’s privacy

The app is not directed at children under 13 (or under 16 in the EEA where applicable). We do not knowingly collect personal information from children. See Target audience policy.

9. Your rights and data deletion

Because we do not host your notes:

Full instructions: Data deletion policy.

10. Data retention

DataRetention
On-device vaultUntil you delete the app or clear data
Firebase Analytics/CrashlyticsPer Google retention (typically up to 14 months for analytics)
Support emailsAs long as needed to resolve your request
Store purchase recordsPer Google/Apple policies

11. International users

Device and store services may process data in other countries per their policies. We do not transfer note content internationally because it stays on your device.

12. Changes

We update this policy when features change. The “Last updated” date will change. Material changes may also appear in the app Settings → Check for policy updates.

13. Contact

Email: totuslife7@gmail.com

*This document is hosted at a stable public URL for Google Play Console and Apple App Store Connect.*

All policies · totuslife7@gmail.com