Norfold legal

Privacy Policy

Alpha notice: Norfold is in heavy testing. Back up your data before using sync, import, export, vault, or attachment features.

Norfold stores notes, tasks, chats, canvas items, files metadata, settings, and sync-chain metadata locally on your device unless you explicitly choose backup, import, export, sync, or crash reporting features. Crash reporting is the only one of those that sends anything on its own once enabled; it is described under Diagnostics And Crash Reporting below.

Data You Choose To Store

The app may store note text, Markdown, task fields, workspace names, profile names, cover image URIs, attachment metadata, sync folder references, diagnostic logs, and encrypted backup payloads.

Google Drive Sync

When you connect Google Drive, Norfold requests Drive access only for app sync data needed to upload, download, and compare sync-chain snapshots. Google account authorization is handled by Google's OAuth flow.

Diagnostics And Crash Reporting

The setting Enable diagnostics and crash reporting, in Settings under Diagnostics, governs two things at once. Locally, crash and error details are recorded on the device so you can review them or attach them to a report yourself. Remotely, while the setting is on, crash reports are also sent automatically to Google Firebase Crashlytics, a Google service, so defects can be fixed without waiting for a report.

A crash report contains the error, the stack trace and the place in the app's code where it happened, the app identifier and version, whether the app was in the background, and information about the device: model, operating system version, CPU architecture, available memory and disk space, screen rotation, and whether the device is rooted. It also carries randomly generated identifiers Crashlytics uses to group crashes and to count how many devices a defect affects. It does not contain your note text, titles, task names, chat messages, workspace or profile names, file names, attachment contents, Google account identity, or the contents of a vault or backup. Norfold attaches no custom keys and no user identifier of its own, so a report is not tied to your account or to anything you have written.

Reporting is off until you turn it on. A newly installed build collects nothing before the setting has been read, and turning the setting off stops sending immediately and discards any report already recorded but not yet sent. No advertising identifiers and no usage or behavioural analytics are collected in either state, and nothing else in the app uploads diagnostics on its own. Google states that crash data is retained for 90 days; its handling of what it receives is described in the Firebase privacy documentation.

Security

Vault exports and backup containers are encrypted, but the live Room database is not encrypted at rest in this pre-beta build. The encryption design has not been independently audited. Keep independent backups of important information and use the device lock and storage protections supplied by Android.

Contact

If you received an alpha build directly, use the same private testing channel that supplied it. Norfold has no public support intake while public distribution is closed.

Last updated: August 24, 2026