NotiScope Privacy Policy
Effective date: 1 August 2026
Last updated: 1 August 2026
NotiScope is published by Good Button (“Good Button”, “we”, “us” or “our”). This policy explains how NotiScope handles information when you use the Android app.
Privacy contact: hello@goodbutton.co.uk
1. The important points
- NotiScope does not require an account.
- Your notification history, searches, rules and insights are stored locally on your Android device.
- Good Button does not receive or remotely access your notification database.
- You choose how much notification information NotiScope stores: Metadata only, Standard or Full inspector.
- You can exclude apps or channels, choose a retention period and delete stored history.
- Android cloud backup and device-to-device transfer are disabled for NotiScope’s app data.
- NotiScope does not sell personal data, show advertising, build marketing profiles or use notification information for tracking.
- NotiScope uses Firebase Crashlytics automatically. Limited technical crash, stability and device information is sent to Google to help Good Button diagnose and fix faults. Notification content is not intentionally added to crash reports.
2. Who controls your information
For notification history and analysis that remain solely on your device, Good Button does not receive the information or decide how you use it. You control capture, storage rules, retention and deletion through NotiScope and Android.
For personal data that Good Button receives through Firebase Crashlytics reports or through support correspondence, Good Button is the data controller.
This policy is written with UK data-protection law in mind and also explains the safeguards relevant to users in the European Economic Area where applicable.
3. Why notification access is sensitive
After you deliberately grant Android notification access, NotiScope can observe notifications delivered by other apps. Depending on what those apps display, notification information may include:
- private messages, sender names and conversation participants;
- email subjects and previews;
- one-time passcodes and security alerts;
- calendar, reminder and travel information;
- purchase, payment, banking or account information;
- health, fitness or medication information;
- location, employment or work-profile information; and
- political, religious, sexual-orientation or other sensitive information.
This information can relate to you or to another person mentioned in a notification. NotiScope does not deliberately infer sensitive characteristics, create a profile about them or use them for advertising. However, Standard and Full inspector modes can store text or structured values that another app placed in a notification.
You should choose the most restrictive privacy mode that still meets your needs and exclude apps or channels whose notifications you do not want retained.
4. Information processed locally on your device
For a notification that is not excluded, NotiScope may process some or all of the following information, depending on your selected privacy mode and rules.
4.1 Notification source and identity
This can include:
- the source app’s package name and app label;
- Android notification key, notification ID and tag;
- posting or delegated package information;
- Android user or work-profile information;
- channel ID and channel name;
- group, sort, conversation and shortcut information; and
- notification category, template or style.
Package names can reveal which apps you use. NotiScope does not request permission to enumerate your complete installed-app inventory. It asks Android for information about packages encountered through notifications so that it can display a readable app name.
4.2 Timing and lifecycle information
This can include:
- source posting time and NotiScope capture time;
- first and last observed times;
- Android’s last alert time, where available;
- whether Android indicates that an observable alert occurred;
- whether the notification is active or removed;
- removal time and Android’s removal-reason code, where supplied;
- revision times and revision count;
- observed lifetime and short-lived status; and
- whether a lifecycle had to be reconciled after the listener reconnected.
Android does not always expose enough information for NotiScope to distinguish sound from vibration reliably, and NotiScope does not claim that it can always do so.
4.3 Technical notification configuration
This can include importance, ranking position, flags, visibility, priority, timeout, badge, bubble, clearable and grouping settings. It can also include channel sound and audio settings, vibration patterns, lights, Do Not Disturb bypass settings, lock-screen visibility, action counts, extras counts and whether Android reports that the user changed certain channel settings.
NotiScope uses this information to explain notification behaviour and create local app and channel reports.
4.4 Notification content
Depending on your privacy mode, this can include:
- title, body, expanded text, subtext and summary text;
- inbox lines;
- action button labels and action metadata;
- structured and historic message text;
- participant and
Personnames; - conversation labels;
- progress values and remote-input history;
- media-related information;
- standard Android notification extras; and
- app-specific extras in Full inspector mode.
NotiScope does not store bitmap image bytes from embedded notification images. It records limited descriptions such as dimensions or icon type instead. Extraction is bounded by limits on field counts, nesting, collection size and rendered value length to reduce accidental over-collection and denial-of-service risks. These limits do not make stored text anonymous.
4.5 Settings, search and insights
NotiScope stores local settings such as:
- onboarding status;
- global, app-specific and channel-specific privacy rules;
- exclusions;
- retention period;
- locked-device capture mode;
- history-lock and timeout settings;
- Recents-screen protection; and
- the short-lived-notification threshold.
Search terms are used locally to query your retained history and are not saved as a separate search history. Local insights and reports are calculated from the retained database. NotiScope does not send notification data to an artificial-intelligence service.
5. Privacy modes and exclusions
You select a global privacy mode and can apply more specific rules to individual apps or notification channels.
Metadata only
Stores identity, source, timing, lifecycle, removal reason and non-content technical information. Titles, bodies, subtext, action labels, extras and other content-bearing values are removed before the notification snapshot reaches storage.
Standard
Stores ordinary visible notification content, action labels and supported Android-defined structured extras. It does not store app-specific extras.
Full inspector
Stores visible content, action labels and safely bounded supported public notification fields and extras, including app-specific extras.
Rules and exclusions
You can exclude an app or a particular channel from future capture. An app exclusion takes priority over channel rules; otherwise, a channel rule takes priority over its app rule.
Exclusions affect future capture. Existing history remains until you delete it or it expires under your retention setting. Changing to a more restrictive storage mode removes fields outside that mode from existing matching history.
6. Capture while your device is locked
The default locked-device capture mode is Metadata only. You can instead choose to:
- apply your normal app and channel rules while the device is locked; or
- pause capture until Android reports that the device has been unlocked.
If capture is paused, a notification that disappears before unlock may not be recorded. Active notifications can be reconciled after unlock. This setting controls local capture and storage; it does not cause notification data to be transmitted to Good Button.
7. How NotiScope uses local notification information
NotiScope uses locally retained notification information only to provide its features, including to:
- show which notification most recently alerted;
- maintain a searchable notification timeline;
- preserve observable revisions and compare changes;
- explain alert behaviour and Android-provided removal reasons;
- identify short-lived notifications;
- display the public notification fields selected by your privacy mode;
- produce local reports and insights;
- open relevant Android app or channel settings;
- create an export when you explicitly request one;
- maintain privacy, retention, exclusion and protection settings; and
- run a diagnostic notification test that you request.
Notification data is not used for advertising, marketing, cross-app tracking, sale, credit decisions, insurance, employment decisions or automated legal decisions.
8. Storage and security
Notification history is stored in an app-private SQLite database on your Android device. Settings are stored in Android’s app-private preferences.
Android cloud backup and device-to-device transfer are disabled for NotiScope’s database, files and preferences. NotiScope relies on Android’s application sandbox and the device’s storage encryption; it does not add separate database encryption such as SQLCipher. A rooted, compromised or unlocked device may weaken or defeat those protections.
The optional history lock uses Android’s system biometric or device-credential prompt. NotiScope receives only whether authentication succeeded. It does not receive or store your fingerprint, face template, PIN, password or device credential.
By default, NotiScope uses Android’s secure-window protection for its Recents preview. This also prevents ordinary screenshots and non-secure screen capture while that protection is active. You can choose a weaker blurred preview or allow normal previews.
No method of storage or software can be guaranteed to be completely secure.
9. Retention and deletion on your device
You can select a retention period of 1, 7, 30 or 90 days, or keep history indefinitely. The default is 30 days.
Automatic retention removes notification lifecycles whose last observed time is older than your chosen period after they have been removed. An active notification can remain beyond the selected period and becomes eligible for deletion only after it is removed or NotiScope later determines that it is no longer active. Cleanup runs during relevant app activity and through an approximately daily Android job, although Android or the device manufacturer may delay scheduled work.
You can delete:
- one notification lifecycle and its revisions;
- all history for an app;
- all history for an app and channel; or
- all notification history.
Deleting history does not automatically reset your privacy mode, retention period or exclusion rules. Uninstalling NotiScope normally removes its app-private data, subject to Android’s own app archival and device behaviour.
