The app, first
Your tasks, groceries, recipes, photos and paperwork stay on your phone. There is no account, so nothing to attach them to, and no server to put them on.
What leaves the device leaves because you asked for it: nothing at launch, nothing in the background, nothing while you type.
- A scanned barcode goes to the public Open Food Facts database to look the product up. Nothing else goes with it — no device identifier, no address.
- A product name, if you search for a safety recall, goes to the French public RappelConso service. That setting is off until you turn it on.
- The language model, if you choose to install it, downloads from Hugging Face. Nothing goes if you do not ask for it. If the file requires a personal access token, the one you paste is sent to Hugging Face to be checked, and to nobody else.
- Signing in to your Hugging Face account, when a model asks you to accept its licence or to create a token, happens in a web view opened by the app itself, not in your browser. That view runs the Hugging Face site and keeps its cookies, third-party ones included: that is what holds the session from one screen to the next. The app reads nothing of what passes through it — it only receives the token you paste — and signing out clears those cookies.
- The address of a recipe or a calendar, when you are the one who supplies it: the app reads that page, with no cookie and no referrer. It introduces itself by the app’s name and version, and by your phone’s language; the site you visit sees your IP address, as does every site you open.
- A task sent to another phone travels directly, with no server in between.
One button hands over to your browser: searching Google for a device’s manual, with the words you typed. What goes then goes from there, with its cookies and whatever accounts are signed in, and its rules apply, not ours. The Hugging Face web view does the same for any address that leaves its domain: it keeps only huggingface.co.
No analytics, no advertising, no automatic crash reporting. There is nothing to sell, so nothing to collect.
The website, next
Reading these pages requires no data about you. No tracker, no cookie, no analytics: nobody knows you were here.
Two things, and only two, stay in your browser: the light or dark theme you pick at the foot of the page, so the site opens the way you left it; and, if you are a tester, the link to your space, so you do not have to dig it out of your inbox. Neither one leaves this device — not to us, not to anyone. Clearing your browser’s site data removes both.
If you sign up for the testing programme, we keep your email address, optionally your phone’s Google account address if you give it, the date of your consent and the exact wording you agreed to. Nothing else — not your name, not your IP address.
- Addresses are encrypted in our database. A stolen copy would not yield a usable list.
- Your address is written down encrypted, pending, and nothing more. If you do not follow the link you receive, the request erases itself after twenty-four hours.
- Every message carries a link to leave, in one click. Unsubscribing is final: we never “correct” it afterwards.
- We only write to you about the app — a new version, a problem that concerns you. Never anything else, never on behalf of a third party.
If you send us tester feedback, it reaches us by email with your address as the reply-to, so that we can answer you. You can ask us to delete what we hold at any time: write to us, and it is done.
Your rights
Access, correction, erasure, objection: European law gives you these, and we have neither the wish nor the means to make them difficult. An email is enough. We have almost nothing to hand back in any case.

