The short version
Nitoru is a local-first journal, planner, goal tracker, discipline tracker and personal money organiser. You can use its core offline features without signing in to Google. Your entries are not published for other users to browse.
Google connection and cross-device synchronization are optional. When you enable synchronization and approve the device, supported records are encrypted before being uploaded to your Google Drive application-data folder. Encryption protects record contents, but does not hide all account, device or network metadata.
The Android app does not include advertising, behavioural-analytics or automatic crash-reporting integrations. We do not sell your personal information or use your Google API data for advertising, credit decisions or AI-model training. Service providers still process technical data as described below.
What stays on your phone
Nitoru stores the content you enter: journal entries, notes, ideas and drafts; calendar titles, dates and notes; goals, wishes and progress; habits, routines, rules and check-ins; and manually entered wallet transactions, categories and budgets. Depending on what you write, these records may include sensitive personal, financial or health-related information. The app uses them to display your workspace, calculate progress and provide the features you choose.
Preferences, reminder settings, the weather location you select, cached weather, local change history and device synchronization state are also stored on the device. Unsaved journal drafts and device-specific preferences are not part of cross-device record synchronization.
Local records use Android app-private storage and depend on your device's security. The current beta does not add application-level encryption to its local database. The optional app lock limits access through the app; it is not an extra layer of database encryption. Separate synchronization keys are protected using Android Keystore.
The app opts out of Android automatic app backup and device-transfer backup through its manifest and backup rules. This is separate from optional Google Drive synchronization and backups you export yourself.
Optional Google connection and encrypted sync
When you choose to connect Google, Nitoru requests Google identity/profile access and the narrow drive.appdata permission for its hidden Drive application-data folder. This permission is not general access to the other files in your Drive. The app processes Google account identity, profile information returned for the connection, and authentication tokens to verify the selected account and access that folder. Current connection tokens are kept in memory during the session.
Signing in alone does not approve a device to decrypt an existing workspace. Device approval is a separate step. After approval, synchronization covers saved Journal, Wallet, Calendar, Goals and Discipline records between your approved Nitoru devices. Record contents are encrypted on a trusted device before upload; the live local database is not uploaded as a database file.
Google processes encrypted records and the technical information needed to store and deliver them. This includes account authorization, file identifiers, workspace/device and operation identifiers, record-module information, sizes, sequence information and timestamps, plus normal network-request metadata. Your approved devices receive and decrypt synchronized records.
A Nitoru coordination service hosted on Cloudflare verifies a short-lived Google identity token and coordinates device approval and synchronization notifications. It processes a derived account identifier, device public keys and trust/security records, request timestamps and operational event/error information. The identity token can contain Google identity claims. Normal network requests can expose an IP address and client information to the provider. The coordination service is not sent readable journal, wallet, calendar, goal or discipline record contents, or your Google Drive access token.
Google API data is used for the connection, device-security and synchronization features you choose. Nitoru's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Keep your phone and Google account secure. Device removal does not remotely erase content or keys already held by that device, and does not by itself re-encrypt existing records. Neither a device lock nor synchronization can guarantee protection from a compromised operating system, malware or an unlocked device.
Weather, updates and other internet services
Weather is optional. Searching for a city sends the text you enter to Open-Meteo's geocoding service. Selecting a city sends that city's coordinates to its forecast service, and the app can refresh the forecast while you use it. These are selected-city coordinates, not a reading of your phone's GPS location. Remove the selected weather location to stop weather requests.
Google Play handles installation and Store update checks under Google's policies. For eligible Play installations, Nitoru can request public Android release information from nitoru.com. A requested release URL may contain an Android version code. These requests do not include your workspace records, Google connection token or a unique Nitoru installation identifier.
Open-Meteo, Google, Cloudflare and website delivery providers receive the technical data needed to handle their requests, such as IP addresses, request times, requested resources and client information. Nitoru's coordination service uses operational counters and error events for reliability and security; this is not behavioural tracking of your journal or other workspace content. Provider processing and retention are also subject to their own policies.