Deletion removes the relevant records from NotiScope’s active database so they are no longer available through the app. It does not perform a forensic overwrite of every underlying byte. Deleted data may remain temporarily in SQLite free pages, logs or flash storage until Android and SQLite reuse or discard it.
10. Android permissions and special access
Notification access
You must deliberately enable NotiScope in Android’s notification-access settings. Without that access, NotiScope cannot capture new notifications, although you can still review history already stored. You can revoke access at any time in Android settings.
Notification permission
On Android 13 and later, NotiScope requests permission to post notifications only if you deliberately run its diagnostic notification test. It is not required for reading other apps’ notifications, and NotiScope does not send routine engagement reminders.
Package visibility
NotiScope declares limited launcher-app visibility so it can resolve a readable label for an app that has posted a notification. It does not request Android’s QUERY_ALL_PACKAGES permission and does not enumerate a complete installed-app inventory.
System authentication
AndroidX Biometric may add biometric-related permissions to the final app manifest. These permissions allow NotiScope to invoke Android’s system authentication prompt. They do not provide Good Button or NotiScope with biometric templates or device credentials.
Files
Exports use Android’s system document picker. NotiScope does not request broad access to all files or media on your device.
11. Exports, clipboard and Android settings
Notification exports
You can create JSON exports at Metadata only, Visible content or Full details level. You can export the latest revision, a complete lifecycle or history matching your current filters.
An export can contain sensitive notification information. NotiScope shows a warning before export. You choose the destination through Android’s document picker. The destination can be local storage or a third-party document provider, including a cloud-storage provider.
Good Button does not receive a copy of an export merely because you create one. After the file is written, its retention, security and onward sharing are controlled by you and the provider you selected.
Privacy-safe diagnostics export
NotiScope can create a diagnostics export containing technical state such as Android SDK level, listener status, selected privacy and retention modes, protection settings, record counts and database size. It is designed to omit notification content, app and channel identities, notification identifiers, search terms, device brand and model, user identifiers and error-message text.
Clipboard
When you copy a raw field name or value, it is placed on Android’s system clipboard. Clipboard contents are then outside NotiScope’s direct control and may be visible to Android, keyboards, device-management software or other apps according to your device and Android version.
Android settings
When you open an app’s or channel’s notification settings from NotiScope, the relevant package name and channel ID are sent locally to Android’s Settings app. They are not sent to Good Button.
12. Firebase Crashlytics reporting
NotiScope uses Firebase Crashlytics, provided by Google, to help Good Button identify, diagnose, prioritise and fix crashes, non-fatal faults and Android Not Responding events.
Crashlytics reporting is enabled automatically and is part of NotiScope’s standard operation. There is no in-app setting to disable it. Crash reports may be sent when the app crashes, experiences a non-fatal fault or becomes unresponsive.
Crashlytics may automatically collect and send information such as:
- crash stack traces and relevant app state;
- exception class and technical exception message;
- crash date and time;
- app package identifier, version and build information;
- Android version;
- device model, manufacturer, CPU architecture, memory and available storage;
- whether the device appears rooted;
- whether the app was in the background and screen orientation;
- network connection type and session information;
- Crashlytics installation UUID;
- Firebase installation ID; and
- Firebase session ID.
These identifiers relate to an installation of NotiScope and are pseudonymous; they are not necessarily anonymous.
Good Button does not use Google Analytics, Firebase Performance Monitoring, advertising services or analytics breadcrumbs in NotiScope. We do not set a Crashlytics user ID. We do not intentionally add notification titles, bodies, messages, package names, app labels, channel details, notification identifiers, search terms, export destinations or copied values to Crashlytics logs, custom keys or reports.
Crashlytics automatically includes some exception messages and technical state. We design the app to avoid constructing exception messages or developer logs from notification content, but no technical safeguard can promise that an unexpected software fault will never expose incidental data. Access to the Firebase project is restricted to authorised maintainers.
Why we process Crashlytics data
We process crash-reporting data to improve NotiScope’s reliability and security, diagnose faults and measure app stability. Where UK or EU data-protection law applies, we rely on our legitimate interests in maintaining, securing and improving the app. We have designed the integration to limit the information sent and to avoid deliberately including notification content or user identifiers.
