Known — Privacy Policy
Last updated: 2026-07-29
Contact
For privacy questions, email privacy@erosdowgroup.com.
Data practices
| Collects personal data | Yes |
| Uses analytics | No |
| Uses crash reporting | No |
| Serves ads | No |
| Uses cookies | No |
| Uses third-party SDKs | Yes |
| Requires account | Not to start — five answers work with no account. An account is required to share. |
| Stores data remotely | Yes |
| Tracks users | No |
| Collects children's data | No |
| Processes payments | No |
Third-party services
- Supabase — the database, authentication and the two functions that create and serve share links. This is our own backend, hosted in the eu-west-2 (London) region, and it is the app's only third-party SDK.
What data is collected
Three things, and this is the complete list: your answers, including any free-text context you add and any "still figuring this out" markers; an account identifier, so the database can tell your vault from anyone else's and so a share can be revoked; and sharing records — which answers a link covers, when it was created, when it expires, when it was last opened and how many times. It does not collect your contacts, calendar, photos, location or microphone: the app requests no system permissions at all. There is no analytics SDK, no crash-reporting SDK and no advertising identifier in it.
How data is used
Your data is used only to run the app: holding your manual, showing you what you have shared, and serving the specific answers a link covers to whoever holds that link. It is never sold, and there is no advertising, tracking or analytics of any kind. On encryption, precisely: this app is NOT end-to-end encrypted. Your content is encrypted in transit and at rest, the database itself enforces who can read what rather than trusting the app, dashboard access is restricted and administrator accounts require multi-factor authentication — but someone with privileged access to the production database could in principle read stored content. End-to-end encryption would have made shared access, revocation and account recovery substantially harder, and we would rather say this plainly than imply more than we can deliver.
Data retention
Your own answers are cached on your device so the app reads offline, written with iOS file protection so they are unreadable until the device has been unlocked at least once after boot. Content shared to you is never cached. On our side, data is stored with Supabase in the eu-west-2 (London) region for as long as your account exists. Editing an answer creates a new version rather than overwriting the old one, so your own history is preserved and anyone currently holding a link sees the current version rather than a stale copy. In-app account deletion is not yet available in this version — it is a known gap, it is required before public release, and until it ships you can email privacy@erosdowgroup.com and we will delete your account and its data.
Your choices
Every answer starts private and says so. Sharing is per answer, never all-or-nothing, and before a link exists you see the exact page the recipient will get — not an approximation of it. Links are unguessable (32 random bytes) and stored only as a hash, so we cannot recover a link to resend it; the recipient page is served no-store, no-referrer and noindex. Every link you have created is listed in the app with when it was made and when it was last opened, and revoking one stops it working immediately. The one limit we cannot engineer around: if someone screenshotted or copied what you shared before you revoked it, that copy is theirs — revocation removes their access, it cannot reach into their camera roll. Depending on where you live you may have the right to access, correct, export or delete your data; in-app export and deletion are not in this version, so email privacy@erosdowgroup.com and we will act on it.