Privacy Policy
Last updated: 7 October 2026
1. Introduction
“Qirtas” (the “App”) is an app for handwriting, drawing and note-taking on Windows and Android and in the browser (the “web version” at qirtas.namari8.com/board), developed and owned solely by Yousuf Ghulam Nabi (the “Developer”). It is an independent product.
Unless stated otherwise, this policy applies to all versions; differences specific to the web version are noted where relevant.
This policy explains what data the App processes, where it is stored, and your rights.
2. No account and no servers for your boards
- The App does not require you to create an account with the Developer.
- The Developer does not operate servers that receive or store your boards.
- The App contains no advertising and no analytics or tracking tools, and the Developer does not sell your data or share it with anyone.
- The two exceptions: problem reports, which are sent only with your permission (Section 7), and, on Windows only, an intermediary for signing in to Google (Section 8). Neither receives your boards.
- In the web version neither exception exists: no problem reports are sent, there is no sign-in, and your boards are not sent to any server.
3. Data the App processes
- Your board content: your handwriting and drawings, their layers, colored sticky notes, tables, connectors, ready-made shapes, element rotation, your typed text, your equations, the names of your notebooks and sections, PDF pages and images you add, the page templates you choose (ruled, grid, dots, isometric, Cornell, monthly planner, to-do list, music staves and graph paper), and the paper color of each board.
- Stylus data: pen pressure and tilt values (when your device provides them) are stored with the strokes inside the board itself, and never leave your device except within a board that you export or sync yourself.
- Your settings: the colors you chose or saved, tool preferences, language, the state of the introductory tour, and the date of the last backup you exported, used to show a backup reminder every 15 days to those who have not linked a cloud account. The App also stores tool settings on your device: palm-rejection mode, snapping on or off, selection mode and its filter, and the paper color and background.
- In-app clipboard: copy and paste use a clipboard inside the App that stays in memory only while the App is running and is not written to disk.
- Thumbnails of your boards, created to display them in the list.
- Audio recordings that you start yourself (optional), and the timing of each stroke linked to them so that the audio jumps to the moment it was written.
- Cloud storage data (optional): an access token that Google or Microsoft gives you when you sign in, stored in your device's secure storage. Your password never reaches the App, and it does not see your name, your email or your other files.
- On Windows, a small file containing a random installation number, used only to detect that the App was reinstalled and then clear the stored cloud-storage token. It is not linked to your identity and is not sent to anyone.
- Handwriting recognition (optional, Android and iOS only, not on Windows): the strokes to be recognized are processed on your device and are not sent to the Developer or to Google (details in Section 8).
- Temporary files: when a Word, PowerPoint or Excel file is converted to PDF on Windows, a temporary PDF copy is created in the system's temporary files folder and is deleted after import.
4. Where data is stored
- On your device: your boards are saved automatically after every edit in the App's local data folder (on Windows outside the Documents folder, so they are not synced with OneDrive; on Android in the App's private space), and the App works without an internet connection.
- In your Google Drive account (optional): if you sign in from the cloud-save button, the App uploads your boards to a hidden folder of its own inside your account. These files are subject to Google's terms and policy, and the Developer does not receive them.
- In your Microsoft OneDrive account (optional): if you sign in with a Microsoft account, the App uploads your boards to its own app folder inside your account. These files are subject to Microsoft's terms and policy, and the Developer does not receive them.
- Audio recordings (optional): stored on your device only, inside the App's folder; they are not uploaded to the cloud and the Developer does not receive them, and you delete them yourself from the recording panel.
- Files you export: a file with the qirtas extension containing your board and its images, or a PNG image or PDF file of the board. You decide where it is saved and with whom it is shared.
- Office files (Word, PowerPoint and Excel): when you choose to open them in Qirtas on Windows, the App converts them to PDF on your device using the Microsoft Office installed on your computer, and does not send the file to anyone.
- In the web version: your boards, their images, PDF files, audio recordings and your settings are stored only in your browser's storage on your device (IndexedDB) and are not sent to any server. This storage belongs to the browser and device you use, so your boards do not appear in another browser or on another device.
