How we protect your data
Specific practices, not promises. Last updated: September 3, 2026.
Encrypted in transit
Every request to our sites and APIs travels over HTTPS. Plain HTTP is redirected, never served.
No client-side reads
Our database rules deny read, update and delete to every browser client. Those paths exist only on the backend.
Validation at the data layer
Writes are checked by the database itself — not just the app. Malformed input is rejected before it is stored.
We never see your card
Purchases are handled by Apple and Google. Card numbers and billing addresses never reach our systems.
Database access control
Our Firestore security rules are written deny-first. For the newsletter collection, browser clients may only create a record; read, update and delete are denied outright and happen only through server-side code. A leaked client key therefore cannot be used to read our data.
Input validation
Validation runs in the database rules, so it cannot be bypassed by calling the API directly: email addresses must match an address pattern, the source application must be identified, and a write is rejected unless every field is on an explicit allow-list. Unknown fields are refused rather than silently stored.
Authentication
Several of our apps use anonymous authentication: you get an account identifier without giving us a name, an email address or a password. Where an app offers cloud sync, signing in is optional and the app remains fully usable without it.
Payments
In-app purchases and subscriptions are processed by the App Store and Google Play through RevenueCat. We receive a purchase confirmation — never payment credentials. There is no card data in our systems to lose.
Diagnostics
Crash reports and usage analytics are collected through Firebase and are anonymised. They describe what the software did, not who you are.
What this page does not claim
We are a small studio. We do not hold SOC 2 or ISO 27001 certification, and we do not run a paid bug-bounty programme. We would rather tell you that plainly than imply a level of assurance we have not been audited for.
Reporting a vulnerability
If you find a security issue, email [email protected] with steps to reproduce it. Please give us a reasonable window to fix the issue before disclosing it publicly. We will confirm receipt and tell you what we found.