My NoteVault

My NoteVault Privacy Policy

Effective 22 September 2026 · Last updated 22 September 2026 · Version 2.1

My NoteVault is a product of ZeengoCorp Innovations.

This policy explains how My NoteVault ("the App", "we", "us" or "our") handles data. My NoteVault is developed and operated by ZeengoCorp Innovations, and this policy covers the My NoteVault Android app and this website, mynotevault.in. My NoteVault is designed so that your vault content never leaves your device. The data processed off the device relates to advertising, app analytics, crash reporting, app configuration, notifications, integrity checks and billing. Each is described below.

Privacy at a glance

  • Your vault content (photos, videos, documents and the vault's index) is stored only on your device. We do not see it, transmit it or back it up.
  • My NoteVault does not require an account, email address or phone number.
  • Your vault passwords and secret word stay on your device. Vault keys are derived from your passwords on the device with PBKDF2-HMAC-SHA256 (100,000 iterations). Vault files are encrypted with AES-256 and vault databases with SQLCipher. We never receive your passwords or keys.
  • We show ads from Google AdMob and its mediation partners. In the EEA, the UK and Switzerland, ads are personalized only if you consent, and you can change your choice at any time.
  • Google (AdMob, Firebase and Google Play), Samsung and the ad partners listed in §5.3 receive technical data such as the advertising ID, IP address, device information and app usage events, under their own privacy policies. They never receive your notes or vault files.
  • You have rights under GDPR, UK-GDPR, CCPA/CPRA and India's DPDPA, described in §10 and §11. Email contact@zeengocorp.com.
  • We do not sell personal information for money. Some advertising may count as "sharing" under California law; see §11.

1. Who we are (data controller)

My NoteVault is a product of ZeengoCorp Innovations, which is the data controller responsible for it:

ZeengoCorp Innovations
Gurugram, Haryana, India
All inquiries: contact@zeengocorp.com
Founder direct (escalations): abhishek.rajput@zeengocorp.com

For matters involving the EEA, the UK or Switzerland, contact the mailbox above and we will route your request through our designated representative if one is required for your jurisdiction.

2. Scope of this policy

This policy applies to:

  • The My NoteVault Android app distributed on Google Play and the Samsung Galaxy Store (package com.zeengocorp.notevault28).
  • This website, mynotevault.in.
  • Messages you send to contact@zeengocorp.com and related ZeengoCorp mailboxes.

It does not apply to third-party services governed by their own privacy policies (listed in §7), or to ZeengoCorp's corporate website, which has its own privacy policy.

3. Data we process

3.1 On-device data (never leaves your device)

  • Notes: text, formatting, labels, pins, archive state, reminders and colors.
  • Vault content: photos, videos, audio, PDFs and documents you choose to hide, encrypted with AES-256.
  • Vault metadata: folder names, encrypted thumbnails and file index entries, stored in a SQLCipher-encrypted database.
  • Authentication data: keys derived from your vault passwords with PBKDF2-HMAC-SHA256, and your secret word, kept in the app's Android Keystore-backed secure storage. We never receive the passwords, the secret word or the keys.
  • Recovery data: generated and stored on the device so you can regain access if you forget your password.
  • Intruder log and intruder photos: timestamps of failed unlock attempts and, if you use the Premium intruder photo, a front-camera photo taken after a wrong password. Stored on the device only.

We cannot read, copy or recover any of this. If you lose both your password and your recovery code, your vault content is permanently inaccessible. My NoteVault opts out of Android's cloud backup, so this data is not copied to your Google account backup, and uninstalling the app deletes it.

