One App – Privacy Policy

Effective date: 2 August 2026
Last updated: 2 August 2026
App name: One App
Package name (Google Play / Official build): com.hemantaggarwal.oneapp.official
Developer / data controller: Hemant Aggarwal
Privacy contact: hemant.060991@gmail.com
Website: https://hemantaggarwal.com

This document is the Privacy Policy for One App. It explains how we access, collect, use, store, share, retain, and delete information when you use the Official (public) version of One App distributed via Google Play or other public channels.

By using One App, you agree to this Privacy Policy. If you do not agree, please do not use the app.

Legal note: This policy is written to align with Google Play’s User Data policy, Prepare your app for review — Privacy policy, Data safety, and Account deletion requirements. It is not legal advice. You should have a qualified advisor review it for your jurisdictions (including GDPR, UK GDPR, CCPA/CPRA, and Indian IT Rules, as applicable) before publishing.


1. Who we are

One App is developed and published by Hemant Aggarwal (“we”, “us”, “our”).

Privacy inquiries: hemant.060991@gmail.com
Postal / other contact (optional): New Delhi, India

The developer name shown on the Google Play store listing for One App is the same entity named in this Privacy Policy.


2. Scope of this policy

2.1 Official (public) app — covered by this policy

This policy applies to the Official build of One App intended for general public distribution (including Google Play). That build may include features such as:

  • Notes, To-Dos, Tasks, Shopping lists
  • Links, Files, Trackers / Medicine
  • Encrypted password vaults
  • Refunds and Subscriptions trackers
  • List sharing and invites
  • Optional cloud sync and Google Drive file storage (subject to free / trial / paid entitlement)
  • In-app subscriptions via Google Play Billing
  • Crash reporting and analytics

2.2 Personal / family build — not distributed on Google Play

A separate Personal build exists for private/family use only. It is not published on Google Play. It may include additional capabilities (for example SMS-related automation, ATM/card tooling, Google Sheets linking, and other family-only features). Those Personal-only capabilities are outside the scope of the public Play listing and are not offered to general users through Google Play.

If you only use the Official app from Google Play, Sections describing Official features apply to you.


3. Summary of our practices

Topic Our practice (Official app)
Account required? Yes — Google Sign-In via Firebase Authentication
Sell personal data? No. We do not sell personal or sensitive user data.
Ads / AdMob? No third-party advertising SDK. The Official app does not show AdMob or similar ads.
Children’s app? No. One App is not directed at children under 13 (or the equivalent age in your country).
Cloud sync? Optional / entitlement-gated (trial, free-list slot, or paid subscription).
Encryption in transit? Yes — HTTPS / TLS for network traffic to Google / Firebase services.
Password vault encryption? Yes — vault entries are encrypted client-side before sync (see §7).

4. Information we collect and access

We collect information in three ways: (a) you provide it, (b) the app generates or stores it to deliver features, and © service providers (especially Google / Firebase) process it as part of authentication, sync, analytics, crash reporting, billing, and optional Drive storage.

4.1 Account and identity information

When you sign in with Google, we receive and may store:

  • Google account email address
  • Display name
  • Profile photo URL (if available from your Google account)
  • Firebase Authentication user ID (UID)
  • Sign-in / authentication tokens managed by Google / Firebase (we do not store your Google password)

We maintain a user registry entry (for example under a Firebase user_registry path) so the app can look up users by email when you invite someone to a shared list or vault.

4.2 User-generated content (app data you create)

Depending on which features you use, One App may store content you create or import, including but not limited to:

Feature area Examples of data
Notes Note titles, body content, tags, list membership, recycle-bin state
To-Dos / Tasks Titles, due dates, completion state, reminders/alarms metadata, tags, history
Shopping lists Items, quantities, checked state, list membership
Links URLs, titles, notes, tags
Files File metadata, tags, list membership; file binaries may be stored on-device and/or in your Google Drive (when cloud storage is enabled)
Trackers / Medicine Tracker items, schedules, logs, tags
Refunds Refund records and related list data
Subscriptions Subscription names, amounts, renewal dates, and related fields you enter
Passwords Vault metadata and encrypted credential entries (see §7)
Inbox / sharing Invites, membership, ownership, and notices related to shared lists
Feature requests (if enabled) Feedback text and related metadata you submit
Settings / preferences Theme, sort/filter preferences, widget configuration, entitlement-related preferences

This content may be stored:

  1. On your device (local Room databases, DataStore / SharedPreferences, app files); and/or
  2. In Firebase Realtime Database when cloud sync / sharing is enabled for that data; and/or
  3. In your Google Drive for Files cloud storage (when entitlement allows and you authorize Drive access).

