NotiLog
Privacy Policy
Last updated: October 9, 2026
This Privacy Policy describes how NotiLog ("the app", "we") handles information when you use the application. By installing or using NotiLog, you agree to the practices described below.
No account
Opt-in sharing
No ads
1. Summary
NotiLog is a local notification logger. It captures the notifications your device receives and stores them on your device so you can browse, search, and recover dismissed or missed notifications.
- No account. NotiLog does not require or provide any login.
- Local by default. Your notification history is stored only on your device. A separate sharing feature can mirror notifications to one paired device — it is opt-in and off by default, end-to-end encrypted, and can be disabled at any time (§4).
- Network access is limited to two purposes: (a) the optional sharing feature, and (b) Google Play billing when you choose to buy the sharing unlock. We do not store your notification history in the cloud and there is no analytics or crash reporting.
- No ads. NotiLog shows no ads and ships no advertising SDK.
- Sharing unlock. Sending notifications to a paired device is a one-time in-app purchase (
unlock_sharing) with a 20-share free try. The purchase is processed by Google Play; we receive no payment details (§5).
2. Information NotiLog Accesses
2.1 Notification Data (Notification Access)
To function, NotiLog asks you to grant "Notification Access" (NotificationListenerService) in your device settings. When granted, the app receives copies of the notifications your device posts — for example the app name, title, text, sender, timestamp, and attached images of incoming notifications. This permission is optional; if you do not grant it, NotiLog cannot capture notifications.
You can revoke Notification Access at any time in your device's settings, after which the app will stop capturing new notifications.
2.2 Data You Create
- PIN (optional): If you enable Delete Protection, you set a numeric PIN. Only a salted, iterated cryptographic hash (PBKDF2-HMAC-SHA256) of the PIN is stored — the PIN itself is never stored or transmitted.
- Labels and exclusions: Conversation labels you set, and the lists of apps and keyword patterns you choose to exclude from capture.
3. Where Your Data Is Stored and How It Is Protected
- All captured notifications, labels, and exclusions are stored only on your device in a local database — unless you explicitly enable sharing (§4).
- The database is encrypted at rest using SQLCipher (AES-256). The encryption key is generated on your device and protected by the Android Keystore, which keeps it in hardware-backed secure storage where available.
- Notification images are stored in the app's private storage.
- Your PIN hash and app settings are stored locally in encrypted device storage.
- Android's auto-backup is explicitly disabled (
allowBackup="false"), so your data is not included in Google's device backup.
4. Sharing to a Paired Device (optional, off by default)
Sharing mirrors notifications to one other device that you pair with, in person.
- What is shared: the notification title, text, app name, and timing. Sharing is off by default and only runs while you have it enabled and a device paired.
- End-to-end encryption: a 256-bit key is generated on your device and exchanged with the paired device at pairing time. It is never sent to any server. Each message is encrypted with AES-256-GCM, so only your two devices can read it.
- Transport: in this release, messages are relayed through the public ntfy.sh service. The relay forwards ciphertext it cannot read, but it can observe metadata (the random topic name, message timing, size, and your IP address). No copy of your notifications is stored on the relay.
- Disable anytime: turning sharing off, or unpairing, stops mirroring immediately. Notifications already received on the other device remain on that device (they are stored in its own local history).
5. In-App Purchase (Google Play Billing)
Sending notifications to a paired device requires a one-time in-app purchase (unlock_sharing); each device may send up to 20 notifications as a free try first. Receiving is always free.
- The purchase is processed entirely by Google Play. We receive no payment details — no card numbers, billing addresses, or account credentials.
- The unlock is tied to your Google account and restores automatically on reinstall or a new device when you use the same account.
- The app stores only the unlock state (owned or not) locally on your device; there is no developer server and nothing is uploaded to us.
- We do not share your notification content (titles, text, senders) with anyone and never use it for advertising — there are no ads and no advertising SDK in the app.
6. Exclusions by Default
For your safety, NotiLog comes with default exclusions so that notifications from banking, two-factor authentication (2FA), password manager, and OTP-generating apps are not captured. You can review and change these exclusions at any time in Settings.
7. Backups and Transfer
- Export: You may choose to export your notification history to a file you control. The export is encrypted with AES-256-GCM using a passphrase you provide (derived via PBKDF2 with 100,000 iterations). NotiLog never stores this passphrase.
- Import: You may import a previously exported, encrypted backup to restore or merge data.
- NotiLog does not transmit these backup files anywhere; where the exported file goes is entirely under your control. This is separate from the optional sharing feature (§4), which transmits notification data end-to-end encrypted to your paired device.
8. Data Deletion
- You can delete individual notifications, all notifications from a specific app, notifications within a time window, or your entire history from inside the app.
- Deleting a notification removes its stored copy. Note that the original notification on your device or its source app is unaffected.
- Uninstalling NotiLog permanently deletes all data it stored on your device — there is no server copy to delete.
9. Children's Privacy
NotiLog is not directed to children under 13, and it does not knowingly collect personal information from children. Sharing is off by default, and the app contains no ads.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the latest revision. Continued use of the app after changes constitutes acceptance of the updated policy.
NotiLog — your private notification logger. Local by default, opt-in encrypted sharing, no ads.