- Clearing your browser data or the Qirtas site data, using a private browsing window, or removing the browser may permanently delete your boards in the web version, and the Developer cannot recover them; keep an exported copy (a qirtas or ZIP file).
- Cloud saving (Google Drive and OneDrive) is not currently available in the web version.
5. Signing in with Google and Microsoft, and their data
Cloud saving is optional and uses one permission only: https://www.googleapis.com/auth/drive.appdata, which allows the App to read, write and delete only the files it created itself inside its hidden app folder in your account. The App does not access your other files in Drive, nor your email or contacts.
We use this access for one purpose: saving, restoring and syncing your boards between your devices. We do not sell Google data, share it, use it for advertising or to train artificial intelligence models, and no human reads it.
Qirtas's use of information received from Google APIs, and its transfer to any other app, adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
You can revoke the permission at any time at myaccount.google.com/permissions, or by signing out of cloud saving inside the App.
Saving to Microsoft OneDrive is likewise optional and uses only the Files.ReadWrite.AppFolder permission, which allows the App to read, write and delete the files it created inside its own app folder in your account. It does not access your other files in OneDrive or your email. It also requests the offline_access permission so that it can renew the sign-in without you repeating it each time. We do not sell Microsoft data, share it, use it for advertising or to train artificial intelligence models, and no human reads it.
You can revoke the permission from your Microsoft account settings (Privacy > Apps and services), or by signing out of cloud saving inside the App.
6. Permissions
- Camera (phone): requested only when scanning a QR code to receive a board; no photos or videos are saved.
- Internet: for optional cloud saving, downloading fonts, downloading the handwriting-recognition language model once (optional), reading small configuration files from the Qirtas website, and sending problem reports with your permission.
- Files: the App accesses only the files you choose yourself (importing a PDF, an image, a Word, PowerPoint or Excel file, or a board, or exporting).
- Microphone (optional): requested the first time you start an audio recording yourself, and no recording starts without a notice and your consent. In the web version the browser itself asks for this permission, and you can revoke it from the site settings in your browser.
- The web version does not request the camera (QR scanning is not available in it), and it accesses only the files you choose yourself.
7. Problem reports
When a problem occurs in the App, it shows you its type and asks you before anything is sent; nothing is sent without your consent. You can turn the prompt off permanently in Settings.
- What is sent if you agree: the type of problem and the error text, the App version, the type of operating system, a random installation identifier not linked to your identity, and the last lines of the run log. You can see this before you agree.
- What is never sent: passwords, sign-in data and the content of your boards. Long numbers and email addresses are automatically masked from the text.
- Where it is stored: in a Google spreadsheet belonging to the Developer's account that no one else can access, and the Developer may receive an email notification.
- Purpose and duration: used only to fix problems, and automatically deleted thirty days after receipt. You may ask us to delete them earlier by contacting us.
- The web version sends no problem reports and no suggestions.
8. External services
- Google Drive: optional; access is limited to the App's hidden folder inside your account.
- Microsoft OneDrive and Microsoft sign-in: optional; access is limited to the App's private folder inside your account.
- Google Fonts: when you choose a non-default font, it is downloaded from Google's servers, so your device's connection address is visible to them.
- Google ML Kit (handwriting recognition, optional, Android and iOS only, not on Windows): the App uses the Digital Ink Recognition service from Google ML Kit, and recognition takes place on your device. On first use the App downloads the recognition language model (Arabic or English) from Google once, so your device's connection address is visible to Google. The strokes being recognized are processed on your device and are not sent to the Developer or to Google.
- Google Apps Script and Google Sheets: only to receive the problem reports you agree to send.
- The Qirtas website (qirtas.namari8.com), hosted by Netlify: the App periodically reads two small files from it (a minimum-version notice, and the on/off status of some optional features such as audio recording). The App sends no data in these requests, but your device's connection address is visible to the hosting provider.
