Privacy Policy

Last updated: June 2026

Zikron is built on the principle that your data is yours. This policy explains what we collect, why we collect it, how long we keep it, and how you can delete it — including specific disclosures for data accessed via Google OAuth.

1. What Data We Collect

Account Information

When you sign up, we collect your email address and any profile information you provide (such as your name). If you sign in with Google, we receive your Google account email and display name — solely to create and identify your Zikron account.

Content You Create

All content you create in Zikron — notes, inbox items, lists, self-chat messages, reminders, collections, and contacts — is stored in our database. This data belongs to you.

Google Contacts Data (if you connect Google)

If you choose to connect your Google account for the Contacts import feature, we request read-only access to your Google Contacts (OAuth 2.0 scope: contacts.readonly). We import only the contact fields you have stored in Google: full name, email address(es), phone number(s), employer, job title, and profile photo URL. We do not read any other Google data — not your Gmail, Google Drive, Google Calendar, or any other Google service.

Google OAuth Tokens

To perform the contacts import on your behalf, we store your Google OAuth access token and refresh token. These tokens are encrypted at rest using AES-256-GCM encryption before being written to our database. The encryption key is never stored alongside the tokens. Token values are never logged, never returned to the frontend, and never transmitted to any third party.

Push Notification Subscriptions

If you enable browser push notifications for reminders, we store your push subscription endpoint. This is used only to deliver reminder notifications you have set up.

Usage Data

We may collect basic, anonymised usage information (such as which features are used) to improve the product. We do not track individual behaviour for advertising purposes.

2. Why We Collect Your Data

To provide the service

Your content is stored so you can access, search, and manage it from anywhere. Without storing your data we cannot provide Zikron's core functionality.

To authenticate you

Your account credentials are used to verify your identity and protect your data from unauthorised access.

To power Google Contacts import

We use your Google Contacts data exclusively to populate the Contacts section of your Zikron account. Imported contacts appear in Zikron's people management features (search, tagging, notes, favourites). This data is not used for any other purpose.

To send reminder notifications

Push notification subscriptions are used exclusively to deliver the reminder alerts you have created.

3. Google Contacts — Specific Disclosures

Scope requested

Zikron requests the OAuth 2.0 scope contacts.readonly. This grants read-only access to your Google Contacts. Zikron never writes to, modifies, or deletes any data in your Google account.

Purpose limitation

Data obtained through Google Contacts is used solely to display and manage your contacts within Zikron. It is not used to build advertising profiles, is not shared with advertisers or data brokers, and is not combined with data from other sources to infer sensitive attributes.

No sharing with third parties

Your Google Contacts data is never sold, rented, licensed, or shared with any third party. It remains within your Zikron account and is accessible only to you.

No use for advertising

Zikron does not display advertisements. Your Google Contacts data is never used for targeted advertising, retargeting, or any form of behavioural profiling.

Revoking access

You can disconnect your Google account from Zikron at any time from the Contacts page (Disconnect button). When you disconnect, your OAuth tokens are permanently deleted from our database. Previously imported contacts remain in your Zikron account unless you delete them manually. You can also revoke access from your Google Account security settings at myaccount.google.com/permissions.

4. How Long We Keep Your Data

Account and content data

Your account and all content you create (notes, contacts, reminders, etc.) is retained for as long as your account is active. If you delete an item, it is permanently removed from our database immediately.

Google OAuth tokens

OAuth tokens are deleted immediately when you disconnect your Google account from Zikron. They are also deleted automatically when you delete your Zikron account.

Push notification subscriptions

Push subscriptions are deleted when you disable notifications or delete your account. Expired subscriptions (reported as gone by the browser push service) are deleted automatically by our server.

Account deletion

When you request account deletion, all your data — including content, contacts, integrations, and OAuth tokens — is permanently deleted within 30 days.

5. How Your Data Is Protected

Row-Level Security (RLS)

Every row in our database is protected by Row-Level Security policies. Your data can only be accessed by your own authenticated session — even at the database level.

Encrypted tokens

Google OAuth tokens are encrypted with AES-256-GCM before storage. The plaintext token value is never written to disk.

Encrypted in transit

All communication between your browser, our API, and our database occurs over HTTPS/TLS. No data is transmitted in plaintext.

JWT-authenticated API

Every backend API request is authenticated using a Supabase-signed JWT. Unauthenticated or tampered requests are rejected before reaching any data.

6. Your Rights and Choices

Access your data

You can view all your content — including imported contacts — inside the Zikron app at any time.

Delete specific data

You can delete any note, inbox item, list, message, reminder, collection, or contact at any time directly within the app. Deletion is immediate and permanent.

Disconnect Google

You can revoke Zikron's access to your Google Contacts at any time by clicking "Disconnect" on the Contacts page. This deletes your stored tokens immediately.

Delete your account

To delete your entire account and all associated data, email us at hasanmunir406@gmail.com. We will permanently remove all your data within 30 days and confirm by email.

Export your data

Account data export is on the roadmap. Until then, contact us and we will provide your data in a machine-readable format on request.

7. Cookies and Local Storage

Authentication cookies

Supabase uses HTTP-only cookies to maintain your authenticated session securely. These are strictly necessary for the service to function.

Theme preference

Your light/dark/system theme preference is stored in localStorage on your device. No server is involved.

8. Changes to This Policy

Notification of changes

If this Privacy Policy changes materially — particularly regarding how Google user data is handled — we will update this page, change the "Last updated" date, and notify active users by email where required. Continued use of Zikron after a change constitutes acceptance of the updated policy.

9. Contact

Privacy questions

If you have any questions about this Privacy Policy, how your data is handled, or want to exercise your data rights, contact us at hasanmunir406@gmail.com. We respond within 5 business days.