3.2 Data processed off the device

When you use My NoteVault, the following may be processed by the services listed in §7:

  • Advertising ID: a resettable identifier issued by your device. You can reset or delete it in Android settings.
  • IP address: seen by ad, analytics and crash services for coarse (country-level) location, fraud prevention and ad serving.
  • Device and app data: model, OS version, app version, language, screen size, time zone and mobile country code.
  • App usage events: for example, that the app was opened, that a vault was unlocked and by which method, how many files an import contained, that a subscription started and which plan was chosen, or which ad was shown and what it earned. Sent to Firebase Analytics with an app instance ID. Events never contain your notes, file names or files.
  • Ad interaction data: impressions, clicks, viewability and latency, used by ad partners to measure and bill.
  • Crash and stability data: diagnostic stack traces and runtime metrics via Firebase Crashlytics, used to fix bugs.
  • Configuration and notification data: an app instance identifier used by Firebase Remote Config to deliver app settings, and a push token used by Firebase Cloud Messaging to deliver notifications.
  • Integrity signals: Firebase App Check uses Google Play Integrity to confirm that requests come from a genuine copy of the app. Tokens are short-lived.
  • Purchase data: if you subscribe to Premium, Google Play or Samsung processes the payment. We receive a purchase confirmation, never your payment details.

We do not receive: your email, phone number, real name, postal address, contacts, calendar, microphone audio, biometric data or any vault content.

3.3 This website

mynotevault.in is hosted by Vercel, which processes your IP address and browser details to deliver pages and keep the site secure. We measure visits with Vercel Web Analytics, which uses no cookies. The site sets no cookies and has no forms. If you use the theme switch, your choice is saved in your browser's local storage and never sent to us.

Under Articles 6(1)(a), 6(1)(b) and 6(1)(f) of the EU General Data Protection Regulation 2016/679 (and the equivalent provisions of UK-GDPR and India's DPDPA 2023), we rely on these legal bases:

Purpose Data used Legal basis
Provide the notepad and vault On-device data (§3.1) Performance of contract, Art. 6(1)(b)
Serve non-personalized ads Advertising ID, IP address, coarse device data Legitimate interests, Art. 6(1)(f)
Serve personalized ads (EEA, UK and Switzerland only with consent) Advertising ID, IP address, ad interaction data, profile via Google Consent, Art. 6(1)(a)
Understand how features are used and improve the app App usage events, app instance ID, device data Legitimate interests, Art. 6(1)(f)
Diagnose crashes and stability bugs Crash traces, app version, device model Legitimate interests, Art. 6(1)(f)
Deliver app settings and notifications App instance ID, push token Legitimate interests, Art. 6(1)(f)
Detect tampered copies of the app Short-lived integrity tokens Legitimate interests, Art. 6(1)(f)
Process Premium subscriptions Purchase confirmation from the store Performance of contract, Art. 6(1)(b)
Respond to support requests The contents of emails you send us Legitimate interests or consent, Art. 6(1)(f) or (a)
Run and measure this website IP address, browser data, page views Legitimate interests, Art. 6(1)(f)

Where we rely on legitimate interests, we have balanced our interest in serving non-personalized ads, improving the app and keeping it stable against your rights and freedoms, and concluded that it does not override them. You may object to processing on this basis under §10.

5. Advertising and personalized ads

My NoteVault is supported in part by advertising. Ads are served by Google AdMob, operated by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) for users in the EEA, the UK and Switzerland, and by Google LLC elsewhere.

5.1 Where ads appear

  • In the notepad (banner and interstitial placements), and an app-open ad that can appear when you start the app.
  • As optional rewarded ads: watching one unlocks every Premium feature for one hour.
  • The vault shows no ads on its own. Once the vault is unlocked, banner, interstitial and app-open ads are suppressed; the only ad you can see there is a rewarded ad you choose to watch from vault settings.
  • Premium subscribers ($1.49 a month) see no ads.

5.2 Personalized and non-personalized ads

A personalized ad is selected using data Google holds about the device, such as previous app usage and inferred interests. A non-personalized ad is selected using only contextual signals, such as the current app and coarse location.

  • EEA, UK and Switzerland: on first launch we show Google's certified User Messaging Platform (UMP) consent screen, which implements the IAB Transparency & Consent Framework v2.2. You can choose "Consent" (personalized ads), "Manage options" (choices per purpose and per partner) or "Do not consent" (non-personalized ads). Your choice is stored on the device as a TCF v2.2 consent string and read by AdMob.
  • All other regions: personalized ads may be served, subject to local law. You can opt out at any time (see §6).

