for the Android app “MultiSync Notes”
Version: 8 August 2026
1. Controller
The controller responsible for processing personal data in connection with “MultiSync Notes” is:
Christof Federowicz
St.-Leonhard-Straße 11
86500 Kutzenhausen
Germany
Email: notes@federowicz.de
2. Data Protection Principles
“MultiSync Notes” has been designed according to the principle of data minimization.
The Provider does not operate its own cloud server for storing user-created note contents and does not create user profiles.
The Provider currently does not use:
- its own analytics or tracking services;
- its own advertising or marketing services;
- profiles for analyzing user behavior;
- its own servers for storing note contents.
The app can generally be used locally on the user’s Android device.
Notes are transmitted to external servers only where the user activates a corresponding function, in particular cloud synchronization.
3. Local Storage
Notes, settings and other app data are generally stored locally on the user’s Android device.
The app uses Android components such as Room/SQLite and Android DataStore for this purpose.
Data is stored within the protected app storage provided by the Android operating system.
The Provider does not obtain access to the contents through this local storage.
4. Cloud Synchronization
Cloud synchronization is entirely optional.
If the user activates synchronization, the selected data is transmitted to the service selected by the user.
Supported services may include:
- Google Drive;
- Nextcloud;
- WebDAV-compatible servers.
The Provider does not operate its own cloud storage for note contents.
The Provider does not obtain access to the contents of synchronized notes through normal use of these synchronization functions.
The respective cloud or server provider’s privacy policy applies to its processing.
5. Google Drive
When Google Drive synchronization is used, the app accesses the application-specific data area to the extent provided by the Google API and the permissions actually requested by the app.
The app is not intended to access arbitrary other files or folders in the user’s Google Drive.
Google may process personal data in connection with Google Drive and Google Play under its own privacy policies.
Google is generally responsible as an independent controller for processing where Google determines the purposes and means of the processing.
6. Nextcloud and WebDAV
When Nextcloud or WebDAV is used, selected data is transmitted to the server specified by the user.
If the server is operated by the user, the user is responsible for the processing and security of data stored there.
If the server is operated by a third party, that provider’s privacy policy and responsibilities may apply.
The Provider of “MultiSync Notes” does not have administrative access to these servers.
7. Background Synchronization
Android WorkManager may be used for automatic synchronization.
WorkManager is used for the technical execution of background tasks on the Android device.
The Provider does not receive user profiles or ongoing usage data through WorkManager itself.
8. Export and Backups
The app allows users to export notes and other data managed by the app.
Depending on the selected function, export files may be encrypted. AES-256 may be used for this purpose.
The Provider does not have access to locally generated export files or encryption passwords selected by the user.
The user is responsible for securely storing export files and passwords.
9. Biometric Authentication
The app may be protected by an optional app lock.
When biometric authentication is used, verification is performed by the Android system functions.
The app does not receive biometric characteristics such as fingerprint images.
The app receives only the authentication result required for the authentication process.
10. Reminders and Notifications
Reminder times and local notifications are generally processed on the user’s Android device.
The Provider does not receive reminder contents for analytics or advertising purposes.
Relevant Android permissions may be required for notifications.
11. Network Communication
For communication with external cloud and server services, the app generally uses encrypted network connections such as HTTPS/TLS where supported and provided by the respective service.
For self-configured WebDAV or local servers, connection security additionally depends on the server configuration and network environment.
12. Permissions
Depending on the functions used, the app may require:
- Internet access;
- network access;
- local network access;
- notifications;
- exact alarms;
- biometric authentication;
- file access or Android’s file picker for import and export.
These permissions are used for the respective functions.
13. Google Play and Pro Purchases
The Pro version may be purchased through Google Play as a one-time in-app purchase.
Payment processing is handled by Google Play.
In connection with purchases, Google or Google Play may process personal data and technical information required for payment processing, purchase confirmation, fraud prevention, license management and provision of the purchased functionality.
The Provider does not receive the user’s complete payment details, such as credit-card or bank information.
For technical activation and management of the Pro functionality, the Provider may process technical purchase information or identifiers provided by Google Play where necessary for contract performance and license management.
Google’s privacy policies apply to processing carried out by Google.
14. Contact by Email
If you contact the Provider by email, the information you provide, including your email address and the contents of your message, will be processed.
Processing is carried out to handle and respond to your request and, where applicable, to comply with legal obligations.
Article 6(1)(b) GDPR may apply where the request relates to an existing or intended contractual relationship.
Article 6(1)(c) GDPR may apply where processing is necessary to comply with a legal obligation.
Article 6(1)(f) GDPR may apply to other inquiries where processing is based on the Provider’s legitimate interests and the statutory requirements are met.
15. Legal Bases
Where the Provider processes personal data itself, processing is based in particular on:
Article 6(1)(b) GDPR – where processing is necessary for the performance of a contract or pre-contractual measures.
Article 6(1)(c) GDPR – where processing is necessary to comply with a legal obligation.
Article 6(1)(f) GDPR – where processing is necessary for the purposes of the Provider’s legitimate interests, provided that the interests or fundamental rights and freedoms of the data subject do not override those interests.
The Provider does not process personal data for its own advertising, tracking or profiling purposes.
16. Retention
The Provider stores personal data only for as long as necessary for the relevant purpose or as required by law.
Local notes and app data remain on the user’s device until deleted by the user or until the app or its data is removed.
Data stored with an external service through synchronization is subject to that service’s retention and deletion rules.
17. Recipients
The Provider does not generally disclose personal data to third parties for advertising or profiling purposes.
Depending on how the app is used, external providers may independently process data, including:
- Google or Google Play for app distribution and Pro purchases;
- Google or Google Drive when Google Drive synchronization is enabled;
- the Nextcloud or WebDAV provider selected by the user.
The respective providers may act as independent controllers under data protection law. Their respective privacy policies apply to their processing.
18. International Transfers
Where external providers process or transfer personal data to countries outside the European Union or European Economic Area, such transfers are carried out in accordance with the applicable legal requirements.
For details, please consult the privacy information of the respective provider.
19. No Own Analytics or Tracking Services
The Provider currently does not use its own analytics, tracking, advertising or marketing services.
The Provider does not create user profiles for its own analytics or advertising purposes.
20. Data Subject Rights
Subject to applicable legal requirements, data subjects have rights including:
- access;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- objection;
- withdrawal of consent with future effect;
- the right to lodge a complaint with a data protection supervisory authority.
Because the Provider generally does not store actual note contents on its own servers, the Provider cannot delete or provide such contents from its own systems.
For data stored with an external cloud provider, rights may need to be exercised directly against the respective provider.
21. Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with a data protection supervisory authority.
This applies in particular in the event of an alleged violation of data protection law.
The competent authority is generally the supervisory authority of the data subject’s habitual residence, place of work or the place of the alleged infringement.
22. Automated Decision-Making
The Provider does not use automated decision-making, including profiling, in connection with “MultiSync Notes” that produces legal effects or similarly significantly affects users.
23. Changes to this Privacy Policy
This Privacy Policy may be updated if app functionality, external services, legal requirements or data processing practices change.
The current version will be made available within the app or at the designated location.
Version: 8 August 2026