Last updated: June 2026
Zikron is built on the principle that your data is yours. This policy explains what we collect, why we collect it, how long we keep it, and how you can delete it — including specific disclosures for data accessed via Google OAuth.
Account Information
When you sign up, we collect your email address and any profile information you provide (such as your name). If you sign in with Google, we receive your Google account email and display name — solely to create and identify your Zikron account.
Content You Create
All content you create in Zikron — notes, inbox items, lists, self-chat messages, reminders, collections, and contacts — is stored in our database. This data belongs to you.
Google Contacts Data (if you connect Google)
If you choose to connect your Google account for the Contacts import feature, we request read-only access to your Google Contacts (OAuth 2.0 scope: contacts.readonly). We import only the contact fields you have stored in Google: full name, email address(es), phone number(s), employer, job title, and profile photo URL. We do not read any other Google data — not your Gmail, Google Drive, Google Calendar, or any other Google service.
Google OAuth Tokens
To perform the contacts import on your behalf, we store your Google OAuth access token and refresh token. These tokens are encrypted at rest using AES-256-GCM encryption before being written to our database. The encryption key is never stored alongside the tokens. Token values are never logged, never returned to the frontend, and never transmitted to any third party.
Push Notification Subscriptions
If you enable browser push notifications for reminders, we store your push subscription endpoint. This is used only to deliver reminder notifications you have set up.
Usage Data
We may collect basic, anonymised usage information (such as which features are used) to improve the product. We do not track individual behaviour for advertising purposes.
To provide the service
Your content is stored so you can access, search, and manage it from anywhere. Without storing your data we cannot provide Zikron's core functionality.
To authenticate you
Your account credentials are used to verify your identity and protect your data from unauthorised access.
To power Google Contacts import
We use your Google Contacts data exclusively to populate the Contacts section of your Zikron account. Imported contacts appear in Zikron's people management features (search, tagging, notes, favourites). This data is not used for any other purpose.
To send reminder notifications
Push notification subscriptions are used exclusively to deliver the reminder alerts you have created.
Scope requested
Zikron requests the OAuth 2.0 scope contacts.readonly. This grants read-only access to your Google Contacts. Zikron never writes to, modifies, or deletes any data in your Google account.
Purpose limitation
Data obtained through Google Contacts is used solely to display and manage your contacts within Zikron. It is not used to build advertising profiles, is not shared with advertisers or data brokers, and is not combined with data from other sources to infer sensitive attributes.
No sharing with third parties
Your Google Contacts data is never sold, rented, licensed, or shared with any third party. It remains within your Zikron account and is accessible only to you.
No use for advertising
Zikron does not display advertisements. Your Google Contacts data is never used for targeted advertising, retargeting, or any form of behavioural profiling.
Revoking access
You can disconnect your Google account from Zikron at any time from the Contacts page (Disconnect button). When you disconnect, your OAuth tokens are permanently deleted from our database. Previously imported contacts remain in your Zikron account unless you delete them manually. You can also revoke access from your Google Account security settings at myaccount.google.com/permissions.
Account and content data
Your account and all content you create (notes, contacts, reminders, etc.) is retained for as long as your account is active. If you delete an item, it is permanently removed from our database immediately.
Google OAuth tokens
OAuth tokens are deleted immediately when you disconnect your Google account from Zikron. They are also deleted automatically when you delete your Zikron account.
Push notification subscriptions
Push subscriptions are deleted when you disable notifications or delete your account. Expired subscriptions (reported as gone by the browser push service) are deleted automatically by our server.
Account deletion
When you request account deletion, all your data — including content, contacts, integrations, and OAuth tokens — is permanently deleted within 30 days.
Row-Level Security (RLS)
Every row in our database is protected by Row-Level Security policies. Your data can only be accessed by your own authenticated session — even at the database level.
Encrypted tokens
Google OAuth tokens are encrypted with AES-256-GCM before storage. The plaintext token value is never written to disk.
Encrypted in transit
All communication between your browser, our API, and our database occurs over HTTPS/TLS. No data is transmitted in plaintext.
JWT-authenticated API
Every backend API request is authenticated using a Supabase-signed JWT. Unauthenticated or tampered requests are rejected before reaching any data.
Access your data
You can view all your content — including imported contacts — inside the Zikron app at any time.
Delete specific data
You can delete any note, inbox item, list, message, reminder, collection, or contact at any time directly within the app. Deletion is immediate and permanent.
Disconnect Google
You can revoke Zikron's access to your Google Contacts at any time by clicking "Disconnect" on the Contacts page. This deletes your stored tokens immediately.
Delete your account
To delete your entire account and all associated data, email us at hasanmunir406@gmail.com. We will permanently remove all your data within 30 days and confirm by email.
Export your data
Account data export is on the roadmap. Until then, contact us and we will provide your data in a machine-readable format on request.
Authentication cookies
Supabase uses HTTP-only cookies to maintain your authenticated session securely. These are strictly necessary for the service to function.
Theme preference
Your light/dark/system theme preference is stored in localStorage on your device. No server is involved.
Notification of changes
If this Privacy Policy changes materially — particularly regarding how Google user data is handled — we will update this page, change the "Last updated" date, and notify active users by email where required. Continued use of Zikron after a change constitutes acceptance of the updated policy.
Privacy questions
If you have any questions about this Privacy Policy, how your data is handled, or want to exercise your data rights, contact us at hasanmunir406@gmail.com. We respond within 5 business days.