5.3 Ad partners

AdMob runs a mediation auction in which these ad networks may bid to show ads in My NoteVault: Meta Audience Network, Unity Ads, Liftoff Monetize and BidMachine. Each receives ad-request data (such as the advertising ID, IP address and device data) under its own privacy policy. Google's list of ad technology providers is at https://support.google.com/admob/answer/9012903. For the IAB Global Vendor List used on the consent screen, see https://vendor-list.consensu.org/v3/vendor-list.json.

5.4 Ad measurement and reporting

Ad partners measure impressions, viewability and clicks to bill advertisers and to detect invalid traffic. This measurement may use your advertising ID and IP address. We rely on legitimate interests for measurement. If you withdraw advertising consent in the EEA, the UK or Switzerland, measurement stops processing personal data and falls back to aggregated counts.

  • In the app: open the menu, then Help & Support → Ad privacy choices, to review or change how ads are personalized. Withdrawing consent is as easy as giving it.
  • Reset your advertising ID: on most phones, Android Settings → Privacy → Ads → Reset advertising ID (or Delete advertising ID).
  • Opt out of personalized ads across Google: visit https://myadcenter.google.com.
  • Remove ads entirely: subscribe to My NoteVault Premium ($1.49 a month).

7. Who we share data with

We do not sell personal data for money. We share data only with these recipients, each acting as an independent controller or as our processor under its own terms:

Recipient Purpose Privacy policy
Google AdMob and the partners in §5.3 Ad serving, measurement, fraud prevention Google
Firebase Analytics (Google) App usage statistics Firebase
Firebase Crashlytics (Google) Crash diagnostics Firebase
Firebase Remote Config and Cloud Messaging (Google) App settings and notifications Firebase
Firebase App Check with Google Play Integrity Detecting tampered copies of the app Google
Google Play Billing Premium subscriptions bought on Google Play Google
Samsung In-App Purchase Premium subscriptions bought on the Galaxy Store Samsung
Vercel Hosting and cookieless analytics for this website Vercel
Legal authorities Only when required by law or valid legal process, or to protect our rights, our users or the public

Each recipient handles data under its own terms and privacy policy, and we are not responsible for its practices.

8. International data transfers

ZeengoCorp is based in India. Google (AdMob, Firebase and Google Play), Samsung, our ad partners and Vercel process data in the United States and other countries. Where personal data of EEA, UK or Swiss residents is transferred outside their region, we rely on:

  • The European Commission's Standard Contractual Clauses of 4 June 2021, as implemented in each provider's data processing terms.
  • The UK International Data Transfer Addendum issued by the Information Commissioner's Office.
  • The Swiss Federal Data Protection and Information Commissioner's recognition of those clauses.
  • Certification under the EU-US Data Privacy Framework, its UK extension and the Swiss-US framework, where the provider holds it.

You may request a copy of the safeguards for a particular transfer by emailing contact@zeengocorp.com.

9. Retention

  • On-device content (§3.1): kept on your device until you delete it or uninstall the app. We never receive a copy.
  • Advertising data: kept by Google and the ad partners under their published retention policies (for Google, typically up to 13 months for personalized advertising; aggregated counts longer).
  • App analytics data: event-level data is kept by Firebase Analytics for 2 months, after which only aggregated reports remain.
  • Crash data: kept by Firebase Crashlytics for up to 90 days.
  • Website analytics: Vercel Web Analytics keeps aggregated page-view counts; it stores no cookies and no IP addresses.
  • Support emails: kept for 24 months from your last message, then deleted, unless the law requires longer.
  • Consent records (TCF v2.2 strings): kept on your device for the framework's validity period (currently 13 months) and refreshed when you are asked again.

