🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
LensNote

LensNote Privacy Policy

How LensNote handles your local journal, optional account, Drive copies and diagnostics.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Working journal Stored locally on your device
Usage measurement Firebase Analytics is initialized without an in-app opt-in
Drive copies Record archives are encrypted; separate photo files are not
Privacy requests [email protected]
On this page
  1. Overview
  2. Data we handle
  3. How we use data
  4. Sharing and processors
  5. Cloud and backups
  6. Retention
  7. Security
  8. Your rights
  9. Children
  10. International transfers
  11. Changes
  12. Contact

LensNote keeps its working journal local while clearly separating the optional services that process limited data.

Overview

Blue Sparrow is a solo developer based in India and operates LensNote, a local-first journal, mood tracker, task manager and reflection app. This policy explains the information LensNote handles, why it is needed, where optional providers become involved and how to make privacy choices.

LensNote is designed around data minimisation, purpose limitation, transparency and the rights provided by the EU General Data Protection Regulation, UK GDPR and other applicable privacy laws. Its working journal database stays on your device. Optional account, purchase, support, configuration, measurement and Google Drive features have separate data flows described below.

Local-first does not mean no connections

You can journal as a guest, but the installed app still initializes Firebase services including Analytics and Remote Config. Signing in, buying Premium, submitting support or using Drive creates additional provider connections.

Data we handle

LensNote may handle these categories:

  • Journal text, timestamps, moods, activities, prompts and the photos you add.
  • Personal tasks, due dates, completion state and task notes.
  • Locally calculated patterns such as streaks, mood trends, activity relationships and Year in Pixels views.
  • Preferences such as theme, onboarding state, reminder schedules, notification choices, backup settings and photo-upload quality.
  • App-lock information and device authentication results used to protect access locally. LensNote does not receive your biometric template.
  • Optional Google and Firebase account information including the account identifier, email address, display name, profile-image URL, provider labels and sign-in timestamps.
  • Limited Firestore entitlement information for signed-in users, such as Premium or VIP status, product identifiers, subscription state and expiry information.
  • Purchase and entitlement information handled by Google Play and RevenueCat, including products, receipts, transaction identifiers, renewal state and subscription status. Blue Sparrow does not receive your full payment-card details.
  • Firebase Analytics information when collection is active, which may include screen or route activity, app interactions, app and device information, approximate technical location derived by the provider, and provider identifiers. LensNote does not intentionally send journal text, moods, tasks or photos as Analytics event parameters.
  • Remote Config fetch information and Firebase App Check or Play Integrity attestation information used to configure and protect connected features.
  • Support or feedback information that you choose to submit, including reply email, optional name and topic, message, app version, platform and locale. Extra diagnostics are included only when you consent in the support flow.

Camera, photo-library, notification, exact-alarm and biometric capabilities are used only for the feature you request. Reminder content and on-device insight calculations are not sent to Blue Sparrow merely because you use those features.

How we use data

Information is used as reasonably necessary to:

  • Save, display, edit, search and delete your local journal, tasks and photos.
  • Calculate local mood, activity and journaling insights.
  • Schedule reminders and authenticate an optional app lock on your device.
  • Authenticate an optional account and associate the correct profile, backup and Premium entitlement.
  • Create, find, restore and remove LensNote files in the hidden app-data area of your Google Drive when the relevant signed-in feature runs.
  • Process purchases, restore entitlements, provide Premium features and reduce purchase abuse.
  • Fetch limited feature configuration, measure app use, understand navigation and maintain reliability.
  • Receive, route and answer support or feedback that you choose to submit.
  • Protect users and connected services and meet applicable privacy, consumer, security and record-keeping requirements.

Firebase Analytics is initialized during app startup and a Firebase Analytics navigation observer is attached to the app. The current app has no in-app Analytics consent switch and does not call the SDK method that disables collection. Collection can still depend on Firebase, build, operating-system and device settings. This replaces older wording that described Analytics as opt-in.

LensNote does not sell or rent personal information, use journal content for targeted advertising or request Android advertising-ID permission.

Sharing and processors

Blue Sparrow does not share personal information for independent advertising. Limited information may be processed by:

  • Google and Firebase for Analytics, Remote Config, App Check, optional Google sign-in, Firebase Authentication, the limited Firestore user record and Google Drive access.
  • Google Play and RevenueCat for products, purchases, receipts, subscription status, entitlement delivery, restoration and store updates.
  • Blue Sparrow's constrained support-request service and its delivery providers when you submit a contact or feedback request.
  • Operating-system providers for notifications, exact alarms, camera or photo selection, local authentication, secure storage and device backup behavior.
  • Infrastructure, security or professional service providers where reasonably necessary to operate, protect or meet obligations relating to the service.

These third-party providers process information under their own terms and privacy notices. Blue Sparrow may also disclose limited information when legally required or reasonably necessary to address fraud, abuse or a serious security threat.

Cloud and backups

Guest use does not upload the working journal database to Firebase or a Blue Sparrow journal server. If you sign in with Google, Firebase Authentication and a limited Firestore user document receive the account and entitlement information described above. Firestore does not hold your journal entries, tasks or photos.

LensNote requests the Google Drive app-data scope for its hidden files rather than general access to your visible Drive. A backup exports supported journal records, task records and attachment references, creates an archive and encrypts that archive on the device with AES-256-GCM before upload. The key is derived from the signed-in Firebase user identifier and cached in secure device storage, so restoring depends on access to the same identity.

Photos are handled separately from the encrypted record archive. While you are signed in, adding a journal photo causes LensNote to attempt an immediate upload of that media file to the hidden Drive app-data area, even if a full backup has not just run. These separate media files are uploaded as their file bytes and do not receive LensNote's AES-256-GCM archive encryption. Google still protects transport and storage under its own controls, but do not treat those photo copies as having the same app-level encryption as the record archive.

Drive backup and media transfer are best-effort convenience features, not guaranteed complete synchronization. Missing, unreadable or failed photo uploads can leave a backup without every attachment. Automatic scheduling, retention cleanup, restore and deletion can also be affected by network, account, operating-system or Google service conditions.

Google controls the physical location and regional handling of files in your Drive account. Signing out stops authenticated backup activity and clears LensNote's cached encryption key on that device, but does not itself delete files already in Drive.

Retention

Local journal information remains until you delete individual content, use the local wipe controls, clear app storage or uninstall the app. Uninstall behavior may differ where device or operating-system backup is enabled.

Drive record archives and separate media files remain until you delete them, use LensNote's optional Drive cleanup during account deletion, LensNote removes older archives under its best-effort retention configuration, or Google applies its own retention rules. Removing one backup archive does not necessarily remove shared media files.

The signed-in account-deletion flow first requires fresh Google authentication. It attempts to delete the Firestore user document and Firebase Authentication user, clear the local RevenueCat cache, end the RevenueCat session and revoke Google access on that device. Drive cleanup and local-device wiping are separate options selected in that flow. Drive deletion targets hidden files whose names match LensNote's backup and media patterns. Local wipe targets the journal database, tasks, attachment records and files, reminders, backup schedule, preferences and secure keys on that device. Individual cleanup steps can fail and the app reports warnings.

Google Play and RevenueCat may retain purchase records under their own requirements even after app-account deletion. Submitted support messages and delivery records remain only as needed for support, abuse prevention and operational records, then are deleted or de-identified under the relevant process.

Security

LensNote uses proportionate safeguards including device storage controls, optional PIN or biometric app lock, secure key storage, HTTPS, Firebase App Check, signed-in Firestore rules, scoped Drive access and AES-256-GCM encryption for record archives. Access within Blue Sparrow is limited to the solo operator and providers that need information for their assigned purpose.

Separate Drive photo files do not receive the archive encryption described above. No device, transfer or connected provider can be guaranteed completely secure. Protect your device, Google account and store account, install trusted updates and avoid including unnecessary sensitive content in support requests.

Your rights

Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, obtain a portable copy, delete it, restrict or object to processing, withdraw consent where consent is the basis, and complain to a local data-protection authority. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy laws, Brazil's LGPD, Canadian privacy laws, Australian privacy rules and comparable laws elsewhere.

Most journal information can be viewed, changed or deleted directly in LensNote. You can decline or revoke camera, photo, notification, exact-alarm and biometric access in device settings; stop Drive features by signing out; manage Drive files through LensNote's controls; and manage subscriptions through Google Play. The current app does not offer an in-app Analytics opt-out. Device or platform controls may still apply.

Email [email protected] with LensNote and enough detail to identify the account or request. Blue Sparrow may request proportionate verification and will respond within the period required where you live. Ordinary requests are not charged, although clearly excessive or repeated requests may be handled as applicable rules permit.

Children

LensNote is a personal reflection app for a general audience and is not designed to collect children's personal information. A parent or guardian should supervise use by anyone who cannot make their own privacy choices. Do not create an account, enable cloud features, purchase a subscription or submit support information for a child unless the responsible adult has a valid basis and provides any required permission. Contact [email protected] if you believe a child's information has been provided inappropriately.

International transfers

The working journal database stays on your device. Google, Firebase, RevenueCat, Google Play and support connections may process limited information outside your country or region. Where transfer safeguards are required, Blue Sparrow and the relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and use data-minimisation and security measures.

Blue Sparrow does not claim that every item of LensNote information remains exclusively in the European Union. EU users receive the protections required by the EU GDPR, while provider-controlled identity, analytics, purchase, security, support and Drive information follows each provider's disclosed infrastructure and transfer safeguards.

Changes

This policy may change as LensNote, its providers or applicable requirements evolve. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised. Earlier processing remains covered by the version applicable at that time unless a change must apply sooner for security or another mandatory reason.

Contact

Blue Sparrow is the developer and privacy contact for LensNote. For privacy questions, rights requests or account-data deletion, email [email protected]. For general support, email [email protected]. Current product and policy information is available at https://bluesparrow.dev.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.