Permissions and your choices
Internet access enables the services described here. Notification permission is used for optional local reminders, and the app can restore reminder scheduling after a device restart. Reminders use generic text rather than including your saved entry contents.
If you enable app lock, Android verifies your biometric or device credential. Nitoru receives the authentication result, not your fingerprint template or device PIN.
The current Android app does not request access to your precise device location, contacts, camera or microphone. Import and export use Android's file picker for the specific file or destination you select, rather than broad access to your files. You can manage optional notification permissions in Android settings.
Backups, copying and support
When you export a backup, Nitoru encrypts it with the password you supply before writing it to the file destination you choose. Backups can include records, drafts and local change history, but do not include Google connection credentials or synchronization secrets. If you choose a cloud-backed file provider, that provider receives the encrypted backup and associated file metadata. Protect the password and manage those files separately from the app.
Joining a synchronized workspace can also keep an encrypted pre-join recovery copy on the phone. Recovery and backup copies may retain information no longer shown in the current workspace.
If you copy journal text, readable content is placed on Android's clipboard and marked sensitive. Clipboard access and clearing depend on Android and other software on your device.
Contacting support opens your email application. We receive your email address and the message or attachments you choose to send, to handle your request. Workspace records are not automatically attached. Do not send passwords, authentication tokens, signing keys or recovery keys.
Retention and deleting information
Local information remains in the app's storage while you use it. Removing an item changes the records shown in Nitoru, but earlier versions, deletion records, drafts and recovery or backup copies may remain. Emptying Journal trash is not a guarantee that every historical copy has been erased.
Disconnecting Google stops this app's current connection. It does not delete local records, approved-device state, cloud records or copies on other devices, and it does not itself revoke Google's authorization. You can separately manage or revoke Nitoru's access in your Google Account settings; revocation is not cloud-data deletion.
The current Android beta does not provide a complete in-app account or cloud-workspace deletion workflow. Encrypted synchronization history can retain earlier or deleted records so devices can synchronize, and the beta has no fixed automatic deletion period for that history. Device-trust/security information remains associated with the synchronization service; temporary coordination records expire separately from persistent trust records.
Where in-app deletion requests are available, a separate Google identity check verifies that you are using the connected account. The coordination service records an account-linked request reference, request status, time and offline-copy preference. A Requested receipt confirms intake only; it does not itself delete cloud records, revoke devices or erase your phone. Pending request records do not automatically expire in this beta. Support correspondence and necessary security records may be retained to process a request or meet legal obligations; any retained data, reason and applicable retention period must be explained during fulfillment.
Android's app-info settings let you clear Nitoru's private local storage, and uninstalling removes the app's private local data. This can also remove keys needed to access your workspace, so keep another approved device or appropriate recovery material before doing so. These actions do not remove exported backups, Google Drive data or copies on other devices. Manage exported files separately and contact support for guidance about remaining copies.
Hosting, identity, weather and email providers may retain their own technical or correspondence records under their policies and applicable requirements. This page does not promise a specific provider log-retention period or immediate erasure of all copies.
Request deletion of your Nitoru account and associated cloud data. You can start this request without reinstalling the app. Ownership verification and cleanup are separate from submitting the request.
Privacy questions and requests
Nitoru is published by Nikolay Katrosha. For privacy questions, support, or a request concerning access, correction, export or deletion, contact support@nitoru.com. Describe the request without sending private keys or the contents of your journal.
Because local records and encrypted cloud contents are not readable by support, some requests require actions on a device or account you control. The current deletion limitations are explained above; contacting support does not itself erase your devices or Google Drive.
Where applicable data-protection law provides additional rights, you may exercise those rights and raise a concern with your local data-protection authority.
Changes to this policy
We will update this page and its date when the Android app's data handling changes. This policy describes the Android beta; the desktop application and Chrome extension have separate policies.