Privacy Policy — Tacky: Notes for Places
Last updated: October 4, 2026
Tacky (“the app”) is a notes app made by Jakub Kidacki
([email protected]) (“we”,
“us”). This policy explains what data the app handles, where it goes, and why.
It applies to the Tacky app (package id com.pixeldreamland.locationnotes) on
Android and iOS.
The short version
- Your notes, saved places, and alerts are stored on your device. We never see them, and there is no Tacky account. If you turn on the optional “Sync across your devices”, an encrypted copy goes to your own Google Drive (Android), in a hidden folder only Tacky can use, or to your own iCloud (iPhone and iPad) — never to us (see “Sync across your devices” below).
- The app has no analytics, no advertising, and no crash-reporting SDKs. Nothing about how you use the app is sent anywhere.
- A few features send small, specific pieces of information to outside services only when you use those features, described below.
- Background location is used only to power alerts you’ve turned on. The app does not keep a history of your location, and your raw location is never uploaded anywhere — but if you have a brand/category alert enabled, moving around can, in the background, trigger a small download of place data for your new area (see “Brand and category alerts” below).
What stays on your device
Everything you create in the app — notes, fragments (text, checklists, images, links), saved places, alerts, and settings — is stored in a local database on your device and is never transmitted to us or to any server we control. We do not operate a backend for this app and have no way to see your data.
Private notes are encrypted on your device (AES-256-GCM): their text, checklists, links and photos are stored encrypted, with a key kept in your device’s secure storage (Android Keystore, or the iOS Keychain). If you turn on sync, that same key becomes your sync key (see below). A private note’s title is not encrypted, because the app shows it in lists, links and search; neither are its location, colour, and created/changed dates. Private notes can also be locked behind your device’s own screen lock or biometric unlock (fingerprint/face). An unlocked private note can’t be screenshotted, and alert notifications for it just say “Private note”. If your device has no screen lock or biometric set up, there is nothing to authenticate against, so private notes open without a prompt, though their content is still encrypted on disk.
Photos you attach to notes come from your camera or photo library and are stored on your device as they are, including any location data (EXIF) your camera recorded in them. They leave your device only inside an encrypted sync (if you turn sync on), an export you create yourself (see “Exporting your data”), or when you open a photo in another app yourself (not possible for a private note’s photos).
Sync across your devices (optional)
Sync is off until you turn it on in Settings → Sync. It syncs between devices of the same kind: Android devices through Google Drive, iPhones and iPads through iCloud.
On Android (Google Drive)
When it’s on:
- Where your data goes. Your notes (including private and trashed ones), places, alerts (their settings, not when they last fired), templates and photos are copied to your own Google Drive, into Tacky’s hidden app folder. That folder counts against your Drive storage, isn’t visible in the Drive app, and other apps can’t read it. Your other Android devices signed in to the same Google Account read it from there. Each item also carries your device’s model name (e.g. “Pixel 8”), used to label a conflicting copy, inside the encryption. Nothing is ever sent to us: we don’t run a server, and we never receive your data or your key.
- Encrypted before it leaves your device. Every item is encrypted on your device (AES-256-GCM) with a random key created for your account, so what’s stored in Drive is unreadable without that key. Google can see only how many items there are, what kind each is (note, place, photo…), their sizes and when they change. Settings, the private-note lock, and per-device choices such as “Location alerts on this device” are not synced.
- Google sign-in is used only to get access to that hidden app folder
(the
drive.appdatapermission). Tacky can’t see your other Drive files, your contacts, or anything else in your Google Account, and doesn’t keep your name or email address. It keeps only an anonymous identifier of that account on the device (Drive’s permission id for it), to notice if you switch accounts. - Where the key is kept. So your other devices can get the key with one tap, it’s saved as a password named “Tacky sync key” in your Google Password Manager (in your Google Account). Google Password Manager protects passwords with your account; they’re private from Google itself only if you’ve turned on on-device encryption for Google Password Manager. If you haven’t, Google could in principle read the key, and with it the encrypted copy in your Drive. So we don’t describe Android sync as end-to-end encrypted from Google unless you’ve turned that setting on. The key is also kept on each device that syncs, protected by Android’s keystore, so sync can run in the background.
- Recovery code. Settings → Sync → “Show recovery code” (after your screen lock) shows the key as a code you can write down. If you lose your Google Account, every device, and the recovery code, the synced copy can’t be decrypted by anyone, including us.
- Turning it off. “Turn off sync” keeps everything on this device and stops syncing; you can also choose to delete the copy in Google Drive. Your other devices keep their own copies (and if they’re still syncing, they upload theirs again). At any time you can also delete Tacky’s hidden data in Google Drive on the web (Settings → Manage apps → Tacky → Delete hidden app data), remove Tacky’s access in your Google Account’s security settings, and delete the “Tacky sync key” entry in Google Password Manager.
