Your data has a life
It enters something, it lives inside something, it leaves something. Every privacy promise you have ever read is a claim about one of those three moments, and most of them fail because the company making the promise built its business on the other two. So we wrote one rule for each moment, and we built the apps so the rules enforce themselves.
We never hold it
Start with a question worth asking: how does “forgot password” actually work? A company can reset your password only because it holds the thing your password protects. Every recovery flow is a receipt for custody. Not villainy, structure: their features need your data on their machines, so the keys live there, and the recovery desk follows.
Our apps have no accounts... nothing to sign into, nothing to reset, and restoring a purchase belongs to Apple, not us. When an app has a lock, it’s your face or your device code, held by your phone, recoverable by proving the phone is yours. So when our support page says we can’t reset your password because we never had it, read it carefully. It sounds like a failure, it’s the audit.
Nothing crosses unseen
Everything the apps do, the math, the intelligence, the storage, happens on the phone in your hand. Where possible the app is built without permission to touch the network at all, which is stronger than any policy: a promise can be broken, a binary without a socket cannot open one. Airplane mode changes nothing. Every feature you paid for works in a basement.
Data does leave sometimes, because you send it: you export a file, you copy, you print. Before any byte crosses that line, the app shows you the blast radius, which means three plain things: what’s in the file, counted, “14 cards with balances,” never “your data”; where it’s going; and how far it can travel once it’s out, because our protections don’t follow it and we can’t recall what we never touch. Then two buttons of equal size. Sharing your own data is your right, sharing it blind is a design failure... ours, not yours.
You leave with everything
Here’s the test every export must pass: if this studio vanished tonight, apps pulled, company gone, could you open your records ten years from now with free, ordinary software and carry on without us? If the answer is no for any piece of your data, the app doesn’t ship. So export is complete, every record, every field, the whole history, in a file a spreadsheet opens and a file a human reads, never behind a payment, never rationed, one tap. And erasing everything is one clear action that offers the export first, because leaving empty-handed should be a choice, never an accident.
Data you can’t take with you and use without us was never yours. That’s the entire theory of ownership these apps run on.
The proof is what we can’t do
Notice what the three rules share: each is an inability. Can’t reset, can’t see, can’t keep you. A privacy policy asks you to trust intentions; an inability doesn’t need your trust... check it. The App Store label reads Data Not Collected because there’s nothing to collect, and view-source on this very page finds no tracker because none exists.
We can’t sell what we never see. Everything else follows from that sentence.