Privacy Policy for Notarium
This policy covers the Android app Notarium (application ID com.gante.notarium). Every sentence below is a statement about the code that ships in the app, not a statement of intent.
The short version: Notarium does not collect, transmit or share any personal data. Everything you do in the app stays on your device. Buying Notarium Pro is the one moment money and an account are involved, and Google Play handles all of it — see Purchases below.
Overview
Notarium is a sheet music app: a library for scores you import or scan, a full-screen viewer with annotations, setlists, a metronome and audio player for practice, rehearsal mode, and a notation editor. All of that works with the network switched off; the two things that reach out are Google's own components — buying Notarium Pro through Google Play, and the ML Kit scanner module, which Google Play services downloads to the device.
There are no user accounts and no registration. The app never asks for your name, email address, contacts or location. Notarium Pro is bought through Google Play and follows the Google account that bought it; the app itself still has nothing to sign in to.
Data stored on your device
Notarium stores the content you create or import in the app's private storage on your device:
- sheet music files you import (PDF and images) and pages you scan;
- scores you write in the notation editor;
- song metadata: titles, composers, genres, tags, ratings, collections;
- annotations, bookmarks, link points, setlists;
- audio recordings you attach to songs;
- app settings;
- whether Notarium Pro is active and which purchase it came from (see Purchases below);
- a local error log: when something in the app fails, the error and its stack trace are appended to a file in the app's own storage, so that a support letter can carry them (see Support letters below). It is never read by anything else and never sent on its own.
None of this is uploaded anywhere. You can delete individual items in the app at any time; uninstalling the app removes all of its data from the device.
Android backup and phone-to-phone transfer
Backup is switched off in the app's manifest, both for Google Drive backups and for device-to-device transfer. Your library is not copied off the device by the system either; moving to a new phone means importing your files there again.
The app has its own backup instead: it can write the whole library — scores, markings and setlists — into a single file that you choose the location for, and restore it from that file on another device. That file goes exactly where you point the system file picker, and nowhere else.
Data collection
- Notarium has no user accounts and no registration.
- We integrate no analytics, no advertising and no crash-reporting SDKs of our own, and we collect no telemetry about you. One Google component does ship inside the app and does report to Google: the ML Kit document scanner described below brings Google's own data-transport library with diagnostics reporting enabled. It tells Google how its scanner performs; it carries no content you scan and nothing from your library, and we receive nothing from it. It is listed among the permissions below.
- The code we wrote performs no network requests at all: it contains no HTTP client and opens no sockets. The only components in the app that speak to Google are Google's own: the data-transport library above, and the Play Billing library described under Purchases, which hands a purchase to the Google Play Store app installed on your device rather than doing any networking itself. There is no path by which your scores, scans, annotations or settings could reach us. We operate no server, and the app sends us nothing on its own. The one thing that ever reaches us is a support letter you write and send yourself from your own mail app; Support letters below says exactly what such a letter carries.
Permissions the release build declares
For completeness, here is every permission in the released app and where it comes from. None of them is a permission Android asks you to approve, and none is used by Notarium's own code:
- android.permission.INTERNET and android.permission.ACCESS_NETWORK_STATE — these are not requested by Notarium. They are merged into the app by com.google.android.datatransport:transport-backend-cct, a Google data-transport component that ships as part of the ML Kit document scanner libraries described below. Google uses that component to report its own usage and performance diagnostics about its scanner; the content you scan is not part of it, and Notarium sends nothing through it.
- com.android.vending.BILLING — required by Google Play Billing so the app can open Play's purchase sheet and ask Play what this device already owns (see Purchases below). It is not written into our manifest by hand: the Play Billing library brings it in. It grants access to nothing on your device — only to Play's own billing service — and Android does not ask you to approve it.
- com.gante.notarium.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION — a signature-level permission declared by the AndroidX core library so that the app can register broadcast receivers for itself. Only code signed with our own key can use it, so it grants nothing to any other app.
The app requests no runtime permissions whatsoever: no camera, no microphone, no location, no contacts, no storage.
Document scanner (Google ML Kit)
The "Scan" feature uses the ML Kit Document Scanner provided by Google Play services. Per Google's documentation, the entire document scanner flow operates on-device: capturing the page, detecting its edges and correcting perspective all happen locally. The scanner module (its models and interface) is delivered and updated through Google Play services rather than bundled with the app.
Notarium does not send your scans anywhere. The resulting images are saved only to the app's local library. The camera is operated by the Google Play services scanner screen only while you are scanning, under its own permission rather than ours. Google Play services is a component of your Android device provided by Google and governed by Google's Privacy Policy.
