Our approach
Useful software, with clear boundaries.
Privacy is not a badge we add at the end. It is a series of product decisions we should be able to explain.
Collect less
Every data point needs a purpose. We avoid advertising profiles and do not add collection simply because a tool makes it easy.
Keep personal work local when possible
Photos, videos, drafts, and other personal work should remain on the device when the product can deliver its core value without a server copy.
Name the services involved
Some functions need outside infrastructure, such as App Store payments, subscription verification, or explicitly disclosed analytics. Product policies should name those services and describe their role.
Make controls real
A setting should change the underlying behavior, survive relaunches, and describe its limits. Turning off optional analytics should stop future collection, not merely hide a label.
Prefer specific claims
“Stored in the app library on your device” is useful. “Privacy is our priority” is not. We aim to publish verifiable descriptions for every app.