- Cloudflare (Windows only): an intermediary operated by the Developer to complete Google sign-in from the Windows version. The intermediary receives sign-in code exchange requests, adds the App's credentials to them and forwards them to Google; sign-in tokens pass through it only in transit. The intermediary does not store your tokens or the content of your files, and Cloudflare may log general technical data about requests according to its own policy.
- The web version: its pages and files (including the rendering engine) are served from the Qirtas website hosted by Netlify, which may log ordinary connection data (such as IP address and browser type) under its own policy. The browser may also download some display fonts (such as the Arabic font) from Google Fonts when needed, so your connection address is visible to Google. None of your board content is sent in any of this.
Other than that, the App does not connect to any external service.
9. Sharing by QR code
The App displays a QR code on your screen when you share a board, and the other device scans it from inside the Qirtas app. When you choose to share, your device opens a temporary direct connection within the same Wi-Fi network with the device that scans the code, with no intermediary server. The board is transferred encrypted (AES-256-GCM), and the encryption key is inside the code itself, so show it only to someone you want to receive your board.
The code is valid for five minutes, the connection is closed after the first receipt, and the App accepts receipt only from local-network addresses.
Sharing and receiving notes by QR code are not available in the web version, because the browser cannot open a direct connection inside the local network.
10. Data security
- The cloud-saving token is stored in the secure storage provided by the operating system.
- Your board files, their thumbnails and the images you add are encrypted on the device with AES-256-GCM, and the encryption key is kept in the operating system's secure storage. Boards saved before this feature are encrypted at their next save.
- The original PDF file added to a board, audio recordings, files you export, and the Google Drive and OneDrive copies are not encrypted (they are uploaded as they are), so their protection depends on your device lock and your accounts. If the key is lost (for example by clearing the App's data or secure storage, or resetting the device), encrypted boards that exist only on the device may become unreadable, so keep an exported or cloud copy.
- The Android app may refuse to run on a rooted device, on an emulator, while developer options or USB debugging are enabled, or when tampering with the app is detected, in order to protect your data.
- In the web version your boards, their thumbnails and the images you add are encrypted with the same AES-256-GCM, using a key the browser creates through WebCrypto and keeps in the site storage as non-extractable. The original PDF file and audio recordings are not encrypted there, and the protection of all of them depends on the protection of your device and your user account on it. Anyone using the same browser on your device can open your boards from the site, so do not use the web version on a shared device.
- No system is completely secure. Do not use the App on a shared device for private information.
11. Retention and deletion
- When you delete a board that has been uploaded to the cloud, the App lets you choose between deleting it from your device only, or from your device and from the cloud together. Deletion from the cloud is permanent and includes the board file and its images not used in another board. If you choose the device only, its copy remains in Google Drive or OneDrive until you delete it.
- On the home screen you can select several boards at once to delete or move them together, and the cloud-deletion choice described above applies to the whole selection.
- Signing out of cloud saving stops uploading and removes the access token from your device.
- On Android, the operating system removes the App's data when it is uninstalled. On Windows, uninstalling does not delete your boards because they are yours; they remain in the Qirtas folder inside the local application data of your Windows account until you delete them yourself. The stored cloud-saving token is cleared when the App is reinstalled on Windows.
- In the web version your boards remain in your browser's storage until you delete them in the App or clear the site data from your browser settings.
12. Your rights
- To view and export your boards at any time (qirtas file, image or PDF), and to export all your boards at once in a ZIP file.
- To delete your boards from your device, and to delete their cloud copies from your Google or Microsoft account.
- To stop cloud saving by signing out of it, and to turn off problem reports in Settings.
- To submit a complaint to us, and we will respond within no more than thirty days. If it is not resolved, you may approach the competent personal-data protection authority.
13. Minors
If you are below the legal age to enter into contracts, use of the App is conditional on your guardian's knowledge and consent.
14. Security incidents
If we discover a vulnerability or incident affecting users' data, we will inform you through the App or the announced contact channels, notify the competent authorities where necessary, and issue an update to address it.
15. Amendments
For any material amendment we will notify you inside the App before you continue using it, and we will update the date of this page.
16. Contact
Yousuf Ghulam Nabi — yousuf@namari8.com — Phone: +973-32006002