Files, imports and exports
- Importing and exporting files goes through the Android system file picker, so the app only accesses the specific files and locations you choose.
- Exports from the notation editor — MusicXML, MIDI, PDF and PNG — are produced on the device and written where you point the picker. Nothing is rendered or converted on a server, because there is no server.
- The app does not access your contacts, location, microphone, or files you have not explicitly picked.
Purchases (Notarium Pro)
Notarium is free to use. A few features are part of Notarium Pro: print-ready PDF export (title page and printing margins), high-resolution PNG export, a whole setlist exported as one PDF, and the pro annotation tools — stamps, shapes, custom palettes, more than two layers, and exporting a page with your marks on it. Pro is sold as a subscription with a monthly or a yearly plan, or as a single one-time purchase. Everything else stays free: the library, the viewer, annotations, setlists and performance mode, the metronome and audio player, rehearsal mode, playing a score back from the library without opening the editor, the scanner, the notation editor with playback and transposition, MusicXML and MIDI export, and backing the library up to a file.
- Google Play takes the payment, not us. Buying opens Google Play's own purchase sheet. Notarium never asks for and never sees your card number, bank details or billing address; no payment data passes through the app, and none of it reaches us. We hold no payment information of any kind.
- What Google gets is what Google gets for any Play purchase: the Google account signed in to the Play Store on your device, the product bought, the price and country, and the payment method you picked there. That transaction is between you and Google, under Google's Privacy Policy and the Google Play Terms of Service. We send Google nothing about you: the app asks Play only about its own products, by product identifier.
- What the app gets back is the purchase record for our products. From it the app stores exactly two values on your device: whether Pro is on, and whether it came from the subscription or from the one-time purchase. Those two values are the whole of it: the order number, the account name and the address on the account are read from Play's answer by nothing and written nowhere, and the two values that are stored stay on the device.
- The purchase is checked on your device. Google signs every purchase, and the app verifies that signature locally against its public licensing key, which ships inside the app. The check runs offline; nothing is sent anywhere for it, because there is no server to send it to.
- Restoring a purchase asks Google Play what this Google account already owns for this app and turns Pro back on. That is the same local value being written again.
- Pro follows the Google account that bought it, since that is the account Play holds the purchase against. Refunds, cancelling a subscription and payment history live in your Google Play account, where we have no access to them.
Support letters
The settings screen has a "Support" page for writing to us. It is the only place in the app where anything travels outward, and it moves only when you send it.
-
The app sends nothing itself. The page fills in a
mailto:draft and hands it to whatever mail app you already use. You read it there and press Send yourself, from your own account. Nothing is transmitted if you close the draft. - What the letter carries is your own message, the app version, and — only if you leave it attached — a diagnostics report. The full text of that report is printed on the screen before anything is handed over, so you see every line of it rather than a promise about "diagnostic data".
- What the report is made of: the app version and language, the database schema number, whether the engraving library loaded, the platform and OS version, the manufacturer and model, the system locale, the screen size, free and total disk space, and how many songs, files, setlists and collections the library holds. Counts and versions only.
-
What the report is not allowed to contain: song
titles, file names, paths, setlist or collection names, or the text of
your annotations. The tail of the local error log does travel with it,
and file names, paths and quoted values in it are replaced with
<file>,<path>and<text>first. - Because it is mail, we see the address you send from, and the letter sits in our mailbox and in your Sent folder afterwards. If you would rather we did not have your address, write from an address you keep for this.
Analytics and advertising
The app contains no advertising SDK, no advertising identifier, no attribution SDK and no analytics of ours. Nothing profiles you, and nothing is shared with third parties for marketing.
Data retention and deletion
Nothing is collected from the app, so there is nothing for us to retain or to delete on your behalf — apart from any support letter you chose to send us, which we keep in our mailbox and delete on request to the address below. Your data lives on your device for as long as you keep it: individual scores, annotations and setlists can be deleted in the app, and uninstalling Notarium removes everything it stored — including the Pro flag, which a restore brings back from Google Play. The record of a purchase itself is kept by Google in your Play account, under Google's retention rules rather than ours.
Children
Notarium does not collect personal data from anyone, including children.
Changes to this policy
If this policy changes (for example, if a future version adds optional cloud backup), the updated text will be published at the same address with a new effective date before the change takes effect.
Contact
Questions about this policy or your data: notarium@gi-gante.com