Legal and product privacy

Privacy Policy

This policy explains how the NotiRecall Android app accesses, uses, protects, retains, and deletes notification and device data.

Last updated: September 20, 2026Applies to: NotiRecall for AndroidPublisher: RakshaLink LabsOperator: Mohan Gangahanumaiah

Summary

NotiRecall is a local notification-recall app. After you make an explicit in-app notification-data choice, separately enable Android Notification Access, and enable a source, NotiRecall can save eligible future notification snapshots in encrypted storage on your device. It does not recover earlier notifications.

NotiRecall has no product account, advertising, notification-content upload, cloud sync, export or sharing feature, automatic crash reporting, or automatic support attachment. Product analytics collection is disabled.

Notification history and search stay on your device. A Pro purchase, restore, or status check uses a separate, content-free online verification flow described below; it never includes notification, source-app, search, contact, or conversation data.

Who operates NotiRecall

NotiRecall is an Android application published on Google Play under the RakshaLink Labs developer identity and developed and operated by Mohan Gangahanumaiah. In this policy, “NotiRecall,” “we,” “us,” or “our” refers to Mohan Gangahanumaiah as the operator of the NotiRecall application.

Notification Access

Notification Access is a user-controlled Android setting. If you grant it, Android can provide NotiRecall with notifications and their updates even while NotiRecall is not open. NotiRecall stores eligible notification content only after you accept the in-app disclosure and enable the relevant source.

You can revoke Notification Access at any time in Android Settings. Revoking access stops future notification processing, but it does not silently delete history already stored on your device. Notifications posted before access and source capture were enabled cannot be recovered.

Data NotiRecall processes on your device

When you have accepted the current disclosure and enabled Android Notification Access, Android may expose notification information even while NotiRecall is not open. For sources you enable, NotiRecall may process and retain:

  • Source-app identity and display label.
  • Notification identifiers and posted, captured, and removed times.
  • Title, text or body, summary, conversation label, sender labels, and structured message text that Android exposes.
  • Notification style and bounded revision or classification metadata.
  • Content-free capture-health, retention, consent, and source-choice state.

NotiRecall may process message text that Android exposes through a notification from an SMS or messaging app you have enabled. It does not access the underlying SMS or messaging database.

NotiRecall does not query contacts, call logs, SMS databases, Android account records, or the broad installed-app inventory. It does not persist Android’s complete raw notification extras bundle.

Apps you choose and apps seen by NotiRecall

For a disabled or newly encountered source, NotiRecall retains only the minimum protected source metadata needed to display and enforce your choice. It does not retain that source’s notification title, body, or revisions.

From version 1.0.1, after you accept the updated disclosure and grant Notification Access, NotiRecall checks which apps have notifications currently in your tray. Discovery keeps app identity, an available app label, and discovery times in protected local storage. It does not inspect notification text or import existing tray messages into history. New unfamiliar tray sources require confirmation before enabling; your existing choices are preserved.

Version 1.0.1 also offers an optional Choose apps on this device entry. When you choose it, NotiRecall opens the app picker and looks up apps with a visible launcher entry in the current Android profile so you can select an app before it sends a notification. This limited lookup stays on your device. Unselected names and icons remain temporary for that view session and are discarded when you leave, background, or lock the app. Only an app you explicitly enable is added to protected source settings; later notification discovery merges with that choice. Sensitive-source confirmation and Free/Pro limits still apply. This lookup does not enable capture, import earlier messages, inspect other profiles, or send an app inventory anywhere.

Newly seen apps are not saved until you enable them. Turning a source off stops future eligible capture but does not silently erase its existing history.

Sensitive notifications and one-time-code safeguards

Likely one-time-code detection and source-sensitivity classification are best-effort safeguards. They can miss sensitive content and can reject ordinary numeric messages. Do not rely on NotiRecall as an authenticator, financial record, or security archive.

How the data is used

Eligible notification data is used only for local app features: a short history, bounded revisions, notification detail, source filtering, protected local search, deletion, and capture-health evidence.

Group summaries and ongoing, foreground-service, or system-category notifications are excluded from saved history by the current capture policy. Their app identities may still appear in discovery. Source apps and Android settings may hide, mute, redact, replace, group, or never deliver content, so NotiRecall cannot promise a complete archive.

Transmission, collection, and sharing

NotiRecall does not transmit notification title or text, saved history, source choices or source history, installed or discovered app inventory, search terms, contacts, conversation identity, app-lock authentication results, or capture diagnostics to the developer/operator or the entitlement service. Product analytics collection is disabled; including an Analytics SDK in the app does not enable collection.

To retrieve the current Google Play product listing and reconcile an existing one-time purchase, the Google Play Billing client may connect to Google Play when NotiRecall returns to the foreground. This Play-managed exchange is limited to the fixed NotiRecall product and package context and Google-controlled purchase context; NotiRecall supplies it with no notification, source, search, contact, conversation, or app-lock data. A Billing response alone never grants Pro.

