Skip to content
Home MarkPDF TopDrawer About Contact

Legal

TopDrawer Privacy Policy

Last updated: 21 September 2026

The short version

Everything you save in TopDrawer stays on your device. There is no account, no sync and no server of ours to send it to. We cannot read your library, because we never receive it.

Reading the text inside your screenshots and documents happens on your iPhone, using what Apple already ships. Nothing is uploaded to be processed.

The App makes one kind of network connection: to our payments provider, to check whether you have bought Ultra. We run no analytics, no advertising and no tracking. The full detail is below.

  • Looking for the Terms of Use?

1. Who we are

TopDrawer is made by Zest Mavericks Pvt. Ltd., Bangalore, Karnataka, India. For the purposes of the GDPR, the UK GDPR and India's Digital Personal Data Protection Act, we are the data controller for the small amount of data described here. Contact: zestmavericks@gmail.com.

2. What stays on your device

Everything you save — notes, links, images, screenshots, PDFs, other files, the titles and tags attached to them, and the text recognised inside them — is stored in TopDrawer's own storage on your device, protected by iOS file protection and your device passcode.

It is never sent to us and never sent to anyone else. We operate no server that could receive it. There is no account to create, so there is nothing tying a library to a person in the first place.

When you share something into TopDrawer from another app, the share extension writes it into a shared folder on your device that only TopDrawer can read, and the main App moves it into the library the next time you open it. That folder never leaves the device either.

3. Reading your images and documents

TopDrawer recognises the text inside images and documents so you can search for it later. This uses Apple's Vision framework and runs entirely on your device. No image, document or page is uploaded anywhere to be read, by us or by anyone else.

4. Titles and tags

TopDrawer suggests a title and a few tags for what you save. On devices that support Apple Intelligence this uses Apple's on-device language model. On devices that do not, it falls back to a simple rule based method. Both run locally. The content of what you saved is not sent to us or to any third party for this, and there is no cloud processing option.

5. iPhone search (Spotlight)

If you leave "Include in iPhone search" switched on, TopDrawer publishes the titles and recognised text of your items to the system search index on your device, so you can find them from Spotlight without opening the App.

That index belongs to iOS and stays on the device. Switching the setting off does not just stop future indexing — it withdraws the items already published. You can switch it off during setup or at any time in Settings.

6. The lock

You can require Face ID, Touch ID or your device passcode before TopDrawer opens. This uses Apple's LocalAuthentication framework. The App asks iOS whether it is you and receives only yes or no. Your face or fingerprint data never leaves the Secure Enclave on your device, and the App never sees it, stores it or transmits it.

7. The clipboard

TopDrawer reads your clipboard only when you tap the Paste button. It never reads it when it launches, when it comes to the foreground, or at any other time. What you paste is then saved on your device like anything else.

8. Purchases

Apple handles every payment. We never see or store your card details, billing address or Apple Account credentials.

To check whether you have bought Ultra, the App uses RevenueCat, a purchase infrastructure provider acting as our processor. This is the one kind of network connection TopDrawer makes. RevenueCat receives an anonymous identifier it generates for the installation, the purchase and renewal information contained in your App Store receipt, and basic technical information such as the device model, the operating system version, the App version and the country of your store.

It does not receive your name, your email address, your Apple Account credentials, or anything you have saved in the App. The identifier is not linked to your identity by us, and we do not attempt to link it.

9. Diagnostics and analytics

We run none. TopDrawer contains no analytics SDK, no advertising SDK, no crash reporting service of ours, and no tracking of any kind. We do not know how many items you have saved, what you searched for, or which features you use.

If you have switched on Apple's own "Share iPhone Analytics" in iOS Settings, Apple may send us crash logs and performance data through App Store Connect. That is Apple's mechanism and your setting. Those reports are aggregated and are not tied to your identity.