4.3 Sharing and collaboration data

If you use sharing features, we process:

  • Invitee email addresses you enter
  • Membership roles (owner / member / invited / declined)
  • List / vault identifiers and ownership transfer events
  • Inbox messages/notices related to invites and membership changes
  • Recently used invite emails (for suggestions), stored as app preference data

When you share a list or password vault, members you invite may access the shared content according to the feature’s membership rules. For password vaults, invitees still need the vault credentials / recovery flow as designed by the vault feature; encrypted payloads remain encrypted at rest in sync storage.

4.4 Subscription and entitlement data (Official)

If you start a trial or purchase the cloud sync subscription through Google Play Billing, we may process:

  • Subscription status and entitlement flags needed to unlock sync / share / Drive features
  • Approximate access window / expiry derived from purchase or trial start
  • Purchase token / billing identifiers as required to acknowledge and verify purchases (we do not log purchase tokens in application logs)

Entitlement state may be mirrored to Firebase (for example under an official_entitlements path) so access can be resolved across devices. Payment card details are handled by Google Play; we do not receive your full payment card number.

4.5 Diagnostics, analytics, and crash data

The Official app integrates:

  • Firebase Crashlytics — crash reports, stack traces, device/OS information, and related diagnostics to fix bugs
  • Firebase Analytics — app usage events (for example screen views and feature interaction events) to understand reliability and product usage

These services may collect device and app information such as:

  • App version, OS version, device model / manufacturer
  • Crash timestamps and non-fatal error reports
  • Analytics event names and parameters we define
  • App-instance / analytics identifiers provided by Google’s SDKs

Where configured, we may associate Crashlytics / Analytics with your Firebase user ID while you are signed in, and clear that association on sign-out / local reset.

Advertising ID: The Official build may declare advertising-related permissions used by Google Play services / measurement APIs (for attribution and analytics infrastructure). One App does not use this to show third-party ads or to sell personal data for advertising.

4.6 Device permissions and why we ask for them

Permissions vary by Android version and feature. Typical Official permissions include:

Permission / capability Purpose
Internet Sign-in, sync, Drive, billing verification, analytics/crash reporting
Notifications Reminders (for example To-Do alarms) and system notifications
Exact alarms / schedule alarms Time-sensitive reminders
Boot completed Reschedule reminders after device reboot
Vibrate / wake lock Notification and reminder delivery
Google Drive authorization (user-granted) Upload/manage Files in your Drive when cloud storage is enabled
Google Sign-In / account access Authenticate you

We do not request SMS, call log, precise background location, contacts address-book, microphone, or camera permissions in the Official Play build for core public features described above.

Runtime permissions (for example notifications) are requested when needed for the related feature.

4.7 Information we do not intentionally collect (Official)

In the Official Play build, we do not intentionally collect:

  • SMS or call contents
  • Precise GPS location for tracking
  • Contacts from your device address book (sharing uses emails you type, plus registry lookup)
  • Advertising profiles for third-party ad networks
  • Government ID numbers

5. How we use information

We use the information described above to:

  1. Provide the app’s core functionality — create, edit, search, organize, remind, and display your content.
  2. Authenticate you and keep your session secure.
  3. Sync and back up your data across devices when cloud features are enabled.
  4. Enable sharing of lists/vaults with people you invite.
  5. Store Files on-device and, when authorized and entitled, in your Google Drive.
  6. Manage subscriptions / trials and gate premium cloud features.
  7. Improve reliability via Crashlytics and Analytics.
  8. Communicate about the service — for example respond to privacy or support requests you send us.
  9. Comply with law and enforce terms, security, and fraud prevention.
  10. Protect users — investigate abuse, prevent unauthorized access, and maintain Firebase security rules.

We limit use of personal and sensitive user data to purposes that are disclosed here and reasonably expected for the features you use. We do not sell personal and sensitive user data.


6. How we share information

We share data only in the following circumstances:

6.1 Service providers (processors)

We use Google infrastructure and SDKs, including:

Provider / service Role
Firebase Authentication Sign-in and account identity
Firebase Realtime Database Cloud sync of app content and membership / entitlement metadata
Firebase Crashlytics Crash and error diagnostics
Firebase Analytics Usage analytics
Google Play Billing Subscription purchase and entitlement
Google Drive API Optional file storage in your Drive account
Google Sign-In / Credential Manager / Play services Authentication and related platform services

These providers process data under their own terms and privacy policies (for example Google Privacy Policy and Firebase / Google Cloud terms). We configure them to support One App functionality and require policy-compliant handling consistent with Google Play Developer Program Policies.

