The short version
Nitoru is local-first and does not require a Nitoru account. Local-only use remains available. In the optional 0.2 beta, Google Drive remains the encrypted source of truth for synchronized Journal, Wallet, Calendar, Goals, and Discipline records, while a Cloudflare coordination service authenticates devices, coordinates trusted-device enrollment, and sends content-free synchronization notifications.
Nitoru contains no advertising, behavioral analytics, or sale of personal information. Optional weather, Microsoft Store services, release information, and user-enabled Google Drive synchronization with Cloudflare device coordination are the product features that can require the internet.
Data stored on your device
Your Nitoru workspace is stored in an AES-encrypted local H2 database. The database key is protected with Windows Data Protection API (DPAPI) for the signed-in Windows user on that device.
This includes journal entries, calendar items, wallet records, goals and wishes, discipline check-ins, preferences, and other content you add to the application.
No Nitoru account
Nitoru does not create an online Nitoru profile. Google authorization selects the private Drive storage and lets Cloudflare verify the selected account for coordination; it does not by itself make an installation trusted and cannot decrypt a Vault. A second installation must be explicitly approved by an existing trusted Nitoru device before it can authenticate existing Drive history. A separately saved cloud recovery key can authorize an emergency takeover; the file-based local recovery kit is a different artifact and cannot authorize that cloud transition by itself.
Optional network services
Weather
If you use weather, the city you enter is sent to Open-Meteo’s geocoding service. The resulting coordinates are sent to its forecast service. Open-Meteo receives the normal technical information associated with a web request.
Microsoft Store
Microsoft Store installation, licensing, and update checks are handled by Windows and Microsoft Store services under Microsoft’s terms and privacy practices.
Nitoru release notes
After Microsoft Store reports an available Nitoru update, the app may request the fixed public stable release manifest from nitoru.com. The requested URL does not contain the installed or target package version. The request carries normal delivery metadata such as an IP address and user agent, but it does not include your journal, calendar, wallet, goals, account information, or a unique installation identifier.
Optional encrypted synchronization through Google Drive
When Account & Sync is included and enabled in a Windows beta build, you may choose Continue with Google to synchronize Journal entries, core Wallet data, Calendar items, Goals and Wishes, and Discipline through Nitoru’s hidden Google Drive application-data folder. Google Drive remains the encrypted source of truth for those synchronized records, and local-only use remains available.
Nitoru requests OpenID identity, email identity, and the narrow drive.appdata permission. Google requires an OpenID identity request to include either email or profile access; Nitoru chooses email. Nitoru does not retain the returned email address or profile information as a Nitoru profile, although the short-lived identity token sent to Cloudflare can contain Google identity claims. Google’s stable account identifier binds the local Vault to the selected Drive account and is used to derive a separate account-room identifier for coordination. The locally stored identifier and refresh credential are encrypted with Windows account protection. Google Drive access credentials remain in Electron main memory and are not sent to nitoru.com, the local Java service, the renderer, or logs.
Before storing a connection, Nitoru uploads, verifies, and deletes a small random test object. When synchronization is enabled, it stores immutable encrypted Journal, Wallet, Calendar, Goal, and Discipline snapshots and operation segments, plus signed and encrypted trusted-device registry projections, in Google Drive. The live H2 database, local database snapshots, Vault root, recovery keys, device private keys, Google Drive credentials, and readable workspace titles or content are never uploaded readably.
Cloudflare device coordination
A Cloudflare Worker and Durable Object authenticate devices, coordinate trusted-device enrollment, and send content-free synchronization notifications. These notifications only tell another trusted device to check Google Drive; they do not carry workspace records.
For this coordination, Cloudflare may process a short-lived Google identity token, a derived account-room identifier, device trust metadata, IP address, user agent, timestamps, and notification types. The Worker verifies the identity token; its Google account subject, email claim, and full token are not forwarded to or stored by the Durable Object account room. Cloudflare does not receive readable Journal, Wallet, Calendar, Goal, or Discipline titles or content, encrypted Drive objects, Drive file identifiers, Google access or refresh tokens, device labels, or the H2 database.
