Zenvut
Privacy Policy
Version 4.0 · Effective Date: October 11, 2026
Zenvut (the “App”) is a personal, offline-first note-taking app built with a local-first privacy design. All core features, including notes, Vault, backups, categories, reminders, and exports, work on your device without internet access, an account, or registration. The developer does not operate any server that receives your notes or personal data.
The App offers rich-text notes with categories, pinning, archive, and a Recycle Bin; a PIN or biometric Vault with Decoy Vault and Dead Man’s Vault; encrypted .znv backups; a Smart Planner with on-device reminders and an optional alarm mode; and PDF export and printing. It also has two optional, user-started local connection features, Open in Browser and Zen Room (Section 6).
Zenvut does not require or support user accounts, logins, cloud accounts, or subscriptions, and does not include:
• Advertising networks, advertising identifiers, or interest-based targeting
• Analytics, behavioural tracking, session-recording, or crash-reporting SDKs
• Any developer-operated server or cloud storage
The developer does not collect, sell, rent, or share your notes or personal information. Your email address reaches the developer only if you choose to send a feedback email yourself (Section 7).
Zenvut stores the following only in app-private storage on your device (a local SQLite database, private files, and Android Shared Preferences). None of it is sent to the developer or to any external server.
• Notes: titles, body text, categories, formatting, and timestamps, plus any photo or audio attachments already stored in a note. Note text and attachment files are encrypted at rest using Android Keystore-backed AES-GCM, and the keys never leave the device.
• Settings: profile name and avatar (a chosen avatar photo is stored as an encrypted private file), theme and planner preferences, Vault and biometric preferences (the Vault PIN is kept only as a PBKDF2-derived hash and salt), Auto Delete Bin, Dead Man’s Vault, backup, and PDF watermark settings, an encrypted Auto Backup PIN, backup history, a deletion-history list used for backup sync, on-device category-learning data, and counters that control the in-app review prompt.
• Reminders: linked note identifier, title, scheduled time, recurrence, priority, and status.
The App opts out of Android Auto Backup (allowBackup is disabled), so Android does not copy this data to cloud backups.
Backups are created only through 1-Tap Backup or optional Auto Backup. A .znv backup is encrypted with AES-GCM using a key derived from your backup PIN through PBKDF2-HMAC-SHA256 (160,000 iterations, random 16-byte salt). It contains your active, non-deleted notes, including archived and Vault notes, and their attachments, which are re-encrypted with the same backup-PIN key. Zen Room notes are not included. The encrypted payload also records the backup time, a format version, and your device’s model name (Android Build.MODEL), used only to label backup history.
Backups are saved to a folder you choose with Android’s system folder picker, or to app-internal storage if none is available. If that folder belongs to a provider such as Google Drive, the provider may synchronise the encrypted file under its own privacy policy; the developer cannot access it. To allow scheduled backups without retyping the PIN, the App keeps an encrypted copy of your default Auto Backup PIN protected by Android Keystore; your backup PIN is never transmitted. When Auto Backup is on, the App may merge changes into the existing encrypted backup after you save, archive, restore, or delete notes. This happens only between your device and the location you selected.
Task detection and categorisation run entirely on your device using local keyword and date/time logic; no note text is sent anywhere. Reminders use Android alarm and notification features (exact alarms where allowed, an optional alarm-clock mode with a full-screen alarm screen, vibration, and Work Manager maintenance) and are rescheduled after the device restarts. Delivery timing depends on your Android version, battery settings, and manufacturer, so Zenvut cannot guarantee exact timing or that every note will be interpreted as you intend. Please check your reminders.
Once Android displays a notification, its text (such as a reminder title) is handled by Android and may appear on lock screens, wearables, notification history, or third-party notification tools you have enabled. Zenvut does not control how those services process it.
Open in Browser and Zen Room are off by default and run only when you start them. They never send data to the developer or to any developer-operated server, and they use network, Wi-Fi, Bluetooth, and nearby-device permissions only for the purposes below.
This feature starts a small web server on your device (port 8080, or 8081 or 8082 if needed), with a “Zenvut Sync Active” notification shown while it runs, so you can view and edit notes from a browser on another device on the same Wi-Fi network. You pair by typing the random pairing code shown on your device, or by scanning a QR code shown in the browser with the Google Code Scanner (Section 7). Repeated wrong pairing attempts are limited. After pairing, your Home notes (not archived, Vault, or Zen Room notes) and the attachments needed to display them are sent to the paired browser over your local network, and edits made there are saved to your device.
The connection uses standard HTTP and WebSocket on the local network without extra encryption, so use it only on a trusted private Wi-Fi network and treat the pairing code as sensitive. The web page served to your browser loads fonts and icons from Google Fonts and creates its pairing QR image with the api.qrserver.com service. These requests are made by the browser on the other device, not by the App, and they reveal that device’s IP address and a temporary browser session code to those services, which handle them under their own privacy policies. Stopping the server, or removing the App from recent apps, ends the session.
Zen Room lets a host create a shared room that other Zenvut users join by scanning the host’s QR code or entering the room PIN. The QR code contains the room PIN, the host’s local network address, and Bluetooth and Nearby connection details. Devices connect directly to each other over the same Wi-Fi network, Bluetooth, or Google’s Nearby Connections, with no Zenvut server in between. While a room is active, a “Zen Room” notification is shown and the host makes the room discoverable on the local network and to nearby devices.
