From fdd3e58db68e0219b55987a9132d0dda02ced317 Mon Sep 17 00:00:00 2001 From: DevBehindYou Date: Tue, 29 Sep 2026 02:02:52 +0530 Subject: [PATCH] Privacy Policy and Terms of Service pages /privacy: what the app and server keep, what they never collect, how each Google scope is used (openid/email/profile for sign-in, drive.file only for the My-Atomic-Notes files), the Limited Use statement for the Google API Services User Data Policy, the vault, storage and protection, retention, user choices (sync off, Danger Zone, revoking access, account deletion on request) and service providers. /terms: the service, accounts, Atomic Energy and Coins as virtual items with no cash value, acceptable use, license, availability, warranty and liability. Both are linked in the footer and the sitemap. Needed to publish the Google OAuth consent screen, which requires a privacy policy URL on the app's homepage domain. Co-Authored-By: Claude Opus 5.5 --- src/app/globals.css | 23 +++++ src/app/privacy/page.tsx | 155 ++++++++++++++++++++++++++++++++++ src/app/sitemap.ts | 2 + src/app/terms/page.tsx | 115 +++++++++++++++++++++++++ src/components/LegalPage.tsx | 30 +++++++ src/components/SiteFooter.tsx | 2 + 6 files changed, 327 insertions(+) create mode 100644 src/app/privacy/page.tsx create mode 100644 src/app/terms/page.tsx create mode 100644 src/components/LegalPage.tsx diff --git a/src/app/globals.css b/src/app/globals.css index 7c39f45..4cbe882 100644 --- a/src/app/globals.css +++ b/src/app/globals.css @@ -1756,3 +1756,26 @@ section h2 { grid-template-columns: 1fr; } } + +/* ---------- privacy policy and terms ---------- */ +.legal { + max-width: 760px; + padding-top: 48px; + padding-bottom: 64px; +} +.legal h1 { + font-size: clamp(2.6rem, 7vw, 4rem); + margin-top: 4px; +} +.legal-updated { + margin: 10px 0 26px; +} +.legal .prose ul { + list-style: disc; + padding-left: 20px; + margin: 0 0 18px; + line-height: 1.7; +} +.legal .prose li { + margin-bottom: 6px; +} diff --git a/src/app/privacy/page.tsx b/src/app/privacy/page.tsx new file mode 100644 index 0000000..9116535 --- /dev/null +++ b/src/app/privacy/page.tsx @@ -0,0 +1,155 @@ +import type { Metadata } from "next"; +import { LegalPage } from "@/components/LegalPage"; +import { REPO_URL } from "@/lib/content"; + +export const metadata: Metadata = { + title: "Privacy Policy", + description: + "How Atomic Notes handles your data: what the app and server keep, how Google user data is used, the end-to-end vault, retention, and your choices.", + alternates: { canonical: "/privacy" }, +}; + +const CONTACT = "https://github.com/DevBehindYou"; + +export default function PrivacyPage() { + return ( + +

+ This policy explains how the Atomic Notes Android app, its sync server and this website handle your + information. Atomic Notes is built and operated by Ashutosh Sharma, who publishes as DevBehindYou (“we”, + “us”). +

+ +

The short version

+
    +
  • Your notes are saved on your phone first. When you sync, they go to a folder in your own Google Drive.
  • +
  • Our server never stores your note titles, text or checklist items.
  • +
  • There is no analytics, no crash reporting, no advertising and no AI in the app.
  • +
  • We never sell your data, and we never use it to train AI models.
  • +
+ +

Information we collect

+

To run your account and sync, our server keeps:

+
    +
  • Your Google account ID, email address and name, from Google sign-in, and the username you choose.
  • +
  • Your Atomic Energy and Atomic Coin balances, and a record of how they changed.
  • +
  • + Metadata for each note: its ID, whether it is a note or a checklist, the pinned and deleted flags, timestamps, + and the ID of its file in your Google Drive. +
  • +
  • Your Google access and refresh tokens, encrypted with AES-256-GCM before they are stored.
  • +
  • A short log of account and security events, such as sign-ins.
  • +
  • Which in-app announcements you have read or dismissed.
  • +
+

+ We do not collect your note content, contacts, location, advertising IDs, analytics or crash reports. Our hosting + provider processes standard request data, such as IP addresses, to deliver the app's server and this + website. This website sets no tracking or advertising cookies. +