Google can process the encrypted bytes and technical metadata needed to provide Drive, including opaque file identifiers and properties, object sizes and timestamps, authorization, IP address, and user agent. Nitoru uses Google API data only for the visible connection and synchronization features—not for advertising, analytics, sale, credit decisions, or AI-model training. Nitoru’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Trusted devices, recovery, and removal
Google authorization selects storage; it does not approve a Nitoru device. A second installation must be approved by an existing trusted installation before it can authenticate the Vault’s Drive history. A separately saved cloud recovery key can instead perform an explicit emergency takeover when trusted devices are inaccessible, revoking all prior device identities and making the recovered installation the sole trusted device. Google sign-in and the file-based local recovery kit cannot authorize that cloud transition by themselves.
Beta limitation: Removing a trusted device makes Nitoru reject that device’s future changes after the signed removal reaches your other devices, but it does not automatically rotate the Vault key or erase keys and copies already stored on that device. A removed device that retained the Vault key and still has access to the same Google account could therefore read later encrypted files in Nitoru’s Google Drive app-data folder, even though Nitoru rejects changes from that device. Keep a lost or removed installation signed out, and contact support before adding more sensitive synchronized content.
Disconnect this device removes only this installation’s protected local Google credential and pauses synchronization here. A separate confirmed account-wide action asks Google to revoke Nitoru access for every installation. Neither action deletes local content, the retained Vault-to-account binding, or previously synchronized encrypted Drive objects. Immutable history can retain ciphertext for earlier or deleted synchronized records so offline devices converge; the beta does not yet compact that remote history. Keep the cloud recovery key and local recovery kit separately, retain at least one trusted installation, and maintain an independent backup of important information.
Local recovery snapshots
Nitoru can retain up to 14 encrypted startup snapshots on the same device to help with local recovery. They use the same Windows user and device-bound protection as the main database.
These snapshots are not portable cloud backups. Moving them to another Windows user or device does not make them transferable. Optional Drive sync uploads separately encrypted operation history for supported synchronized areas, never these files.
Important security boundaries
On supported Windows 11 devices, you can optionally require Windows Hello verification before Nitoru opens selected Journal, Wallet, or Discipline data. One verification opens all selected sections together until they lock. Protected sections automatically lock after a configurable 1–60 minutes of inactivity; the default is five minutes. Activity inside Nitoru resets that timer, while activity in other applications does not. Protected sections lock immediately when Nitoru is minimized or hidden, Windows is locked, or the computer is suspended. Every change to the protected-section selection or inactivity timing requires a fresh Windows verification.
While protection is enabled, Nitoru asks Windows to exclude the application window from supported screen captures. This defense-in-depth request does not guarantee exclusion from every capture path or removal of every previously cached taskbar thumbnail.
This is a device-local access gate tied to the current Windows account. It is not another encryption key, a Nitoru password, a passkey, or a replacement for Windows account recovery. Nitoru cannot reset a Windows PIN, face, or fingerprint credential, and the protected-section selection is not synchronized through Google Drive.
No software can guarantee protection against malware, compromised operating-system accounts, physical access to an unlocked device, or loss of every trusted device and recovery material. Keep Windows updated, protect your Windows and Google accounts, preserve recovery materials separately, and maintain backups appropriate for your needs.
The current application also does not yet provide one complete “erase everything” workflow. Data removal may require uninstalling the app and removing its local application-data folder.
This website
Nitoru.com does not use advertising pixels, behavioral analytics, account cookies, or a contact form in this first version. Like any website host, our hosting and delivery providers may receive standard request metadata such as your IP address, browser information, requested page, and request time for delivery, reliability, and security.
The public release-notes JSON contains product release information only. If it is unavailable, invalid, equal to or older than the installed release, the app simply omits the optional “What’s new” section and retries later.
Questions and requests
Nitoru is published by Nikolay Katrosha. For privacy questions or support, email support@nitoru.com.