When a completed NotiRecall Pro purchase must be verified during purchase, restore, status check, or reconciliation, the app sends a content-free entitlement request over encrypted HTTPS to a NotiRecall verification function hosted by Vercel. The request is limited to the Google Play purchase token, the fixed NotiRecall Pro product ID, the NotiRecall Android package name, and an encrypted Google Play Integrity token bound to a hash of those three purchase fields. The service uses Google’s Play Integrity API to check that the request came from a Play-recognized, licensed app on a device that meets the required integrity verdict, and uses the Google Play Developer API to check the exact product and current purchase state. It transiently checks the binding and state of the exact order ID returned by Google, requesting no buyer, price, tax, revenue, or order-history fields. If Google does not expose a retrievable order, it instead checks whether the exact purchase appears in Google’s recent voided-purchase records. The app does not submit an order ID, and the verifier does not retain the order or void list.

Google Play Integrity processes the request hash, app package, app version, signing certificate, Play license status, and device-attestation information for fraud and unauthorized-access prevention. NotiRecall does not use Integrity data to fingerprint, track, advertise to, or build a profile about a person or device.

The verification function is stateless: NotiRecall’s application code does not persist the request or response and does not log purchase tokens, Integrity tokens, Google responses, account or order data, IP addresses, or request bodies. It returns only a typed entitlement decision, a reason category where needed, and minimal verification/recheck timing. Vercel and Google necessarily process network and service data to host, secure, and perform these requests under their respective terms and retention practices.

The in-app privacy and support actions hand one fixed, build-reviewed destination to an installed browser or email app rather than loading or sending it inside NotiRecall.

The support action adds no attachment, message body, notification data, source data, search text, diagnostics, authentication result, or device identifier. It may prefill only a constant subject and public version/build identity. Anything you later choose to type into another app is controlled by you and that app’s privacy terms.

Local storage and security

Saved notification history, protected source metadata, and local search data are stored in a SQLCipher-encrypted database. The database secret is wrapped through Android Keystore-backed app storage. Content-free privacy and consent records are stored in app-private, backup-excluded files.

Ordinary app logs do not contain notification content, source identity, or search text. NotiRecall blocks screenshots and recent-app previews and excludes its UI from Android Autofill.

Optional App Lock requires supported Android device authentication before protected UI access. App Lock controls the UI session; it is separate from storage encryption and does not change Notification Access, source choices, or retention.

No security mechanism can guarantee protection against every compromised or unlocked device, operating-system vulnerability, or physical attack.

Retention and deletion

Free offers one-day, three-day, or seven-day retention. While a verified Pro entitlement is active, you can also choose 30-day, 90-day, or unlimited local retention. Unlimited means no age-based expiry; it does not override available device storage. A recently verified Pro entitlement can remain available offline for no more than seven days.

If Google Play and NotiRecall verify that Pro access ended, one fixed 30-day downgrade period preserves existing remembered apps and history while new Pro-only choices are paused. A valid restoration cancels the pending downgrade. Otherwise, at the deadline and after a fresh verification, you choose exactly three apps to keep if more than three are enabled, and history older than the Free seven-day limit is removed. Temporary network, Play, verifier, clock, or storage failures do not start or complete that downgrade.

Android may delay scheduled cleanup, so expiry is enforced in bounded background batches rather than at an exact wall-clock instant.

You can delete an individual notification, one source’s history, a selected age range, or all saved history. Disabling a source stops future eligible capture but does not silently erase existing history. Withdrawing notification-data consent stops notification processing and tray discovery but does not silently erase existing encrypted history.

Uninstalling NotiRecall removes its app-private data under Android’s normal app-removal behavior. Android backup and device-to-device transfer are disabled for all NotiRecall app-data domains.

Android access and permissions

Core capture uses Android’s user-controlled Notification Access screen. You can revoke that access at any time in Android Settings. NotiRecall reads the current Android state after you return instead of trusting a stored success flag.

The app requests only the Android access needed for local notification capture, restart recovery, bounded background work, optional device authentication, and Google Play purchase and integrity verification. Internet access is used for Google Play Billing, Play Integrity, and the content-free NotiRecall entitlement verifier; it is not used to upload notification history, searches, source history, or discovered app inventory. The app does not request broad installed-app access.

Own-device use and age eligibility

NotiRecall is intended for notifications on a device you own or control and for your own accounts. It is not intended for covert monitoring, workplace surveillance, or access to another person’s accounts.

NotiRecall is designed for users aged 18 and over and is not directed to children.

Website privacy

When you visit notirecall.com, Vercel, our hosting provider, may process standard technical request information such as your IP address, browser or user-agent information, requested path, request timestamp, approximate region, and technical logs needed to deliver, operate, and secure the website. Vercel handles that information under its Privacy Notice.

The public NotiRecall pages are static. The site also hosts the stateless app-entitlement verification function described above. Site code uses no account, form submission, advertising pixel, site analytics, cross-site behavioral tracking, cookies, remote fonts, or third-party browser scripts.

Third-party software

NotiRecall uses Android libraries for local application functionality and encrypted storage, Google Play Billing for purchases, and Google Play Integrity for request integrity and abuse prevention. Builds that include Google Analytics for Firebase keep its collection deactivated. We will update the disclosures and applicable user controls before introducing product analytics collection. The app contains no advertising, product-account, crash-upload, or notification cloud-sync SDK. Exact dependency and license information is available in Help & About → Open-source licenses.

Policy changes

Material changes to data access, use, storage, sharing, retention, diagnostics, purchases, or online functionality require an updated disclosure and policy before the affected release is distributed. The “Last updated” date above will change when this policy is revised.

Contact

Developer / operator: Mohan Gangahanumaiah
Product: NotiRecall

For privacy questions or product support, email support@notirecall.com.