Ruminote Privacy Policy
Last updated: 30 July 2026
Türkçe · English
Ruminote is a note-taking app that keeps your notes primarily on your device. Creating an
account is optional; if you use the app without an account, no data is sent to our servers.
We show no ads, we do not sell your data, and we use no third-party analytics or tracking tools.
1. Data we process
Data is processed only when you create an account and/or share a note:
- Account information: email address, username, password (stored only as a cryptographic hash — never in plain text), and an optional profile photo.
- Sign in with Google (optional): If you use "Continue with Google", we receive your Google account's verified email address (and name) to create or match your account. We never see your Google password; authentication is handled by Google.
- Shared notes: Only when you share a note with others, that note (text, images, video, audio, drawings, maps) is synced to our servers. This content is end-to-end encrypted: the server cannot read the content, title or tag; it stores only the encrypted data and wrapped encryption keys for authorized members. Depending on your sync media quality setting, photos and videos may be downscaled on your device before upload (to reduce data); the original files on your device are never modified.
- Search queries: When you use the "AI Info" / web search feature, the query you type is sent to our server and on to search engines to fetch results. We do not associate queries with your account or store them.
- Code execution: When you run a code snippet, for languages that cannot run on the device the code text is sent to our server (and on to the execution engine) to return the result. The result may be briefly cached to speed up re-running the same code; we do not associate the code with your account or store it permanently. Python, Ruby and the Compose preview run entirely on-device and are not sent to a server.
- Purchase validation: When you buy Collab, the Google Play purchase token is sent to our server for verification. We never see payment details (cards, etc.) — payment is handled by Google Play.
- Notification token: So we can notify you of shared-note updates, a Firebase Cloud Messaging (FCM) token is assigned to your device and stored on our server, linked to your account (deleted on sign-out).
2. Data that stays on your device / we never send
- All notes, media and drawings you do not share stay only on your device and are never sent to the server.
- Artificial-intelligence processing runs on-device; your note content, photos or audio recordings are not sent to a server for these features. This includes:
- text summaries, "ask your note" Q&A and title/tag suggestions (Gemma models);
- OCR / text recognition, handwriting recognition and QR reading;
- speech-to-text (dictation / transcription) and speaker diarization; audio noise removal, classification and music/vocal separation;
- photo-editing models: object and sky selection, object removal, background removal/replacement, super-resolution, low-light enhancement, noise/blur/haze removal and artistic style;
- running code and the Compose preview on-device (except the cloud languages noted above).
- AI model files are downloaded on demand: the first time you use a feature, its model file may be downloaded from the internet. This download only fetches the model file; your note content or personal data is not sent.
3. Permissions and their purposes
- Camera: photo/video notes, OCR scanning, QR code reading.
- Microphone: audio notes and speech-to-text.
- Notifications / Alarms: note reminders.
- Bluetooth / Wi-Fi (Nearby): local note sharing with a nearby device (not used to determine location).
- Location (Android 12 and below only): when adding a location to a map card. Not requested on newer versions.
- Internet: account, synchronization, search and purchase validation.
4. Third-party services
- Google Play Billing — purchases (payment handled by Google).
- Sign in with Google (Credential Manager) — optional authentication; we receive only your Google account's verified email address and name (never your password).
- Google Play Services (Nearby) — local sharing with a nearby device.
- OpenStreetMap — map tiles (only when a map card is opened, the viewed area is requested from OSM servers).
- Firebase Cloud Messaging (Google) — push notifications; an FCM token is assigned to your device (used only for notifications; no analytics/tracking).
- Google Fonts (Downloadable Fonts) — only when you choose to download a font, the requested font family name is sent to the Google Play Services fonts provider to fetch the font file. No note content or account data is involved.
Other than these, we do not share your data with any third party; we use no ad networks or data brokers.
5. Security
- All server communication is encrypted with HTTPS.
- Passwords are stored hashed, never in plain text.
- Shared notes are end-to-end encrypted — the server cannot decrypt the content.
6. Data retention and deletion
You can permanently delete your account and all your server-side data from within the app via Profile → Delete account. Local data on your device is removed when you uninstall the app.
7. Children
Ruminote is not directed to children under 13 and does not knowingly collect personal data from them.
8. Changes
We may update this policy from time to time. We will notify you of material changes in the app or on this page.
9. Contact
For privacy questions: ruminotedev@ruminote.org
Ruminote · kasimtmc