10. Your rights (GDPR, UK-GDPR, DPDPA)

If you are in the EEA, the UK, Switzerland or India, you have these rights:

  • Access (Art. 15): confirmation of whether we process your personal data, and a copy.
  • Rectification (Art. 16): correction of inaccurate or incomplete data.
  • Erasure, or the right to be forgotten (Art. 17): deletion of your data, subject to lawful exceptions.
  • Restriction (Art. 18): limited processing while a correction or objection is checked.
  • Portability (Art. 20): your data in a structured, commonly used, machine-readable format.
  • Objection (Art. 21): to processing based on legitimate interests, including direct marketing.
  • Withdrawal of consent (Art. 7(3)): at any time, without affecting processing before the withdrawal.
  • Not to be subject to solely automated decisions (Art. 22): My NoteVault makes no decisions about you with legal or similarly significant effects.
  • Complaint (Art. 77): to your local supervisory authority; see §16.

To exercise any right, email contact@zeengocorp.com. We respond within 30 days, extendable to 60 days for complex requests, with notice. We may ask for information to verify your identity. There is no fee unless a request is manifestly unfounded or excessive.

11. California (CCPA/CPRA) rights

If you are a California resident, the California Consumer Privacy Act of 2018, as amended by the CPRA, gives you these rights over personal information we processed in the previous twelve months:

  • Right to know the categories of personal information collected, their sources, the business purposes and the categories of recipients.
  • Right to delete personal information we have collected from you.
  • Right to correct inaccurate personal information.
  • Right to opt out of "sale" or "sharing" for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes other than those permitted under § 7027(m) of the CCPA regulations.
  • Right of non-retaliation for exercising your rights.

Sale and sharing: ZeengoCorp does not sell personal information for money. Some advertising activity may count as "sharing" under California law. Withdrawing advertising consent in the app (§6) works as an opt-out.

To make a request, email contact@zeengocorp.com with the subject line "California Privacy Request".

12. Children's privacy

My NoteVault is not directed at children. We do not knowingly collect personal information from children under 13 (United States, COPPA), under 16 (EEA, where the GDPR Art. 8 digital consent age applies, subject to Member State rules) or under 18 (India, DPDPA).

Because My NoteVault is not directed at children, its ad requests are not tagged as child-directed, and we limit ad content to the PG maturity rating.

If you believe a child has provided us information, contact contact@zeengocorp.com and we will delete it without delay.

13. Security

  • Vault files encrypted with AES-256; vault databases encrypted with SQLCipher.
  • Keys derived with PBKDF2-HMAC-SHA256 (100,000 iterations), with a separate key for each vault. Passwords, secret words and recovery codes are never stored in plain text.
  • App secrets kept in Android Keystore-backed secure storage, hardware-backed where the device supports it.
  • Minimum permissions, following Android's scoped-storage and photo-access rules.
  • TLS 1.2 or newer for all network calls (ads, analytics, crash reports, configuration, notifications and integrity checks).
  • Firebase App Check with Google Play Integrity to detect tampered copies of the app.
  • Breach notification: if we identify a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours, as Art. 33 GDPR requires, and notify affected users without undue delay where Art. 34 requires it.

No method of electronic storage is perfectly secure. We cannot protect against sophisticated physical attacks on a device already in someone else's possession. You are responsible for keeping your device, passwords, secret word and recovery code secure. To the extent the law allows, we are not liable for unauthorized access that results from a lost, stolen, shared, rooted or compromised device, or from credentials you disclose.

14. Automated decision-making

My NoteVault does not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). Ad selection is automated, but it is part of operating the service, not a qualifying decision.

15. Changes to this policy

We may update this policy when our practices or the law change. The "Last updated" date at the top shows the latest revision. Where the law requires it, we will notify you in the app or on this page, or ask for your consent again. Earlier versions of this policy are available on request.

16. Contact and complaints

For privacy questions, requests to exercise your rights, or to withdraw consent at any time, contact us. We aim to respond within 30 days.

Right to lodge a complaint

You may complain to a data protection supervisory authority, for example:


© 2026 ZeengoCorp Innovations. My NoteVault is a ZeengoCorp Innovations product. This policy is provided in English; if it is translated, the English version controls. See also the security page and the terms of use.