Your data is yours. We don't want it.
Our default is not collecting your data in the first place. We never sell it, we design our products to work without holding it whenever we can, and where that's not possible we build in self-hosting rather than run a server ourselves. This isn't a policy bolted on after the fact — it's how we build software.
We don't sell your data
Not to advertisers, not to data brokers, not to "partners." There's no version of our business model that involves selling what we know about you, because we've built our products to not need to know much about you in the first place.
We'd rather not have it at all
Wherever possible, our products are designed to work fully offline, so your data lives on your device, not our servers. Data we never receive can't be leaked, subpoenaed, or misused by us — that's a stronger guarantee than any policy promise.
Self-hosting by design
When a product needs backup or multi-device sync, our default architecture points it at infrastructure you control, not a server we operate. That's a design philosophy we build in from the start, not a bolted-on option for the technical few.
Your rights don't depend on us
Because your data lives on your device or your own server, you already have complete access, export and deletion — not as a policy we grant you, but as a consequence of where the data sits. If we ever offer hosted sync, we'll publish exactly what it stores, and where, before it launches.
No analytics or tracking SDKs
This is a currently-verifiable fact, not an unfalsifiable promise — our backend and apps are source-available, so it can be checked against the code rather than trusted on faith.
Exceptions require disclosure
If a future feature in any of our products ever needs to send data off-device (for example, optional cloud backup or receipt scanning via a third-party API), that will be a deliberate, opt-in decision — never a silent default.
What this page isn't
This page describes the engineering philosophy behind everything we build — it is not a substitute for a formal legal privacy policy. Individual products will have their own required privacy policy text (for example, covering payment processing), written to match the principles described here.
Want the technical details?
See exactly how these principles are implemented in Trend & Tend, our current product — self-hosting, data storage, and sync internals, all of it.