10. Device backups

TopDrawer's data lives in the App's storage, which is included in the device backups Apple makes if you have them switched on, whether to iCloud or to a computer. That is Apple's backup, under your control and your Apple Account, and it is encrypted by Apple. We have no access to it. If you do not want your library in a backup, exclude the App from backups in iOS Settings.

11. Permissions the App asks for

  • Face ID: only if you switch the lock on, and only to confirm it is you. See section 6.
  • Photos, Files and other apps: TopDrawer does not ask for library-wide access. You choose what to send it, through the share sheet or the file picker, and it receives only that.

TopDrawer asks for no location, no contacts, no microphone, no camera and no health data, because it has no use for any of them.

12. Why we are allowed to process this

Where the GDPR or UK GDPR applies, our legal basis for the purchase information in section 8 is performance of our contract with you — it is how we unlock what you paid for. Where we rely on anything else, it is our legitimate interest in keeping the App working and preventing fraudulent access to paid features. Since we hold nothing else, there is nothing else to justify.

13. Who we share with

We do not sell your data, and we do not share it for advertising. There is nothing to sell: your library never reaches us. The only parties involved at all are:

  • Apple — as the App Store operator and payment processor, under Apple's own privacy policy.
  • RevenueCat — as our processor for purchase checking, as described in section 8.

We may disclose information if the law genuinely requires it. Given what we hold, that would amount to purchase records and nothing about what you saved.

14. How long we keep things

Your library is kept for as long as you keep it, on your device, and is gone when you delete the item or the App. We keep nothing of it at any point.

Purchase records held by our processor are kept for as long as needed to support the entitlement and to meet tax and accounting obligations.

15. International transfers

We are based in India. Our payment processor operates in the United States. Where personal data is transferred out of the EEA or the UK, it is covered by the European Commission's Standard Contractual Clauses or another approved mechanism.

16. Your rights

Depending on where you live you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, ask for it in a portable format, withdraw consent, and complain to a regulator. Users in India have rights of access, correction, erasure, grievance redressal and nomination under the DPDP Act. Users in California may ask what we collect and request deletion, and will not be treated differently for asking.

Because we hold almost nothing that identifies you, there is usually very little for us to return, and your library is not ours to return at all — it is already in your hands, and deleting the App deletes it. Write to zestmavericks@gmail.com and we will answer within 30 days.

17. Complaints and grievances

If something we have done with your data bothers you, tell us first and we will try to fix it. Our grievance officer for the purposes of Indian law is Aakash, reachable at zestmavericks@gmail.com. You may also complain to your local data protection authority, or to the Data Protection Board of India.

18. Children

TopDrawer is a general purpose tool and is not directed at children. We do not knowingly collect personal data from children under 13, or under the age at which parental consent is required where you live, which is 16 in parts of the EU and 18 in India. If you believe a child has provided us with personal data, write to us and we will delete it.

19. Security

Everything the App sends over the network uses HTTPS. Your library stays in the device's own storage and is protected by iOS file protection and your device passcode, and by the App's optional Face ID lock if you switch it on.

The most reliable security measure available to us is holding nothing, and that is the one we have taken: there is no server to breach and no database of user content to leak. No system is perfect, and no transmission over the internet can be guaranteed against interception.

20. Do Not Track

There is no finalised standard for Do Not Track signals, so we do not respond to them. We do not track you across other companies' apps or sites in any case.

21. This website

zestmavericks.com sets no cookies and runs no analytics or advertising scripts. If you use the contact form, the subject, name, email and message you type are sent to a Google Apps Script endpoint and stored in a Google Sheet we control, so that we can reply. We keep those messages for as long as we need them and delete them on request. Our web host may keep standard server logs, including IP addresses, for a short period.

22. Changes to this policy

We will post any change here and update the date at the top. If a change is significant, for example a new category of data or a new processor, we will say so in the App. This version is effective from 21 September 2026.

23. Contact

Zest Mavericks Pvt. Ltd., Bangalore, Karnataka, India. zestmavericks@gmail.com.