Google, processing locations and retention
Google acts as a service provider or processor for relevant Firebase customer data under the applicable Firebase terms. Google may process data using global infrastructure, including in countries outside the UK or European Economic Area. Where required, these transfers are governed by Google’s contractual data-transfer safeguards, including applicable standard contractual clauses.
Firebase states that Crashlytics keeps crash stack traces and associated identifiers for 90 days before beginning removal from live and backup systems. Further information is available in Privacy and Security in Firebase and the Firebase Data Processing and Security Terms.
Because NotiScope does not have accounts or collect your name through Crashlytics, Good Button may be unable to identify which crash reports relate to you without relevant technical installation information. If you make a rights or deletion request about Crashlytics data, we may ask you for information reasonably necessary to locate the relevant reports and prevent unauthorised access to another person’s data.
13. Contacting support
If you email hello@goodbutton.co.uk, Good Button receives the information you choose to include, such as your email address, message and attachments.
Please use NotiScope’s privacy-safe diagnostics export where possible. Do not send a full notification export, screenshot or copied notification content unless it is necessary and you understand that it may contain information about you or other people.
We use support information to respond to your request, investigate faults, protect the app and keep an appropriate record of the enquiry. Our lawful basis is our legitimate interests in providing support and maintaining a safe, reliable product, and taking steps at your request where applicable. If material contains special-category information, we will limit access and use it only where an appropriate legal condition applies.
Support correspondence is normally deleted or anonymised within 12 months after the enquiry is closed, unless we need to keep it longer to establish, exercise or defend legal claims, comply with law, prevent abuse or maintain essential security records.
We do not add support emails or attachments to advertising or marketing profiles.
14. Sharing and sale
Good Button does not sell personal data.
Good Button does not share your local notification database because it does not receive it. Personal data may be disclosed only:
- to Google through Firebase Crashlytics as described above;
- to service providers that help us operate business email or support, subject to appropriate obligations;
- where you deliberately choose a third-party destination for an export;
- where required by law, court order or a competent authority; or
- where reasonably necessary to establish, exercise or defend legal rights or protect users, Good Button or others from fraud, abuse or security threats.
15. Your data-protection rights
Depending on where you live and the information Good Button holds, you may have rights to:
- be informed about processing;
- request access to your personal data;
- ask us to correct inaccurate data;
- ask us to erase data;
- restrict processing;
- object to processing based on our legitimate interests, including Crashlytics processing, where applicable; and
- receive certain data in a portable format.
Most notification information never reaches Good Button. You can access and manage it directly within NotiScope, including through its search, export and deletion controls. Good Button cannot retrieve or delete local data from your device remotely.
To exercise a right or raise a data-protection complaint, email hello@goodbutton.co.uk. Please describe your request clearly. We may need to verify enough information to prevent disclosure or deletion of another person’s data.
We will handle data-protection requests and complaints within the time limits required by applicable law.
If you are in the UK and remain dissatisfied, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. If you are elsewhere in the EEA, you may complain to the data-protection authority in the country where you live or work, or where you believe an infringement occurred.
16. Children
NotiScope is not designed or directed specifically to children under 13. Notification history can contain sensitive information, so a parent or guardian should consider whether granting notification access is appropriate on a child’s device.
If you believe a child has sent personal data to Good Button through support or Crashlytics reporting in circumstances that require deletion, contact hello@goodbutton.co.uk.
17. Third-party services and stores
If you download NotiScope through Google Play, Google may process store, account, payment, security and device information under Google’s own privacy policy and terms. That processing is separate from NotiScope’s local notification history.
Android, device manufacturers, apps that create notifications, keyboards, document providers and cloud-storage providers may process information under their own privacy policies. Good Button does not control those independent services.
18. Changes to this policy
We may update this policy when NotiScope’s features, data handling, legal obligations or service providers change. We will update the date at the top and, where a change materially affects your choices or how data is collected, provide an appropriate in-app notice or take any other step required by law.
If a future version begins transmitting notification content or adds another third-party service, we will update this policy before that processing begins and take any additional steps required by law.
19. Contact
For privacy questions, rights requests or complaints:
Good Button
Email: hello@goodbutton.co.uk