01
The short version
ZUKA is a notes app reimagined as conversations. Every thread you write, every
reply, reaction, label, branch and merge — along with everything
ndani works with — is stored locally on your device.
It is not uploaded to our servers, because we don't operate servers that hold
your notes.
We can't read your content, sell it, mine it, train models on it, or lose it in a
breach — for the simple reason that we never receive it in the first
place. This policy explains, in plain language, the few pieces of
information that do leave your device (anonymous diagnostics only), why,
and what control you have.
This policy applies to the ZUKA mobile app and the
Zuka App website.
02
Who's responsible
ZUKA ("we", "us", "our") is the provider of the ZUKA application. For the limited
anonymous diagnostic data described in this policy, we act as the data controller.
For the contents of your notes, there is no controller relationship — that data
stays entirely under your control, on your device.
You can reach us about anything in this policy at
apps@abubunamay.com.
03
What stays on your device
Everything you create inside ZUKA lives in local storage on your phone and never
touches our infrastructure. This includes:
- Your threads and every reply within them
- The full text and content of every note you write
- Reactions — ⚡ Execute · 💬 Answer · ✔️ Done · 👀 Noted · ✨ Fresh Take · 🎯 Action
- Labels — 💡 Idea · ❓ Question · ✅ Task · 📌 Important · 🔁 Revisit · 💭 Reflection
- Branches you split off and merges you accept
- Your in-app settings and preferences
Because this data is local, it is governed by your device's own security (your
passcode, biometrics, and OS-level encryption) rather than by us.
04
How ndani handles your data
ndani — Swahili for inside — is the intelligence
at the core of ZUKA. Its single job is to notice when two of your threads are
converging on the same idea and offer you the merge, so you think a thought through
once, not twice.
Crucially for your privacy: ndani runs entirely on-device. The
analysis that detects overlap between threads happens locally, using your phone's
own processing. The connections ndani surfaces are computed on your device and
never leave it. ndani sends nothing about your notes to us or to any third party.
ndani also doesn't auto-organise anything. It only flags possible overlap
and surfaces a suggestion — you decide whether to merge. Nothing is acted on
without you.
05
What we do not collect
To be unambiguous, ZUKA does not collect, receive or store:
- The content of your notes, threads or replies
- Your reactions, labels, branches or merges
- The connections ndani identifies between your threads
- Your contacts, photos, microphone or location
- An account — ZUKA requires no sign-up, email or password to use
- Any data used to build an advertising profile of you
06
The only third-party processing: Firebase
ZUKA uses Google Firebase for two narrow, technical purposes only.
This is the sole data that leaves your device — and none of it includes your note
content.
Firebase Crashlytics
When ZUKA crashes, Crashlytics sends us a diagnostic report so we can find and fix
the bug. A typical report contains the type of crash, the line of code involved, the
device model, and the OS version. It does not contain the text of your notes.
Firebase Analytics
Analytics gives us anonymous, aggregate signals about how features are used — for
example, how many people use branching, or how often the app is opened. These are
counts and patterns across many users, not a record of what any individual writes.
This data is processed by Google as our sub-processor under its own terms. We use it
solely to keep ZUKA stable and to decide what to improve — never to read
your notes or build a profile of you. You can review Google's handling at
firebase.google.com/support/privacy.
07
Why we're allowed to process it (legal bases)
For users in the EEA and UK, our legal basis under the GDPR for the limited
diagnostic data above is our legitimate interest in keeping ZUKA
stable, secure and improving — balanced against the fact that the data is anonymous
and aggregate. Where local law requires consent for analytics, we rely on the
consent you provide in-app or via your device settings.
For your note content there is no processing by us, and therefore no legal basis is
required — it stays with you.
08
How long data is kept
-
Your notes: kept on your device for as long as you keep them.
You control deletion entirely; uninstalling the app removes them.
-
Crash & analytics data: retained by Firebase according to
Google's standard retention windows (typically up to 14 months for analytics
events, and up to 90 days for detailed crash data), after which it is aggregated
or deleted.
09
Security
The strongest security guarantee is architectural: data that never leaves your
device cannot be intercepted in transit to us or stolen from a server we don't have.
Your notes are protected by your phone's own operating-system encryption and the
lock you set on your device.
For the diagnostic data that does travel to Firebase, transmission is encrypted in
transit (HTTPS/TLS) and handled within Google's secured infrastructure. No method of
transmission is ever 100% secure, but the surface area here is deliberately tiny and
contains no note content.
10
Backups & deletion — the honest trade-off
Local-first comes with a responsibility we won't hide from you:
you are responsible for your own backups. Because we hold no cloud
copy of your notes, there is nothing we can restore if your device is lost, reset,
or damaged.
Deleting the app deletes your notes permanently. Where your device
or OS offers an encrypted local/device backup, your ZUKA data may be included in
that backup under your control — but that mechanism belongs to your device, not to
us.
11
Your privacy rights
Depending on where you live (for example, under the GDPR in Europe or the CCPA in
California), you may have rights to access, correct, delete, port, or object to the
processing of personal data held about you.
For your notes, these rights are satisfied directly by you: the data is on your
device, you can read, edit, export or delete it at any time, and you never need to
ask us. For the anonymous diagnostic data, because it isn't tied to your identity we
generally cannot single you out — but you can stop it entirely (see the next
section), and you can contact us at
apps@abubunamay.com with any
request. We do not sell personal information.
12
Your choices & controls
-
Opt out of analytics: where offered, you can disable diagnostics
in ZUKA's settings or via your device's privacy controls.
-
Manage your notes: create, edit, branch, merge and delete freely —
it's all local and all yours.
-
Walk away cleanly: uninstalling ZUKA removes your local data from
the device.
13
International users & data transfers
Your notes don't cross borders, because they don't leave your device. The only data
that travels — anonymous Firebase diagnostics — may be processed by Google on
servers outside your country, including in the United States, under Google's standard
data-transfer safeguards. By using ZUKA you understand this limited, anonymous
transfer.
14
Children's privacy
ZUKA isn't directed at children under 13 (or the minimum age in your region), and we
don't knowingly collect their personal data. Since notes stay on-device and we
operate no accounts, no note content reaches us regardless of a user's age. If you
believe a child has provided us with personal data, contact us and we'll address it.
15
Changes to this policy
As ZUKA evolves, this policy may change. When it does, we'll update the "last
updated" date at the top of this page, and we'll highlight material changes inside
the app so you're not caught off guard. Continued use after an update means you
accept the revised policy.
16
Contact
Questions, requests, or concerns about your privacy? We'd genuinely like to hear
them. Reach us at
apps@abubunamay.com and we'll
respond.
Pages stay silent. Threads talk back —
but only to you.