On iPhone and iPad (iCloud)
When it’s on:
- Where your data goes. Your notes (including private and trashed ones), places, alerts (their settings, not when they last fired), templates and photos are copied to your own iCloud: Tacky’s private CloudKit database in your Apple Account, which counts against your iCloud storage and which only Tacky, signed in as you, can read. Your other iPhones and iPads signed in to the same Apple Account read it from there. There’s no separate sign-in: Tacky uses the Apple Account your device is signed in to, and reads only an anonymous identifier of that account (to notice if you switch accounts), never your name or email address. Nothing is ever sent to us: we don’t run a server, and we never receive your data or your key.
- Encrypted before it leaves your device. Every item is encrypted on your device (AES-256-GCM) with a random key created for your account, so what’s stored in iCloud is unreadable without that key. Apple can see only how many items there are, what kind each is (note, place, photo…), their sizes and when they change. Settings, the private-note lock, and per-device choices such as “Location alerts on this device” are not synced.
- Where the key is kept. The key is saved in your iCloud Keychain, which Apple protects with end-to-end encryption, so your other Apple devices get it automatically and neither Apple nor we can read it. (If iCloud Keychain is turned off, the key stays on this device and your other devices will ask for the recovery code.) A copy is also kept in this device’s own keychain, so sync can run in the background; like other keychain items, it stays on the device even if you delete the app.
- Recovery code. Settings → Sync → “Show recovery code” (after Face ID, Touch ID or your passcode) shows the key as a code you can write down. If you lose your Apple Account, every device, and the recovery code, the synced copy can’t be decrypted by anyone, including us.
- Turning it off. “Turn off sync” keeps everything on this device and stops syncing; you can also choose to delete the copy in iCloud. Your other devices keep their own copies (and if they’re still syncing, they upload theirs again). At any time you can also delete Tacky’s iCloud data in the Settings app (your name → iCloud → Manage Account Storage → Tacky → Delete Data).
Location
Foreground location is used to sort your notes by distance and to show which ones are “here now.”
Save my spot saves a note at your current location, with its address (from the geocoding service described below). Find my way back points you to a note’s location using your phone’s compass, on the device only. Tapping Walking directions opens Google Maps (or Apple Maps on iPhone and iPad) with that spot’s coordinates as the destination; from then on, that app’s own privacy policy applies.
Background (“Always”) location is used only to power alerts you create — a notification when you enter or leave a place, a chain (e.g., “any McDonald’s”), or a category (e.g., “any supermarket”) you’ve chosen to be notified about. If you have no alerts turned on, the app doesn’t request or use background location at all.
To do this, the app monitors a small number of geofences (invisible virtual boundaries) around the locations your alerts need, and keeps them centered on roughly where you are by watching for when you leave the currently covered area. The app does not keep a history of your past locations or route — the geofencing plugin it uses is configured not to retain a location log, and the app itself only ever remembers your single most recent rough location (stored locally on your device, so it can pick the right nearby geofences the next time it needs to); that value is overwritten every time it updates and is never transmitted anywhere (other than in your device’s own backups, see below).
However: if you have a brand or category alert enabled, moving into a new area — including while the app is in the background or fully closed — can by itself trigger the app to fetch place data for that new area, as described next. This is the one way background location use can lead to a network request without you actively opening the app.
Brand and category alerts (place data)
If you set an alert for “any branch of a brand” or “any place of a type” (e.g., “any supermarket”), the app needs to know where nearby matching places are, and re-fetches that data as you move — at app start, whenever you add or change such an alert, and automatically in the background when you move far enough that your cached data no longer covers you (from a few hundred metres in a dense city up to 15 km, at most once every 10 minutes per alert), or after about a week regardless of movement.
In the version of the app you install from Google Play or the App Store, this data comes from a pre-built, read-only grid of map files (“tiles”) we host on GitHub Pages, built in advance from OpenStreetMap data. Each request downloads the tile(s) covering a rough ~30 km radius around you (a handful of files, each covering roughly 20 km × 20 km), so the host sees only which rough tile files were requested and when, never your exact coordinates. Tile files are cached on your device and reused for about a week before being re-downloaded.
A development/test build of the app that isn’t the one published on the stores can instead be configured to query OpenStreetMap’s public Overpass API directly — and that query does include your exact coordinates at the time. This mode is never used in the published app; it’s mentioned here only for completeness.
Google Maps and Google Places
The app uses the Google Maps SDK to display maps, and the Google Places API when you search for a place by name or address (autocomplete) or select a search result (place details).
- When you view a map, Google’s map-tile servers receive requests for the map tiles needed to draw the area you’re viewing — standard for any app that shows a Google Map, and handled under Google’s own privacy policy.
- When you type in the place search box, the text you type is sent to Google’s Places API to get suggestions, along with your current location (when available) so Google can prioritize nearby results; when you pick a result, its place ID is sent to Google to get its address and coordinates. This only happens when you actively search — it is not triggered by simply opening the app.