Room participants receive your profile name and the titles and content of notes you add to or edit in the room, including edits and deletions. Messages are encrypted with AES-GCM using a key derived from the room PIN, and anyone who has the PIN can join, so share it only with people you trust. Zen Room notes are saved in local storage on each participating device, kept separate from regular notes, and excluded from backups and Open in Browser. Content you share may remain on other participants’ devices, and Zenvut cannot remove it from them. Nearby Connections is a Google Play services feature governed by Google’s terms and privacy policy.
Zenvut requests only the permissions needed for the features described above. Runtime permissions are requested when a feature is used, and if you deny one, only that feature is unavailable.
• Notifications, exact alarms, full-screen intent, vibration, boot completed, and battery-optimization exemption: to deliver reminders and alarms reliably and restore them after restart. The battery exemption is optional.
• Biometrics: Vault unlock through Android’s biometric prompt. Zenvut never receives fingerprint, face, or other biometric data.
• Internet, network state, and Wi-Fi state, change, and multicast: only for Open in Browser and Zen Room on local networks. They are not used to contact the developer or any advertising, analytics, or cloud service.
• Bluetooth (scan, connect, advertise) and Nearby Wi-Fi devices: only for Zen Room device-to-device connections.
• Location (Android 12 and below only): Android requires this permission for nearby-device discovery on those versions. Zenvut only checks whether the Location setting is on; it does not read, collect, store, or transmit your location.
• Foreground services and wake lock: to keep Open in Browser and Zen Room running while you use them.
Zenvut does not request Camera, Microphone, Contacts, SMS, Phone, or Storage and Media permissions. QR codes are scanned with the Google Code Scanner, which runs in Google Play services, and Zenvut receives only the decoded text. Avatar photos are chosen with the Android Photo Picker, and files are exported, imported, and backed up through Android’s system file pickers.
The App uses Google Play services components for the Code Scanner, Play In-App Review, and Nearby Connections. Zenvut does not pass note content to them, and Google’s privacy policy governs their operation. The review prompt appears at most once per app version after usage milestones, and Zenvut receives no rating or review data. Send Feedback opens your email app with a draft to support.zenvut@gmail.com containing the app version, device manufacturer and model, Android version, and any text you add; nothing is sent unless you send it. Links to the developer’s social pages or Google Play, and the Share option, open in your browser or another app under that service’s own policies.
• Vault and Decoy Vault: the Vault uses a PIN and optional biometrics. If a PIN is entered that does not match, locally generated placeholder notes are shown instead of your real Vault notes.
• Dead Man’s Vault: if enabled and your chosen inactivity period passes, the next launch permanently deletes all Vault notes and clears the Vault PIN hash, salt, and biometric settings. This is irreversible, and no data is transmitted.
• Screen protection: Vault-related screens, the Backup PIN screen, and the locked note editor use Android’s secure window flag, which blocks screenshots, screen recording, and recent-app previews of those screens.
PDF export, printing, copying to the clipboard, creating or importing backups, and sharing happen only when you start them, through Android system services. Clipboard contents, exported files, and printed pages may be accessible to other apps or services under their own policies, and once content leaves the App the developer is not responsible for how it is handled.
Notes in the Recycle Bin stay on your device until restored or permanently deleted. If Auto Delete Bin is on, eligible non-Vault notes are permanently deleted after 30 days. Permanent deletion also removes a note’s attachment files. You can delete your data at any time by deleting notes, resetting the Vault, clearing the App’s storage in Android settings, or uninstalling the App. Because the developer holds no copy of your data, there is nothing for the developer to access or erase on your behalf. Backup files you saved elsewhere must be deleted by you.
Zenvut is a general-audience app that is not directed at children under 13 (or the minimum age in your country). It has no accounts, advertising, analytics, or automatic personal-data collection, and the developer does not knowingly collect personal information from anyone, including children.
Zenvut is provided free of charge on an “AS IS” and “AS AVAILABLE” basis without warranties of any kind, express or implied. To the maximum extent permitted by applicable law, the developer does not guarantee availability, device compatibility, freedom from bugs, protection against every security threat, reminder delivery, or data preservation, and is not liable for any direct, indirect, incidental, special, consequential, or punitive damages arising from use of, or inability to use, the App. This includes lost, corrupted, or unrecoverable notes, backup, import, export, or sync failures, and security issues caused by the device, Android, or third-party software.
You are responsible for keeping your own up-to-date backups, remembering your Vault and backup PINs (the developer cannot recover them), protecting your device and any Zen Room PIN, verifying exported, imported, and shared data, and using the App lawfully.
This Privacy Policy may be updated to reflect changes in the App’s features or applicable legal requirements. Updated versions replace previous versions within the App or in the app store listing, and continued use of the App after an update means you accept the revised policy.
This Privacy Policy and the use of Zenvut are governed by the laws of India. To the extent permitted by applicable law, legal matters relating to the App or this Privacy Policy are generally handled under the laws and courts of Kolkata, West Bengal, India.
For privacy-related questions or concerns, please contact the developer:
Developer: Arnab Roy
Email: support.zenvut@gmail.com
By installing or using Zenvut, you acknowledge that you have read and understood this Privacy Policy, including that the App is free, your core data stays on your device unless you export, share, back up, or transfer it, the developer does not collect or have access to your notes or personal content, and use of the App is at your own discretion and risk.
Thank you for using Zenvut.