Privacy Policy
This Privacy Policy explains how Olnesta Ltd (“Olnesta”, “we”, “us”) collects, uses, and shares personal information when you use our iOS applications and related services (each, an “App”). It covers every App published by Olnesta Ltd on the App Store.
1. Who we are
Olnesta Ltd is a private limited company registered in England and Wales under company number 17191832, with its registered office at 17 Kings Gardens, Walton on Thames, Surrey, KT12 2DW, United Kingdom.
For any privacy questions, contact us at privacy@olnesta.com.
2. Information we collect
2.1 Information you give us directly
- Profile inputs. Information you enter into an App during onboarding or use — for example a first name or nickname, free-text answers to in-app questions, evening reflections, or items you photograph and label.
- Email address (optional). Some Apps ask you to enter an email so we can send you a periodic note. Email capture is opt-in and can always be skipped.
- Photos and similar media (optional). Some Apps let you take or upload a photo so we can identify or describe its contents. Photos are not stored on our servers beyond the time needed to return a result.
- Customer support correspondence. If you email us, we keep the message and our reply.
2.2 Information we collect automatically
- Anonymous device identifier. Each App generates a random identifier on your device (stored in iOS Keychain) so that your settings and content can sync across your own devices. This identifier is not linked to your Apple ID, your email, or any directly identifying information unless you choose to provide one.
- Subscription state. Whether you are on the free tier, on a free trial, or have an active subscription, returned to the App by Apple’s StoreKit. We do not see your payment card or your full Apple ID.
- Product analytics. Anonymous usage events (screen views, button taps, errors) tagged with the App’s bundle identifier and a random analytics ID, used to understand how the App is used and to fix bugs. Analytics events do not contain free-text inputs, photos, or your email.
- Crash and diagnostic logs. If the App crashes, the iOS system may forward an anonymous crash report to us via Apple. You can opt out in iOS Settings → Privacy & Security → Analytics & Improvements.
3. How we use your information
We use the information described in Section 2 to:
- Run the App, including syncing your content across your own devices and persisting your settings.
- Provide the specific feature you requested — for example, returning a photo identification, generating a written response, or sending a weekly note to your inbox if you opted in.
- Process subscriptions, free trials, and refunds via Apple’s StoreKit.
- Send service messages relating to your subscription, such as renewal reminders or material changes to this Policy.
- Diagnose problems, fix bugs, and improve the App.
- Comply with legal obligations and respond to lawful requests.
4. Lawful bases for processing (UK and EU users)
If you are in the United Kingdom or European Economic Area, we rely on the following lawful bases under UK GDPR and EU GDPR:
- Contract (Article 6(1)(b)) — to provide the App you have downloaded and any subscription you have purchased.
- Legitimate interests (Article 6(1)(f)) — to keep the App secure, prevent fraud, debug crashes, and improve the product. We balance this against your rights and only collect what we need.
- Consent (Article 6(1)(a)) — for optional features such as email capture or push notifications. You can withdraw consent at any time.
- Legal obligation (Article 6(1)(c)) — when we must keep records or respond to a lawful request.
5. Who we share information with
We do not sell your personal information and we do not share it with advertisers. We do use a small number of trusted service providers (data sub-processors) to run the App. Each of them is bound by a written contract that limits how they may use your data.
| Service provider | Purpose | Region |
|---|---|---|
| Apple Inc. | App Store distribution, in-app subscriptions, push notifications, crash reports. | United States |
| Google Cloud (Google LLC) | Hosting our backend services (Cloud Run) and storing synced content (Cloud Storage). | europe-west1 (Belgium) by default |
| PostHog Inc. | Anonymous product analytics. | United States |
| Anthropic PBC | Generating written responses for Apps that use a chat or daily-content feature. | United States |
| OpenAI, OpenAI Ireland Ltd | Generating images and analysing photos that you submit for identification. | United States / Ireland |
| Hume AI Inc. | Speech synthesis for Apps that use a voice feature. | United States |
| Resend (Resend, Inc.) | Sending email when you opt in to receive one. | United States |
Any of these sub-processors may change over time. We will update this list when we add or remove a sub-processor.
6. International data transfers
Some of our sub-processors are based outside the United Kingdom and the European Economic Area, primarily in the United States. Where personal data is transferred internationally, we rely on the European Commission’s and the UK Information Commissioner’s approved transfer mechanisms — including Standard Contractual Clauses and the UK International Data Transfer Addendum — to make sure your data continues to be protected.
7. How long we keep information
- Synced content (your settings, history, written entries, labels) — kept while you use the App and for 24 months after the App is uninstalled or you ask us to delete your account, after which it is deleted from our backend.
- Photos submitted for identification — processed in real time and deleted from our servers within 30 days.
- Subscription records — kept for 7 years to meet UK accounting and tax requirements.
- Customer support correspondence — kept for 24 months after the conversation closes.
- Anonymous analytics — kept in aggregated form indefinitely; the underlying anonymous events are kept for up to 12 months.
8. Your rights
Depending on where you live, you have some or all of the following rights over the personal information we hold about you. To exercise any right, write to privacy@olnesta.com.
8.1 Rights for UK and EU users
- Access — request a copy of the personal information we hold about you.
- Rectification — ask us to correct anything that is wrong.
- Erasure — ask us to delete your information (the “right to be forgotten”).
- Portability — receive a copy of your information in a portable format.
- Restriction and objection — limit how we use your information, or object to processing based on legitimate interests.
- Withdraw consent — for any processing we do based on your consent.
- Complain to a regulator — UK users may complain to the Information Commissioner’s Office (ico.org.uk); EU users may complain to their local data protection authority.
8.2 Rights for California users (CCPA / CPRA)
- The right to know what personal information we have collected, the categories of sources, and the purposes of collection.
- The right to delete personal information we have collected.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the CCPA.
- The right not to be discriminated against for exercising any of these rights.
You can exercise any of these rights by writing to privacy@olnesta.com.
9. Children
Our Apps are not directed at children under 13 (or under 16 in some EU countries) and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. Security
We take reasonable technical and organisational measures to protect your personal information, including encryption in transit (TLS) and at rest, narrow access controls on backend services, and isolating each App’s backend tokens. No method of transmission or storage is perfectly secure; if we ever experience a breach that affects your personal information, we will notify you and the relevant regulator as required by law.
11. Cookies and tracking technologies
Our Apps do not use cookies or third-party advertising trackers. This website (olnesta.com) uses no cookies and serves no third-party scripts.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date at the top and, where the change is material, we will notify you in-App or by email if you have provided one. Your continued use of an App after the change takes effect means you accept the updated Policy.
13. Contact
If you have any questions or want to exercise a right under this Policy, contact us at:
Olnesta Ltd
17 Kings Gardens, Walton on Thames, Surrey, KT12 2DW, United Kingdom
privacy@olnesta.com