I am currently researching note-taking applications within the F-Droid ecosystem with a focus on ‘Privacy-by-Design’ principles. I have been analyzing various manifest structures and have noticed that while many apps provide great functionality, they often rely on broad permissions for sync or hardware features.
I am interested in whether there is a growing trend or ‘best practice’ for developing notes applications that operate without extra permissions—or with the absolute minimum required to function.
Are there any notable projects or design patterns you recommend for a ‘Zero-Permit’ or ‘Local-Only’ note-taking experience? I am particularly interested in how developers handle data persistence and organization while adhering to the principle of least privilege.
Thank you for your time and for all the great work on these projects!
Also @Auditor46 please stop using AI to ask qs. BTW, why are you here? You do not look like an auditor and I am very much doubting if you are even a real person, are you? Are you a bot in guise of this user?
I apologize for the misunderstanding. I am a real person, not a bot. I’m just very interested in mobile security and have been using tools to help me articulate my technical questions, as English isn’t my primary language and I’m still learning how to navigate forum discussions.
I’m here because I want to learn more about application privacy and how to audit permissions myself. I clearly overreached with my previous posts, and I’ll take a step back and keep my future questions simple and direct.
To answer your question, Markor is the note app I use and I feel it’s the best at what it does:
It asks for network access only so that you can chose to sync your notes if you wish, but it is not required. As for hardware permissions, I feel that those are somewhat required so that the app can access storage, otherwise you would lose your notes over time (it’s been a while since I developed for Android, so I may be wrong on the details here").
There is at least one app in FDroid that requires no permissions, but I have no experience with it. You might try it out and see how they’re handling the privileges you’re interested in: