We believe privacy is an inviolable human right. Our iOS and Android mobile architectures run offline-first with zero behavioral trackers, localized cryptographic keyrings, and client-side zero-knowledge telemetry isolation.
Zero third-party trackers, no Meta pixel, no Firebase Behavioral Analytics, and no Advertising Identifiers (IDFA / GAID) embedded in binaries.
No Brokers. Ever.
phonelink_lock
Offline-First Storage
Habits, workflows, audio files, and notebooks execute entirely on sandboxed device silicon using AES-256 SQLite and iOS Secure Enclave / Android KeyStore.
Hardware Sandboxed
key
Zero-Knowledge Sync
When opting into cloud replication via FocusFlow or Chronicle, payloads are encrypted client-side. Our server clusters hold zero decryption keys.
E2E Mathematical Seal
monetization_on
No Data Monetization
Our sole source of revenue is direct app licenses and honest native subscriptions. We do not sell, rent, license, or exchange user habits with data intermediaries.
100% User-Funded
Article 01Strict Prohibitions
Information We Never Collect
Unlike traditional mobile apps relying on ad-supported monetization schemes, AppNaya rejects the gathering of non-essential signals. Under no circumstances do our client apps or backend daemons record the following telemetry:
cancel
Advertising IDs (IDFA & AAID)We never solicit advertising authorization from iOS or Android OS kernels.
Contact Book & Call LogsWe never request permission to scrape your personal address book or social graphs.
cancel
Session Replay / HeatmapsNo FullStory, Smartlook, or touch vector recording libraries run in our processes.
balanceArchitecture Comparison Matrix
Data Vector
Ad-Supported Apps
AppNaya Standard
User Content (Notes, Habits)
Server NLP & Ad Retargeting
lockLocal SQLite / E2EE
Analytics Frameworks
Google Firebase, Meta SDK
check_circleZero SDKs (0 KB)
Biometric Authentication
Often relayed to cloud identity
shieldLocal Hardware Enclave
Data Retention Policy
Indefinite lake archival
delete_foreverEphemeral / User Controlled
Article 02Operational Scope
Information We May Process
To provide critical operational functionality (such as validating software licenses or delivering customer support), we handle a deliberately minimal set of data:
receipt_longAnonymous App Store Receipts
When you activate AppNaya Pro, Apple StoreKit or Google Play Billing sends a cryptographically signed transaction token. We receive an obfuscated transaction identifier to unlock features without linking your legal name or payment card number.
contact_supportVoluntary Support Inquiries
If you email supportappnaya@gmail.com, we retain your email address and message thread strictly to resolve your query. Support transcripts are automatically pruned 90 days after ticket resolution.
Article 03E2EE Protocol
Sync & Cloud Infrastructure
For users who enable multi-device sync across iPhone, iPad, Mac, and Android, AppNaya operates on a pure Zero-Knowledge Cryptographic Model:
lockSync Pipeline CryptographyChaCha20-Poly1305
phone_iphone
Device KeyringKey created in Secure Enclave. Never transmitted.
enhanced_encryption
Client-Side CipherVault encrypted prior to socket dispatch.
cloud_done
Zero-Knowledge CloudStores opaque blobs. Blind to all content.
infoiCloud Private Database or Google Drive AppData folder is used when native ecosystem sync is toggled.
If our servers are ever subpoenaed or legally compelled to release data, we can only produce randomized ciphertext. We physically cannot recover notes, audio clips, or task lists because we do not possess the client master passphrase.
Article 04Commercial Terms
In-App Purchases & Payments
All financial transactions are mediated exclusively through the platform operating system:
check_circleApple App Store (iOS/macOS): Handled via Apple StoreKit 2 APIs. Apple processes billing instruments; we never see your credit card number, billing address, or CVV.
check_circleGoogle Play Store (Android): Managed through the Google Play Billing Library. Google secures PCI-DSS compliance on our behalf.
Article 05Strict Opt-In
Diagnostic Crash Reports (Opt-In Only)
If an application encounters an unexpected exception or crash, symbolicated crash logs are handled solely through operating-system level diagnostics:
bug_report
System Level DiagnosticsOnly dispatched if you enabled “Share with App Developers” in iOS Settings or Android System Preferences.
No Sentry / No Crashlytics
Article 06Global Compliance
Your Rights & Data Portability (GDPR, CCPA, CPRA)
We extend full European Union GDPR standards and California Consumer Privacy Act (CCPA/CPRA) protections to every user worldwide, regardless of citizenship:
Right of AccessInspect any telemetry or billing metadata associated with your platform store receipts.
Right to ErasureInstant cryptographic shredding of all server-stored encrypted sync payloads.
Data PortabilityOne-click uncompressed JSON & open-format SQLite raw databases straight out of the app.
database
Self-Service Data Management Utility
Generate raw device backups or purge cached encryption keys
AppNaya products maintain your local SQLite instances in human-readable, schema-documented structures. Use the client tool below to trigger an integrity and export dry run:
Article 07COPPA Compliance
Children's Privacy Protection
Our applications do not knowingly collect personal information from children under the age of 13 (or 16 in certain European member states). Because our apps operate without registration accounts or online behavioral monitors, young learners and minors can safely employ our utility apps without personal exposure.
Article 08Corporate Governance
Legal Entity & Amendments
This policy is governed by AppNaya Studio LLC, incorporated in Delaware, United States, and operated in accordance with GDPR representative mandates in the United Kingdom. We reserve the right to revise this policy to adapt to new native operating system revisions (e.g., iOS major releases or Android API level updates). Continued use of the software signifies your understanding of updated terms.
securityDirect Governance Contact
Data Protection Officer & Legal Inquiries
Questions regarding our cryptographic implementations, independent audit verifications, or GDPR/CCPA regulatory requests may be directed to our dedicated DPO desk: