1. Introduction & Core Philosophy
Recallr ("we", "our", or "the App") is developed and maintained by MinHackerz. Recallr is designed to serve as an intelligent, secure, and privacy-preserving notification archive, reminder engine, and financial transaction manager for Android users.
We believe your personal notifications contain sensitive, private information. Therefore, Recallr is engineered with a strict Local-First Architecture: your notification messages, senders, timestamps, and extracted records are processed and retained strictly on your physical device.
2. Information We Access, Process, and Store
A. Notification Messages & Content (Sensitive Personal Data)
To fulfill the core functionality of archiving and organizing notifications, Recallr uses Android's NotificationListenerService to capture incoming notifications as they arrive.
- Data Processed: Notification title, body text, subtext, timestamp, sender/app identifier, and channel categories.
- Purpose: Notification search, historical timeline view, category classification, smart reminders, and local financial tracking.
- Storage: 100% saved locally on your device in a sandboxed SQLite/Drift database.
- Sharing: Never transmitted to external servers, cloud databases, or third parties.
B. Installed Applications & Package Identifiers (QUERY_ALL_PACKAGES)
Recallr requires the QUERY_ALL_PACKAGES permission to identify which applications post notifications.
- Purpose: Resolving application names and app icons next to notifications in the timeline, allowing users to customize notification capture filters (blocking unwanted apps), and grouping notifications by application.
- Privacy Guarantee: Package queries are executed strictly on-device in real-time. We do not generate, upload, or monetize lists of your installed applications.
C. Financial Transaction Analysis (Local Parser)
Recallr includes an optional on-device financial insights engine that parses bank SMS and payment alerts (such as UPI, debit, credit notifications).
- Processing: Parsing runs completely locally using regular expressions and on-device text analysis.
- Security: No account numbers, transaction amounts, or merchant names leave your device.
D. User Account & Authentication (Optional)
If you choose to sign in via Google Sign-In or Firebase Authentication:
- Data Collected: Email address, display name, profile avatar URL, and Firebase User ID.
- Purpose: Managing your user profile and securing access to optional cloud features if enabled.
- Opt-Out: Account registration is optional; all core notification management features operate fully offline without logging in.
E. Diagnostics & Crash Reporting
We utilize Firebase Crashlytics and Firebase Analytics to monitor app stability and identify fatal bugs.
- Data Collected: Device hardware model, Android OS version, crash stack traces, app launch timestamps, and non-identifying aggregated metrics.
- Exclusion: Crash reports do NOT include the contents or bodies of your private notifications.
3. Android Permissions & Justifications
Recallr requests the following Android permissions to deliver core functionality. Each permission is strictly utilized as described:
| Permission | Category | Reason & Justification |
|---|---|---|
| BIND_NOTIFICATION_LISTENER_SERVICE | Core Service | Required to capture incoming system notifications and save them into the local database history. |
| QUERY_ALL_PACKAGES | App Visibility | Required to map package names to app icons and names, and enable per-app notification capture blocking rules. |
| POST_NOTIFICATIONS | UI / Alerts | Allows Recallr to post status notices, service health indicators, and scheduled reminder alerts. |
| SCHEDULE_EXACT_ALARM / USE_EXACT_ALARM | Reminders | Required for the native alarm clock engine to ring user-scheduled notification reminders at the precise second requested. |
| RECEIVE_BOOT_COMPLETED | System | Reschedules active reminder alarms and reinitializes notification listeners after the device restarts. |
| USE_FULL_SCREEN_INTENT | Alarm UI | Displays the full-screen ringing alarm banner when a reminder fires while the device screen is locked. |
| REQUEST_IGNORE_BATTERY_OPTIMIZATIONS | Reliability | Prevents OEM battery killers (MIUI, ColorOS, OneUI) from killing background notification capture listeners. |
| INTERNET | Network | Used strictly for AdMob banner ads, Firebase Crashlytics error logging, and optional Firebase authentication. |
4. Third-Party Services & SDK Disclosures
Recallr integrates with selected third-party SDKs to facilitate advertising, authentication, and application stability. These services operate under their respective privacy policies:
Google Mobile Ads (AdMob)
AdsAdMob serves banner and native advertisements. It may collect and process Advertising IDs (AAID), coarse IP locations, and interaction logs.