+ +

How we use Google user data

+

Atomic Notes asks Google for these permissions, and uses each one only as described:

+
    +
  • + openid, email and profile: to sign you in, create your account, and show your name and email in the app. +
  • +
  • + drive.file: to create a My-Atomic-Notes folder in your Google Drive, and to create, read, + update and delete the note files Atomic Notes makes there, so your notes sync between your devices. This + permission only covers files the app created. Atomic Notes cannot see any other file in your Drive. +
  • +
+

+ We use Google user data only to provide and improve these features for you. We do not sell it, use it for + advertising, or use it to train artificial-intelligence or machine-learning models. We do not transfer it to + anyone except as needed to run the service (see “Service providers” below), for security, or to comply + with the law. No person reads your Google data unless you ask for help and give permission, it is needed to + investigate abuse or a security problem, or the law requires it. +

+

+ Atomic Notes' use and transfer to any other app of information received from Google APIs will adhere to the{" "} + + Google API Services User Data Policy + + , including the Limited Use requirements. +

+ +

The end-to-end vault

+

+ If you turn on Encryption, the app derives a key on your phone from a 6-word recovery phrase and encrypts every + note with AES-256-GCM before it leaves the device. Your Drive and our server then hold only ciphertext. The phrase + and the key never leave your phone, so we cannot recover vault notes if you lose the phrase. With the vault off, + note content is stored as plain text in your own Drive and passes through our server on its way there, without + being stored. +

+ +

Where data is stored and how it is protected

+
    +
  • Note content: on your phone, and in your own Google Drive when you sync.
  • +
  • Account data: in our database (MongoDB Atlas), used by our server on Vercel (Mumbai, India region).
  • +
  • All traffic between the app and the server uses HTTPS.
  • +
  • In the app, the session and vault key are kept in Android's secure storage.
  • +
+ +

How long we keep it

+
    +
  • Account and balance data: for as long as your account exists.
  • +
  • Security event log: 30 days.
  • +
  • Records of deleted notes and of each sync: 30 days.
  • +
+ +

Your choices

+
    +
  • Turn cloud sync off in Settings. Your notes then stay on your phone only.
  • +
  • + Use Settings > Danger Zone to delete the cloud copies (this deletes the note files from your Drive and their + metadata from our server) or the notes on your phone. +
  • +
  • + Remove Atomic Notes' access to your Google account at any time at{" "} + + myaccount.google.com/permissions + + . +
  • +
  • + To delete your account, or to get a copy of the data we hold about you, contact us (below). We delete account + data within 30 days of a verified request. +
  • +
+ +

Service providers

+
    +
  • Google: sign-in and Google Drive storage.
  • +
  • Vercel: hosting for the server and this website.
  • +
  • MongoDB Atlas: the database for account data.
  • +
+

+ If you choose to support the project, the payment is handled by the platform you use, under its own policies. We + only use the account email you send us to add your supporter reward. +

+ +

Children

+

Atomic Notes is not directed at children under 13, and we do not knowingly collect their information.

+ +

Changes to this policy

+

+ We will update the date at the top when this policy changes, and announce significant changes in the app's + notification center. +

+ +

Contact

+

+ Questions or requests: reach the developer through{" "} + + github.com/DevBehindYou + + . The app's source code, including how it handles data, is public to read at{" "} + + Atomic-Notes-App-V0.2 + + . +

+
+ ); +} diff --git a/src/app/sitemap.ts b/src/app/sitemap.ts index b6e87fb..c1fb511 100644 --- a/src/app/sitemap.ts +++ b/src/app/sitemap.ts @@ -17,6 +17,8 @@ export default function sitemap(): MetadataRoute.Sitemap { { url: `${BASE}/blog`, changeFrequency: "weekly", priority: 0.8 }, { url: `${BASE}/updates`, changeFrequency: "daily", priority: 0.6 }, { url: `${BASE}/support-atomic-notes`, changeFrequency: "monthly", priority: 0.5 }, + { url: `${BASE}/privacy`, changeFrequency: "yearly", priority: 0.3 }, + { url: `${BASE}/terms`, changeFrequency: "yearly", priority: 0.3 }, ...posts, ]; } diff --git a/src/app/terms/page.tsx b/src/app/terms/page.tsx new file mode 100644 index 0000000..9072fa2 --- /dev/null +++ b/src/app/terms/page.tsx @@ -0,0 +1,115 @@ +import type { Metadata } from "next"; +import Link from "next/link"; +import { LegalPage } from "@/components/LegalPage"; +import { REPO_URL } from "@/lib/content"; + +export const metadata: Metadata = { + title: "Terms of Service", + description: "The terms for using the Atomic Notes app, its sync service, Atomic Energy and Atomic Coins.", + alternates: { canonical: "/terms" }, +}; + +export default function TermsPage() { + return ( + +

