Legal and product privacy

Privacy Policy

This policy explains how the NotiRecall Android app accesses, uses, protects, retains, and deletes notification and device data.

Effective: August 25, 2026Applies to Android 0.1.xContact: privacy@notirecall.com

Summary

NotiRecall is a local notification-recall app. After you make an explicit in-app notification-data choice, separately enable Android Notification Access, and enable a source, NotiRecall can save eligible future notification snapshots in encrypted storage on your device. It does not recover earlier notifications.

The current release has no NotiRecall account, advertising, analytics, notification-content upload, cloud sync, export or sharing feature, automatic crash reporting, or automatic support attachment.

Its production Android manifest has no Internet permission. Notification data remains on the device unless you independently type or share information through another app.

Data NotiRecall processes on your device

When you have accepted the current disclosure and enabled Android Notification Access, Android may expose notification information even while NotiRecall is not open. For sources you enable, NotiRecall may process and retain:

  • Source-app identity and display label.
  • Notification identifiers and posted, captured, and removed times.
  • Title, text or body, summary, conversation label, sender labels, and structured message text that Android exposes.
  • Notification style and bounded revision or classification metadata.
  • Content-free capture-health, retention, consent, and source-choice state.

For a disabled or newly encountered source, NotiRecall retains only the minimum protected source metadata needed to display and enforce your choice. It does not retain that source’s notification title, body, or revisions.

NotiRecall does not query contacts, call logs, SMS databases, Android account records, or the broad installed-app inventory. It does not persist Android’s complete raw notification extras bundle.

How the data is used

Eligible notification data is used only for local app features: a short history, bounded revisions, notification detail, source filtering, protected local search, deletion, and capture-health evidence.

Likely one-time-code detection and source-sensitivity classification are best-effort safeguards. They can miss sensitive content and can reject ordinary numeric messages. Do not rely on NotiRecall as an authenticator or security record.

Group summaries and ongoing, foreground-service, or system-category notifications are excluded by the current capture policy. Source apps and Android settings may hide, mute, redact, replace, group, or never deliver content, so NotiRecall cannot promise a complete archive.

Transmission, collection, and sharing

The current app does not transmit notification, source, search, authentication, diagnostic, or device-derived data to the NotiRecall developer or third parties. No analytics, advertising, telemetry, account, HTTP client, or cloud SDK is included in the audited release runtime.

The in-app privacy and support actions hand one fixed, build-reviewed destination to an installed browser or email app. NotiRecall itself has no WebView or Internet permission.

The support action adds no attachment, message body, notification data, source data, search text, diagnostics, authentication result, or device identifier. It may prefill only a constant subject and public version/build identity. Anything you later choose to type into another app is controlled by you and that app’s privacy terms.

Local storage and security

Saved notification history, protected source metadata, and local search data are stored in a SQLCipher-encrypted database. The database secret is wrapped through Android Keystore-backed app storage. Content-free privacy and consent records are stored in app-private, backup-excluded files.

Ordinary app logs do not contain notification content, source identity, or search text. NotiRecall blocks screenshots and recent-app previews and excludes its UI from Android Autofill.

Optional App Lock requires supported Android device authentication before protected UI access. App Lock controls the UI session; it is separate from storage encryption and does not change Notification Access, source choices, or retention.

No security mechanism can guarantee protection against every compromised or unlocked device, operating-system vulnerability, or physical attack.

Retention and deletion

The current Free build offers one-day, three-day, or seven-day retention. Android may delay scheduled cleanup, so expiry is enforced in bounded background batches rather than at an exact wall-clock instant.

You can delete an individual notification, one source’s history, a selected age range, or all saved history. Disabling a source stops future eligible capture but does not silently erase existing history. Withdrawing notification-data consent stops future callback-derived processing but does not silently erase existing encrypted history.

Uninstalling NotiRecall removes its app-private data under Android’s normal app-removal behavior. Android backup and device-to-device transfer are disabled for all NotiRecall app-data domains.

Android access and permissions

Core capture uses Android’s user-controlled Notification Access screen. You can revoke that access at any time in Android Settings. NotiRecall reads the current Android state after you return instead of trusting a stored success flag.

The production app uses only the reviewed manifest boundary needed for local capture, restart recovery, bounded background work, and optional device authentication. It has no INTERNET, QUERY_ALL_PACKAGES, or production POST_NOTIFICATIONS permission.

Immediate self-verification is attempted only when the operating system already permits it. Otherwise, NotiRecall waits for the first real eligible notification instead of asking for notification-posting permission merely to manufacture a test.

Own-device use and children

NotiRecall is intended for notifications on a device you own or control and for your own accounts. It is not intended for covert monitoring, workplace surveillance, or access to another person’s accounts.

The product is not directed to children under 13.

Third-party software

The app includes AndroidX and Jetpack, Kotlin and kotlinx libraries, JetBrains annotations, JSpecify, Guava’s listenablefuture compatibility API, and SQLCipher, including SQLite and LibTomCrypt native provenance.

These components provide local app and runtime functionality. The audited build includes no third-party analytics, advertising, account, crash-upload, or network SDK. Exact release inventory and license texts are available in the app under Help & About → Open-source licenses.

Policy changes and contact

Material changes to data access, use, storage, sharing, retention, diagnostics, purchases, or online functionality require an updated disclosure and policy before the affected release is distributed.

For privacy questions, email privacy@notirecall.com. For product support, email support@notirecall.com.

NotiRecall is the product and operator named by this policy. The same operator identity and contact should be used in the Google Play listing.