- If you save a place found this way, its place ID (not your location) is sent back to Google roughly every 25 days to refresh its coordinates (Google’s terms only let apps cache them for up to 30 days). This runs for every saved Google-sourced place whenever you open the app; a separate, less frequent background task additionally refreshes only the saved places that an active alert of yours actually depends on, so alerts stay accurate even while the app isn’t open.
See Google’s Privacy Policy for how Google handles this data.
Reverse geocoding (turning coordinates into an address)
Whenever a note gets a location — whether it’s added automatically when you start a new note, or you pin one on the map yourself — the app asks your phone’s built-in geocoding service to turn the coordinates into a readable address to show you. This uses the operating system’s own location-lookup service (provided by Google on Android and by Apple on iOS, not by us), governed by their respective privacy policies. If the lookup fails, the app just shows “Pinned location” instead.
Notifications
Alert notifications (“you’ve arrived near X”) and any other notifications the app shows are generated entirely on your device using your phone’s local notification system. The app doesn’t use any push-notification service, and no notification content is sent to us or anyone else.
Exporting your data
The app can create a backup file (a .zip containing your notes — including
private and previously trashed ones — places, alerts, templates and photos)
when, and only when, you choose to export it. The archive itself is not
encrypted or password-protected: whoever has the file can read everything
in it, except private notes, whose content and photos stay encrypted with
your key, as they are on the device (their titles, locations and dates are
readable), so treat it as sensitive. Exporting private notes asks for your
screen lock first, and importing the file on another device opens them only
if that device has the same key. The file is created locally on your device
and handed to your phone’s normal share sheet or saved where you choose
(e.g., a file, an email, cloud storage you pick). We never receive a copy,
and nothing is exported automatically or in the background.
Sharing a note
You can share a single note as text, an image or a PDF through your phone’s share sheet. This happens only when you tap Share, and the copy goes wherever you send it. It contains what’s written in the note (for a saved spot, that includes its address and directions link) but not the note’s pinned location. A link to a private note is shared as that note’s title only, and a locked private note can’t be shared.
Backups made by your device’s operating system
Independently of the export feature above, your phone’s own operating system may back up the app’s data as part of its normal device backup system — Android’s Auto Backup (to your Google Account) or iOS’s device/iCloud backup — the same as it does for most apps. This can include your notes, places, alerts, photos, and your most recent rough location (see “Location”). Private notes stay encrypted in these backups (their titles, locations and dates don’t), and the encryption keys aren’t included, so private notes restored onto a new device can be opened only if it gets the key through sync (or its recovery code). This is controlled by your device’s own backup settings, not by us; see your device’s backup/account settings if you want to exclude app data from it.
What we don’t do
- We don’t collect analytics or usage statistics.
- We don’t show ads or use advertising SDKs.
- We don’t use crash-reporting or telemetry services.
- We don’t have user accounts, and we don’t run any server that stores your data. Optional sync goes to your own Google Drive or iCloud, encrypted (see “Sync across your devices”).
- We (the developer) never receive your notes, places, alerts, or photos — they’re never sent to us in the first place, so there’s nothing of yours for us to sell or share. The specific outside services above (Google, our tile host, your phone’s OS) only ever see the specific, limited piece of information described for that feature, and only when you use it.
A note on standard internet traffic
Like any app that connects to the internet, every request the app makes — to Google, to our tile host, or (development builds only) to OpenStreetMap’s Overpass service — reveals your device’s IP address and ordinary technical request details (timing, approximate network location) to that service, the same as visiting any website does. That’s a normal, unavoidable part of how the internet works, not something this app adds on top; it’s separate from the app-specific data described in each section above. Google’s own data collection through its Maps/Places SDKs (for its own purposes, not ours) is covered by Google’s Privacy Policy, linked above.
Children’s privacy
The app is not directed at children and we do not knowingly collect personal information from children. As explained above, the app is built so that we never receive personal information from any user in the first place, which is naturally true for children’s use of the app as well.
Your choices and control
- You can deny or revoke location and notification permissions at any time in your device’s settings; the app degrades gracefully (notes just won’t be sorted by distance, and alerts won’t fire).
- Deleting a note, place, or alert in the app removes it from your device. A deleted note first moves to Trash rather than disappearing immediately; it’s permanently erased only once you delete it from Trash (there’s no automatic expiry). With sync on, the same happens on your other devices and in the encrypted copy in your Google Drive or iCloud. With sync off, a delete stays on this device: if you turned sync off without deleting the copy in Google Drive or iCloud, that copy (as of when sync was last on) stays there until you delete it (see “Turning it off” above); if you never turned sync on, there’s no copy anywhere else to delete.
- Uninstalling the app removes all of the app’s local data, subject to your operating system’s normal app-data rules — though a prior OS-level backup (see above) may still exist until you clear it separately.
Changes to this policy
If this policy changes, we’ll update the “Last updated” date above and, for material changes, note it in the app’s release notes.
Contact
Questions about this policy or the app’s data handling: Jakub Kidacki, [email protected]