6.2 Other One App users (only when you share)

If you invite another user to a list or password vault, that user can access the shared content (subject to feature rules and encryption). That is a user-initiated share, not a sale of data.

6.3 Legal and safety disclosures

We may disclose information if required to:

  • Comply with applicable law, regulation, legal process, or governmental request
  • Protect the rights, property, or safety of users, the public, or us
  • Detect, prevent, or address fraud, security, or technical issues

6.4 Business transfers

If we undergo a merger, acquisition, reorganization, or asset sale, user information may be transferred as part of that transaction, with notice as required by law.

6.5 What we do not do

  • We do not sell personal or sensitive user data.
  • We do not share your content with third-party advertisers for their advertising.
  • We do not publicly disclose financial information you store in the app.

7. Security practices

We take reasonable technical and organizational measures to protect personal and sensitive user data, including:

  • Encryption in transit using modern TLS/HTTPS for communication with Google / Firebase services.
  • Firebase Authentication and security rules that gate access to user and member-scoped data.
  • Password vault encryption: vault entries are encrypted using a data encryption key (DEK) protected by your vault master password / recovery mechanism. Encrypted payloads are what sync to the cloud; we design the feature so plaintext vault secrets are not stored server-side in recoverable form without your vault credentials.
  • Local storage on device using Android app sandboxing; sensitive local databases are excluded from casual backup where configured.
  • Least-privilege permissions — we request permissions needed for features you use.
  • Sign-out / local reset clears local databases and preferences on the device.

No method of transmission or storage is 100% secure. You are responsible for protecting your Google account, device lock screen, and password-vault master passwords / recovery codes. If you lose vault credentials and recovery material, we may be unable to recover encrypted vault contents.


8. Data retention

We retain information as follows:

Data type Typical retention
Account / user registry While your account exists, or until deletion is completed
Synced app content in Firebase While your account exists and the data remains; deleted or tombstoned according to app delete/sync behavior
Local on-device data Until you delete it in-app, sign out / reset local data, or uninstall (uninstall removes local app storage)
Google Drive files you uploaded via One App Remain in your Drive until you delete them in Drive or via the app’s file-delete flows
Crashlytics / Analytics Per Google Firebase retention defaults / our project configuration
Billing / entitlement records As needed to provide the subscription, prevent fraud, and meet accounting/legal obligations
Support / privacy emails you send us As needed to respond and for legitimate record-keeping

When data is deleted through normal app operations, local copies are hard-deleted after sync where the app’s sync design removes tombstones (we do not keep deleted item tombstones locally indefinitely).


9. Your choices and controls

You can:

  • Choose which features to use and what content to enter.
  • Decline optional permissions (some features may not work without them).
  • Disable notifications in system settings.
  • Avoid cloud sync / Drive by staying on free local-only modes where available, or by not authorizing Drive.
  • Stop sharing by leaving a list, removing members (if owner), or deleting shared collections (subject to ownership rules).
  • Sign out, which clears local databases and preferences on that device.
  • Uninstall the app to remove local data from that device.
  • Manage Google account / Drive / Play subscriptions in your Google Account and Google Play subscription settings.
  • Limit analytics where Android / Google account settings allow (platform controls vary by OS version).

10. Account and data deletion

Google Play requires that apps which allow account creation also provide:

  1. An in-app way to request deletion of the app account and associated data; and
  2. A public web resource where users can request deletion without reinstalling the app.

10.1 How to request deletion

In-app (when available):
Open Settings → Account and use Delete account. Follow the confirmation steps. (This control will ship in a future Official release; until then, use the web / email request below.)

