← Onus

Data policy

Everything we touch, listed.

The privacy policy says what Onus does in plain English. This page is the same thing field by field, with retention periods and the list of companies involved — so nothing rests on a sentence you have to take on trust.

Last updated 1 September 2026.


Who is responsible

Onus is made and operated by an independent developer, who is the data controller for the small amount of personal data described below. For anything on this page, write to privacy@onusapp.co.uk.

What stays on your device, permanently

The following never leaves your phone. It is written to the app’s own private storage, it is not uploaded, and there is no table on our side it could be written to even if we decided to build one. We are not the controller of it in any meaningful sense, because we never receive it.

If you use Onus without an account — which is the default, and works completely — that is the entire data story. Nothing at all is sent to us and there is no record of you anywhere.

What we hold, if you open an account

An account exists so that Oni is still there on your next phone. It is optional, it is asked for late, and this table is the complete contents of it.

Category Why, and for how long
Handle Identifies the account. Legal basis: performance of a contract. Kept until you delete the account.
Password Stored only as a one-way hash by our authentication provider; not readable by us. Performance of a contract. Kept until you delete the account.
What Oni calls you Free text, often blank, never used to identify you. Performance of a contract. Kept until you delete the account.
Recovery email, if you gave one Used for password resets you ask for and nothing else. Consent, withdrawable by clearing the field. Kept until you clear it or delete the account.
Account creation date Support and abuse handling. Legitimate interests. Kept until you delete the account.
Entitlement — Keeper or Custodian So a paid feature works on a new phone. Performance of a contract. Kept until you delete the account.
Subscription term, status and period end So the app knows whether the subscription is live. Performance of a contract. Kept until you delete the account.
Billing provider identifier An opaque string that lets a renewal be matched to your account. Not a card number, not an email. Performance of a contract. Kept until you delete the account.
Server logs Written automatically when the app calls our API. Security and debugging. Legitimate interests. Deleted after 30 days.

There is no other column and no other table. Accounts cannot see each other — no social graph, no leaderboard, no directory, and no way to look up another keeper.

What we do not collect at all

Under Apple’s App Privacy categories, this makes Onus Data Not Linked to You: none, Data Used to Track You: none, and, for anyone who opens an account, Data Linked to You limited to contact info (a recovery email, if given), user ID (the handle) and purchases (the entitlement above).

Notifications

Reminders are scheduled with iOS on your own phone. They are not push notifications: nothing is sent from a server, so there is no push token to store and no delivery record anywhere. The text of a reminder is passed to iOS, because iOS is what displays it, and to no one else. Permission is requested the first time you set a reminder rather than on first launch, and can be withdrawn in Settings → Notifications → Onus without affecting anything else in the app.

Who else touches it

Three processors, each doing one thing, each bound by a data processing agreement:

Nobody else. No data is sold, and no data is shared for anybody else’s purposes. Where a processor operates outside the UK or EEA, transfers are covered by the standard contractual clauses.

Security

Everything travels over TLS. Account rows are protected by row-level security so one account cannot read another’s, passwords are hashed by the authentication provider rather than held by us, and no administrative interface exposes the ledger because the ledger is not there to expose. On the device, data sits in the app’s private container, protected by the phone’s own encryption whenever it is locked.

Getting it back, or getting rid of it

Delete the account: in the app, at More → Account → Delete account. The profile row and the subscription record are removed immediately and permanently. No grace period, no archived copy.

Delete the ledger: delete the app. The ledger was only ever on the phone, so removing the app removes it. That is the trade this design makes, and it is worth saying plainly: complete privacy and effortless portability are opposites, and Onus chose privacy.

Ask us: write to privacy@onusapp.co.uk for a copy of everything held about you, a correction, or erasure. We answer within 30 days, and usually the same week, because there is very little to look up.

Your rights

In the UK, EU and EEA you have the right to access, rectify, erase, restrict, export and object to the processing of your personal data, and to withdraw consent where consent is the basis. Almost all of them resolve to the one button described above. You can also complain to your national supervisory authority — in the UK, the Information Commissioner’s Office.

Nothing here is used for automated decision-making or profiling. Onus is not directed at children under 13 and we do not knowingly hold anything from them.

Changes

If a new field is collected, it appears in the table above and the date at the top changes in the same release. A change that moved your ledger off your device would be announced before it happened, not after — and would not ship without asking you first.