This Privacy Policy explains how Javaway (the developer, “we”) processes data in the Raccoon Notes mobile application. The App can be used without an account: notes are kept locally by default, synchronization is optional, and optional analytics requires consent.
Store-specific statements below were verified for the Huawei AppGallery build 1.4.15 (155), package info.javaway.raccoon_notes. Features and payment providers in builds from other stores may differ where this Policy says so.
1. Privacy choice and consent
On first launch, and again when the Policy version changes, the App asks whether you accept optional analytics. You can open this Policy before deciding. Choosing “Accept” enables optional analytics. Choosing “Continue without optional analytics” keeps it disabled and does not restrict local note-taking features. Closing the notice is not treated as consent.
The decision (UNKNOWN, ACCEPTED, or DECLINED) and the accepted Policy version are stored only in the App settings on your device. The consent value is not sent to the synchronization server during registration.
Successful email registration after you check “I have read and accept the Privacy Policy” records the same ACCEPTED state and can enable optional analytics. This also replaces an earlier DECLINED state. Ordinary sign-in to an existing account does not change the privacy choice.
2. Data stored on your device
Unless you choose an online feature, the following data stays on your device:
- notes, folders, checklists, links, colors, pinned items, and related metadata;
- photos, images, voice recordings, audio attachments, and custom folder icons;
- reminders, calendar links, time actions, and alarm settings;
- App settings, local security settings, and the privacy decision;
- local technical logs used to diagnose problems.
Local data remains until you delete it, clear the App data, or uninstall the App. Uninstalling the App does not delete data already synchronized to a server or stored in a third-party cloud.
3. Account and authentication
An account is needed only for synchronization and related online features. Email/password registration sends your email address, the same value as the username, and your password tohttps://raccoon.javaway.info over HTTPS. The server stores a password hash rather than the plain-text password. The App may also send locale, country, and distribution channel to select the correct account and store behavior. An authentication token is stored locally after a successful sign-in.
If you choose Yandex or Google sign-in, the selected provider processes the OAuth request and the App/server exchanges the provider code or token needed to authenticate you. The server may obtain and store the provider email as the account email and username, together with the selected authentication method. Distribution channel is sent with email/password registration. Country may be recorded during supported sign-in/account flows, and locale may be sent when requesting a localized password-reset email. We do not send your privacy checkbox value as an account field.
4. Optional synchronization
When you enable synchronization, the App sends the data needed to reproduce your notes and settings on your devices to our synchronization server. This can include:
- note, folder, and checklist text and metadata;
- links, colors, pinned state, reminders, calendar entries, and time actions;
- internal identifiers, timestamps, deletion markers, and synchronization status;
- media metadata, attachment metadata, and custom folder icons;
- purchase or entitlement status used to restore Deluxe features.
Synchronization can be turned off. Turning it off stops future synchronization but does not by itself erase copies already stored on the synchronization server or another device.
5. Media and external cloud storage
If you connect Yandex Disk or Google Drive, media files are normally uploaded to the selected cloud account under that provider's terms. The App exchanges the authorization tokens and file metadata needed for the operation. Our synchronization server may process media metadata, custom folder icons, and legacy image or attachment requests; therefore we do not claim that every media-related item bypasses our server.
Disconnecting a cloud provider stops future access but does not automatically delete files in that provider. Manage or delete those files in the provider account as well.
6. Optional analytics and diagnostics
The AppGallery build contains Yandex AppMetrica Analytics 7.14.0. The SDK is not activated and App analytics events are not sent while consent is unknown or declined. It is activated only after you accept the current Policy version.
After consent, AppMetrica may receive:
- App and device technical information, such as App/OS version, device model, screen, network, session, and installation data;
- feature interactions and reminder/alarm action or status categories;
- sync performance and media operation categories, size buckets, stages, and pending item counts;
- diagnostic messages, error categories, stack traces, and internal technical identifiers.
We do not intentionally include note text, attachment contents, email addresses, or passwords in analytics events. Advertising identifiers, App Set ID, location, screenshot, billing, ad-revenue, and identifier-sync modules are excluded from the AppGallery build. Firebase Analytics and advertising SDKs are not included in this build.
Some diagnostic entries may still be written locally when optional analytics is disabled. They stay on the device unless you explicitly send a problem report. A manually submitted sync error report can include the error type, a shortened diagnostic detail, App/platform version, time, and an optional email address.
AppMetrica is provided by Yandex LLC, which processes analytics data for this purpose. See the AppMetrica terms and Yandex Privacy Policy.
7. Purchases, subscriptions, and advertising
The AppGallery build 1.4.15 does not contain an advertising SDK, does not show ads, and does not offer new purchases or donations. When you are signed in, it may read an existing entitlement from our billing service to restore Deluxe access. For this lookup, the App sends the account email to the billing service as an HTTPS query parameter and receives matching purchase or entitlement records. It does not include a Huawei IAP or YooKassa payment SDK and does not collect payment card details.
Builds distributed by other stores may offer purchases through Google Play, RuStore, or another payment provider shown before payment. Those providers process payment credentials under their own terms. We may receive the account email, purchase/transaction identifiers, product, dates, and status needed to provide, renew, or restore paid features and meet legal accounting requirements.
8. Permissions and special access
Camera access is used only when you choose to take a photo and attach it to a note. Microphone access is used only when you choose to record a voice note or audio attachment. Permission to display over other apps is used for fullscreen reminders at a time you set. Camera and microphone are requested at the moment you choose the corresponding capture or recording action. When you start creating a reminder or calendar event, the App may show one reminder-permissions screen that groups overlay access with notifications, exact alarms, Do Not Disturb, and battery settings. That screen does not request camera or microphone access. Denial does not restrict unrelated features.
Depending on the feature and Android version, the App may also use:
- notifications, exact alarms, full-screen intents, vibration, wake lock, boot, and foreground services — to schedule and show user-created reminders reliably;
- notification policy / Do Not Disturb access and battery-optimization exemption — optional special access for reminders requested by the user;
- biometrics — optional local protection of the App;
- storage or file access — user-initiated import, export, backup, and attachments; legacy broad storage access is limited to older Android versions;
- internet and network state — account, sync, cloud, billing restore, policy links, support reports, and consented analytics.
9. Service providers and data recipients
- our synchronization and billing services at Javaway domains, when you use account, sync, support, or entitlement features;
- Yandex AppMetrica, only after optional analytics consent;
- Yandex or Google, only when you select their sign-in or cloud-storage functionality;
- the applicable app store or payment provider when you start or restore a store purchase in a build that supports it;
- authorities where disclosure is required by applicable law.
We do not sell your note content or personal data.
10. Retention and deletion
- local data remains until you delete it, clear App storage, or uninstall the App;
- account and synchronized data are retained while needed to provide synchronization, until we complete a verified erasure request, or as required by law;
- transaction records may be retained for the period required by accounting, tax, anti-fraud, and store rules;
- analytics retention is governed by our AppMetrica configuration and Yandex terms;
- the current service does not apply an automatic expiration period to manually submitted sync error reports; contact us to request their deletion;
- server security logs and backups may remain for operational, security, or legal purposes; no shorter fixed deletion period is promised here.
The App includes an account deletion action, which sends an authenticated deletion request to the synchronization service. Do not treat signing out or uninstalling the App as confirmation that server data was erased. To request deletion of the account and synchronized server data, to obtain confirmation, or if the in-App action fails, email max.simple.apps@gmail.com from the account address. We may need to verify account ownership before deletion.
Files stored in Yandex Disk or Google Drive and records held by an app store/payment provider are controlled separately and may need to be deleted through that provider.
11. Security
Network requests to our services use HTTPS. Passwords are hashed on the server, and authentication tokens are stored on the device. Optional PIN, folder passwords, and biometrics protect local access. No method of storage or transmission is completely secure, so export important local data before deleting or resetting the App.
12. Your choices and rights
Depending on applicable law, you may:
- use the App locally without an account or optional analytics;
- export or delete local data and disable synchronization;
- request access to, correction of, or deletion of account and synchronized data;
- object to or restrict processing and withdraw consent for future optional analytics;
- disconnect Yandex Disk or Google Drive and manage files with the selected provider;
- complain to the competent data-protection authority.
A separate in-App reset control for an already accepted analytics choice is not available in the audited AppGallery release. Contact us before clearing App storage so we can help you stop future optional processing without accidentally losing unexported local notes. Withdrawal does not make prior lawful processing unlawful.
13. Children
The App is a general-purpose notes tool and is not directed to children below the minimum age at which they may independently consent to data processing in their country. We do not knowingly ask children for personal data. A parent or guardian who believes a child created an account can contact us to request deletion.
14. Policy changes
We may update this Policy when the App or its data processing changes. The current version is published at this URL. If the version changes, the AppGallery build asks for a new privacy choice before enabling optional analytics under the new version.
15. Contact
For privacy questions and data requests:
Email: max.simple.apps@gmail.com
Telegram: @max_simple_apps