Web / email request (available without the app):
Send a deletion request to hemant.060991@gmail.com from the Google account email associated with your One App account, with subject line One App — Account Deletion Request, and include:

  • Your account email
  • Your Firebase / app user ID if known (optional)
  • Confirmation that you want your One App account and associated cloud data deleted

Web page for deletion instructions (paste this URL in Play Console):
https://hemantaggarwal.com/one-app/delete-account

10.2 What we delete

Upon a verified deletion request, we will delete or irreversibly de-identify, within a reasonable period (and no later than required by applicable law):

  • Your Firebase Authentication account linkage for One App (where we control deletion)
  • Your user registry entry
  • Cloud-synced One App content associated with your account that is not required to be retained
  • Entitlement / trial metadata associated with your account

10.3 What may remain or require separate action

  • Google Drive files stored in your Drive remain under your Google account control; delete them in Drive if you want them removed.
  • Shared content owned by others (lists where someone else is owner) is not deleted from other members’ accounts when you leave; leaving removes your membership.
  • Billing records retained by Google Play remain subject to Google’s retention.
  • Legal retention: we may retain limited records if required for security, fraud prevention, dispute resolution, or legal compliance, and we will disclose the categories retained where required.
  • Backups / logs may take a limited additional period to fully purge from backup systems.
  • Temporary deactivation or “freezing” an account is not treated as deletion.

10.4 Sign-out vs deletion

Sign-out clears local data on the current device and ends the session. It does not by itself delete your cloud account or synced server-side data. Use the deletion process above to delete the account and associated cloud data.


11. Children’s privacy

One App is intended for a general audience of adults and is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children for the Official app. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

If you later choose to include children in the target audience on Google Play, you must additionally comply with Google Play Families policies and update this Privacy Policy accordingly.


12. International data transfers

Our service providers (notably Google / Firebase) may process and store data in data centers outside your country of residence, including in the United States and other countries. Where required, transfers rely on appropriate safeguards offered by those providers (for example Standard Contractual Clauses or other lawful transfer mechanisms).

If you are in the EEA, UK, or Switzerland, you may have additional rights under GDPR / UK GDPR (see §13).


13. Your privacy rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Delete personal data
  • Object to or restrict certain processing
  • Data portability
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with a supervisory authority

To exercise rights: email hemant.060991@gmail.com with enough detail to verify your request. We will respond within the timeframe required by applicable law.

California / similar US state laws: We do not sell personal information as “sale” is commonly defined. We also do not share personal information for cross-context behavioral advertising. You may still request know / delete / correct rights as applicable.

India: Where the Digital Personal Data Protection Act / IT Rules apply, you may contact us to exercise applicable rights as a Data Principal.


14. Third-party links and services

One App may contain links (for example in the Links feature) or integrate with Google services. Third-party sites and services have their own privacy practices. This Privacy Policy does not govern those third parties. Review their policies before providing data to them.

Relevant Google policies include:


15. Data safety disclosures (Google Play)

We maintain a Data safety form in Google Play Console describing collection, sharing, security, and deletion practices. That form is intended to be consistent with this Privacy Policy. If there is any conflict, we will update the form and/or this policy to keep them aligned.

Categories typically declared for One App (Official) include, as applicable:

  • Personal info (name, email, user IDs)
  • Photos (profile photo URL from Google account, if present)
  • App activity / app info and performance (analytics, crash logs)
  • Device or other IDs (analytics / instance IDs)
  • User content you create in the app (notes, lists, files metadata, encrypted password entries, etc.)
  • Financial info only insofar as subscription entitlement status is processed via Play Billing (card numbers are processed by Google, not by us)

We declare whether data is encrypted in transit, whether users can request deletion, and whether data is sold (it is not).


16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top. Material changes may also be communicated in-app, on our website, or via the Play Store listing. Continued use of One App after an update means you accept the revised policy, to the extent permitted by law.


17. Contact us

For privacy questions, data requests, or complaints:

  • Email: hemant.060991@gmail.com
  • Developer: Hemant Aggarwal
  • App: One App (com.hemantaggarwal.oneapp.official)
  • Website: https://hemantaggarwal.com

18. Play Console checklist (for the publisher)

Use this section when submitting App content / Data safety. It is part of the policy document for operational completeness.

Play requirement Status / action
Privacy policy URL on Play Console (App content) Host this Markdown as an HTML page on a public, non-geofenced HTTPS URL (not a PDF; not behind login).
In-app privacy policy link or text Add Settings → Privacy Policy opening the same URL.
Data safety form completed Match §§4–10 of this policy; include SDK collection (Firebase Auth, RTDB, Analytics, Crashlytics, Play Billing, Drive).
Account deletion in-app Ship Settings control that deletes account + associated cloud data.
Account deletion web URL Publish §10 instructions page; paste URL into Play Console Data safety / App content.
Ads declaration Declare No ads if no ad SDK / house ads (verify before submit).
Target audience Declare adult / not primarily children unless Families compliance is implemented.
Sensitive permissions Official build should not declare SMS/call-log; Personal-only SMS must not ship in the Play AAB.

End of Privacy Policy