+ These terms apply to the Atomic Notes Android app, its sync service and this website (together, “the + service”), operated by Ashutosh Sharma, who publishes as DevBehindYou (“we”). By using the + service, you agree to them. How we handle your data is described in the{" "} + Privacy Policy. +

+ +

1. The service

+

+ Atomic Notes is a free notes app. Notes are stored on your phone, and cloud sync stores them in your own Google + Drive. Sync needs a Google account and depends on Google's services being available. The service is under + active development, and features may change. +

+ +

2. Your account and your notes

+
    +
  • You own your notes. We claim no rights over their content.
  • +
  • You are responsible for keeping your Google account and your phone secure.
  • +
  • + If you use the end-to-end vault, keep your 6-word recovery phrase safe. We cannot recover vault notes without + it. +
  • +
  • Keep your own backups of anything important.
  • +
+ +

3. Atomic Energy and Atomic Coins

+
    +
  • + Atomic Energy and Atomic Coins are virtual items used only inside Atomic Notes, for cloud sync and note + capacity. +
  • +
  • They have no cash value, cannot be exchanged for money, and cannot be transferred to another account.
  • +
  • + We may change how much energy or how many coins features cost, and how they are granted. We will announce + significant changes in the app. +
  • +
  • + Coins sent as a thank-you for supporting the project are a gift from the developer. Payments you make to + support the project are handled by the payment platform under its own terms. +
  • +
+ +

4. Acceptable use

+

You agree not to:

+
    +
  • attack, overload or try to get unauthorized access to the service or other people's accounts;
  • +
  • use automated means to create accounts, earn energy or coins, or send excessive requests;
  • +
  • use the service to break the law.
  • +
+ +

5. The software

+

+ The app's source code is public to read under the{" "} + + Atomic Notes Source-Available License + + . Install only official releases from the Atomic Notes GitHub Releases page. +

+ +

6. Availability and changes

+

+ We try to keep the service running, but we do not guarantee it will always be available or error-free. We may + change, suspend or end any part of it. If we end cloud sync, the notes on your phone and the files in your Drive + stay yours. +

+ +

7. No warranty

+

+ The service is provided “as is” and “as available”, without warranties of any kind, to + the fullest extent the law allows. +

+ +

8. Limitation of liability

+

+ To the fullest extent the law allows, we are not liable for any indirect or consequential loss, or for any loss + of data, profits or goodwill, arising from your use of the service. +

+ +

9. Ending your use

+

+ You can stop using the service at any time and ask us to delete your account. We may suspend or close accounts + that break these terms. +

+ +

10. Changes to these terms

+

+ We will update the date at the top when these terms change, and announce significant changes in the app. + Continuing to use the service after a change means you accept the new terms. +

+ +

Contact

+

+ Questions about these terms: reach the developer through{" "} + + github.com/DevBehindYou + + . +

+
+ ); +} diff --git a/src/components/LegalPage.tsx b/src/components/LegalPage.tsx new file mode 100644 index 0000000..97a50fc --- /dev/null +++ b/src/components/LegalPage.tsx @@ -0,0 +1,30 @@ +import { SiteNav } from "@/components/SiteNav"; +import { SiteFooter } from "@/components/SiteFooter"; + +/** Shared frame for the privacy policy and the terms: site chrome, a title block and readable prose. */ +export function LegalPage({ + eyebrow, + title, + updated, + children, +}: { + eyebrow: string; + title: string; + updated: string; + children: React.ReactNode; +}) { + return ( + <> + +
+
+

{eyebrow}

+

{title}

+

Last updated: {updated}

+
{children}
+
+
+ + + ); +} diff --git a/src/components/SiteFooter.tsx b/src/components/SiteFooter.tsx index b31670e..bff0829 100644 --- a/src/components/SiteFooter.tsx +++ b/src/components/SiteFooter.tsx @@ -32,6 +32,8 @@ export function SiteFooter() { Transparency + Privacy + Terms Blog Updates RSS