Google Ads Privacy Policy →Google Firebase
Crash & AuthFirebase Crashlytics, Analytics, and Auth manage optional sign-in, anonymously track crash reports, and diagnose performance regressions.
Firebase Privacy & Security →Google Play Services
System ServicesProvides system runtime dependencies, secure auth tokens, and Play Store licensing verification.
Google Privacy Policy →GitHub (Open Source)
RepositoryThe source repository, issue tracking, and documentation hosting are managed on GitHub under MinHackerz.
GitHub Privacy Statement →5. Data Retention & Automatic Pruning
You maintain complete authority over how long your notification data is retained on your device:
- Configurable Retention Windows: Through the Settings menu, you can configure automatic database retention pruning (e.g. automatically delete notifications older than 7 days, 15 days, or 30 days).
- Dual-Layer Background Pruning: Automatic cleanup runs periodically in the background to purge expired records without user intervention, minimizing storage usage.
- Pinned / Bookmarked Notifications: Notifications marked as favorites or saved to custom vaults are protected from automatic deletion until you manually remove them.
6. Data Deletion & Account Deletion Instructions
In compliance with Google Play's Data Safety and User Data policies, Recallr provides clear mechanisms for users to delete their personal data and accounts:
Instant In-App Data Wipe
You can permanently wipe all notification logs, cached application icons, and statistics directly inside the app:
- Open Recallr → Navigate to Settings.
- Scroll down to the Data Management section.
- Tap "Clear All Data" and confirm the prompt.
- All local SQLite database files, logs, and cached assets are deleted permanently and immediately.
App Uninstallation
Because Recallr stores your database in Android’s protected app sandbox, uninstalling Recallr from your device immediately and irreversibly deletes the entire SQLite database file, cached images, and local preferences from disk.
Firebase Account & Remote Data Deletion Request
If you registered with Firebase Authentication or have inquiries regarding account deletion:
- You may tap "Sign Out & Delete Account" inside the App Profile screen.
- Or, send an email to minhaj99mhq@gmail.com with the subject "Recallr Account and Data Deletion Request".
- We will process and verify your request within 30 business days, deleting all associated authentication tokens and user records from our Firebase database.
7. Security & Storage Architecture
We implement industry-standard technical security practices to safeguard your data:
flutter_secure_storage.
8. Children's Privacy (COPPA & GDPR-K)
Recallr is not intended for or directed at children under the age of 13 (or under 16 for residents of the European Economic Area / UK). We do not knowingly collect, solicit, or maintain personal information from children.
If you are a parent or guardian and become aware that your child has provided us with personal information without parental consent, please contact us at minhaj99mhq@gmail.com. We will immediately purge all related data from our systems.
9. Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on your geographic location, you may have specific statutory rights under data protection laws (such as GDPR in Europe or CCPA/CPRA in California):
- Right of Access: You can view all stored notification records directly inside the App's UI.
- Right to Rectification: You can edit categories, rename tags, or adjust preferences at any time.
- Right to Erasure ("Right to Be Forgotten"): You can wipe the local database or request deletion of your account.
- Right to Data Portability: You can export your notification history and settings in standard formats.
- Right to Non-Discrimination: We will never discriminate against you for exercising any of your privacy rights.
10. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect new app features, legal obligations, or Google Play Developer Policy amendments.
When changes occur, we will update the "Last Updated" date at the top of this document. We encourage you to review this page periodically. Continued use of Recallr after changes are published constitutes your acceptance of the revised terms.
11. Developer & Contact Information
If you have any questions, concerns, feedback, or data deletion inquiries regarding Recallr, please reach out to us: