In short
Your Bro is an Android app for tasks, habits and notes, designed with a focus on privacy. The app is oriented toward storing data locally on the device and protects it with encryption. It does not use third-party analytics or trackers.
Not all data lives only on the device, though: some features — Google Sign-In, server-side Premium status verification and an optional encrypted backup to Google Drive — rely on external services. They are described below.
Important to understand: no app can guarantee absolute protection. The mechanisms below noticeably improve the security of personal data, but they don't replace the basic security of the device itself and the strength of your passwords.
Where data is stored
Tasks, habits, notes and attachments are stored locally on your device. A cloud account is not required by default for the app to work.
Data that may be stored locally on the device includes: tasks, habits, notes, the Password Vault, audio, video, attachments, settings, local session data, and the key material required for encryption.
- The database is encrypted with SQLCipher.
- Media (attachments, voice and video notes) is encrypted with AES-256-GCM.
- Keys and secrets are stored via Android Keystore and EncryptedSharedPreferences.
- System Android backup is excluded for the app.
Access protection
App access can be protected with a PIN and biometrics. The FLAG_SECURE flag limits screenshots and previews of the app in the system's recent apps list.
Google Sign-In
Google Sign-In is used to identify you, link the app installation to a verified Google account, find an existing active subscription and restore Premium on another device, show the connected account email and prefill it in Paddle Checkout when the email is available.
The app may receive a stable Google account identifier, the email and the display name if Google provides it. The primary subscription identifier is the server-verified account identifier, not the email.
Google Sign-In does not give the app your Google password, does not provide access to Gmail and does not by itself enable backup to Google Drive. The Google ID token is sent to the server only for verification and is not used as a persistent session; after verification the server uses its own secure session.
Backup to Google Drive
Backup is a separate feature that is enabled only if you activate it yourself. Without your consent, a backup is not sent to the cloud.
- The backup is encrypted with a separate password (backup password) on the device — before upload.
- Google Drive is used as external storage for the encrypted backup file (the appDataFolder service folder).
- Google Drive authorization is separate from Google Sign-In and is requested separately.
- The app does not read arbitrary files or documents in your Google Drive.
- A backup password is needed to restore. Without it, the backup cannot be decrypted.
- The Google account by itself is not the decryption key.
Turning off backup to Google Drive does not automatically delete local data on the device. An archive that has already been uploaded may continue to exist in Google Drive separately. Google does not receive the backup password.
Full restoration of all data and media on any device is not guaranteed. Some media uses device-bound keys, so moving it to another device may be risky. Keep the backup password safe — without it, restoration is impossible.
Manual export and import
You can manually create an encrypted archive and save it to your phone, your computer, a cloud storage of your choice or another location through the system file interface.
You choose the storage location, and the app does not control the security of that external location. Restoring requires the backup password; a forgotten password cannot be recovered. Manual export remains a separate way to restore your data if Google Drive or a cloud integration is temporarily unavailable. After export, you are responsible for the security of the chosen storage location.
Premium and Paddle
Premium is activated only after a Paddle purchase is confirmed and the subscription or purchase status is verified on the server. Google Sign-In does not by itself activate Premium and does not replace payment, but it lets you find an existing active subscription and restore Premium on another device without buying again.
Payment is processed by Paddle. Card payment details are entered directly in Paddle Checkout. Your Bro does not receive or store your bank card number. If you signed in with Google and the email is available, the verified email may be passed to Paddle to prefill checkout. The server stores and verifies the Premium status; the actual status is determined by current Paddle data and server-side verification.
Speech recognition
Speech recognition works offline-first via Vosk and runs on the device. The language model is downloaded separately — that download requires the internet.
Analytics and trackers
The app has no third-party analytics or advertising trackers. The app was not built to collect and sell personal data.
Sign-out, deletion and stopping use
Signing out of your Google account does not automatically delete local data and does not cancel a Paddle subscription. Uninstalling the app may delete local data on the device, while a backup in Google Drive may continue to exist separately. A request to remove the server link or a personal-data request is handled through the available support channel: info@your-bro.com.
Third-party services
The app uses only the third-party services that are actually needed:
- Google Identity — account verification;
- Google Drive — optional storage of the encrypted backup;
- Paddle — payments and purchase status;
- Cloudflare — site delivery and server / API infrastructure.
Platform dependency
Some features depend on the Android system and Google services (for example, backup via Google Drive and biometrics). Those components are subject to the terms and policies of the respective providers, which Your Bro does not control.
Contacts
Questions about privacy and how the app works — write to info@your-bro.com.
Back to home