Privacy Policy for Yanuma
This Privacy Policy describes how Yanuma ("the app") handles information when you use the Android application package com.yanuma.
Overview
Yanuma is a personal memory app: notes, tasks, events, and other moments of your life are stored in one connected "life graph" on your device, and an on-device AI assistant helps you capture and find them.
The app is local-first by design. It does not require an account, does not ask you to register, and does not send your notes, tasks, memories, audio, or documents to the developer. There is no developer server that stores a copy of your data.
Information stored on your device
To provide its features, the app stores the following data locally, in a single database encrypted with AES-256 (SQLCipher). The encryption key is protected by your device's secure hardware keystore:
- notes, tasks, reminders, and other entries you create;
- the connections between them (the life graph) and search indexes built from them;
- read-only copies of calendar events, if you allow calendar access;
- labels computed on-device from photos you choose to index, and locations you define for reminders;
- app settings, consent decisions, and a local access log that shows you every time data was used;
- diagnostic logs in a small ring buffer, kept only on the device (see Diagnostics below).
Android's automatic cloud backup is disabled for the app's data
(android:allowBackup is set to false). The only backups are
the ones you create with the app's own encrypted backup and export
features, protected by a passphrase or a 12-word recovery phrase that
only you know.
Permissions used by the app
All permissions are requested just-in-time, when you first use the feature that needs them. Declining a permission never breaks the rest of the app.
- Calendar (read) — to show your events on your timeline and in answers. Events are mirrored into the local encrypted database and are not uploaded anywhere.
- Microphone — for voice input in the Ask screen. Speech recognition runs on-device whenever your phone supports it (see Voice input below).
- Location — for location-based reminders you set. Geofences are evaluated by Android on your device; your location history is not collected or transmitted.
- Notifications — to deliver the reminders you create.
- Internet — used only for the optional end-to-end encrypted sync between your own devices (see Sync below) and, if you explicitly allow it, the device vendor's speech service. It is not used to upload your data to the developer.
On-device AI
The AI assistant, semantic search, and photo labeling run entirely on your device using local machine-learning models. Your questions, answers, and the content they draw on stay on the phone. No prompt, embedding, or model output is sent to the developer or any cloud AI service.
Voice input
Voice input uses your phone's on-device speech recognition whenever it is available, so audio never leaves the device. On phones without on-device recognition, the app can fall back to the speech service provided by your device manufacturer — that service may process audio in the manufacturer's cloud. The app never uses this fallback silently: it asks for your explicit consent first, and every use is recorded in the app's local access log. You can revoke this consent at any time in the Data inventory screen.
Sync between your devices (optional)
You can pair your own devices to keep your memory in sync. Sync is end-to-end encrypted: changes are packed into envelopes encrypted on your device for your paired devices only (AES-256-GCM with per-device key agreement). The relay server that passes envelopes between your devices cannot decrypt them — it only ever sees ciphertext, sizes, and timestamps, and it stores no account information because there are no accounts.
Sync is off until you pair a device, requires your explicit consent before anything is sent, and every transmission is recorded in the app's local access log. Pairing codes contain only public information (a device identifier and a public key).
Diagnostics and crash information
The app does not include third-party analytics, advertising, or crash reporting SDKs, and it does not upload crash reports automatically. Diagnostic information (a short ring buffer of technical logs and, if a crash happens, a crash record) stays on your device. If you contact support, you can export a diagnostics bundle yourself from the Diagnostics screen; personal content is scrubbed from it, and you choose where the file goes.
Purchases
Optional premium features, when offered, are processed through Google Play Billing. Google may process purchase-related and technical data under its own terms and privacy policies. The app uses purchase information only to determine whether premium features should be available on your device. Free features work without any account or server.
Data sharing
The developer does not sell or share your personal data. The app is not designed to upload your notes, tasks, memories, audio, or photos to the developer's servers.
When you use Android's share function to send content into or out of Yanuma, the handling of that content is governed by the app you choose to share with.
Third-party services provided by Google (Google Play app distribution, Google Play Billing, Google Play services on-device components such as the code scanner used for device pairing) may process data as needed to deliver their services under Google's policies.
Data retention and deletion
Your data is retained only on your device, for as long as you keep it. You can delete individual entries at any time; deleted entries go to an in-app trash for 30 days and are then permanently removed.
You can erase everything with the app's full deletion feature, which performs a cryptographic erase of the encrypted database, or by clearing the app's data in Android settings, or by uninstalling the app. Because the developer keeps no server-side copy, there is nothing to delete anywhere else. If you enabled sync, envelopes stored on the relay expire and cannot be decrypted without your devices' keys.
Children
The app is not directed to children under 13. If the target audience selection in Google Play changes in the future, this policy will be reviewed and updated accordingly.
Changes to this policy
This Privacy Policy may be updated from time to time. Material updates will be reflected on this page by changing the "Last updated" date.
Contact
For privacy questions or support requests, use the developer support contact listed on the Google Play store page for Yanuma. The Google Play listing is the authoritative contact point for the current version of this app.