Data policy
Everything we touch, listed.
The privacy policy says what Onus does in plain English. This page is the same thing field by field, with retention periods and the list of companies involved — so nothing rests on a sentence you have to take on trust.
Last updated 1 September 2026.
Who is responsible
Onus is made and operated by an independent developer, who is the data controller for the small amount of personal data described below. For anything on this page, write to privacy@onusapp.co.uk.
What stays on your device, permanently
The following never leaves your phone. It is written to the app’s own private storage, it is not uploaded, and there is no table on our side it could be written to even if we decided to build one. We are not the controller of it in any meaningful sense, because we never receive it.
- Your three non-negotiables, and their wording.
- Your weekly, monthly and yearly vows.
- Every mark you make, and every day you let go.
- The reason you gave for letting a day go.
- Your weekly reviews, monthly wraps and the whole ledger.
- Which form Oni has taken, and every card Oni has drawn you.
- Every reminder you set, and the time you set it for.
- Every line on your list.
- Your name, and anything else you told Oni during onboarding.
If you use Onus without an account — which is the default, and works completely — that is the entire data story. Nothing at all is sent to us and there is no record of you anywhere.
What we hold, if you open an account
An account exists so that Oni is still there on your next phone. It is optional, it is asked for late, and this table is the complete contents of it.
| Category | Why, and for how long |
|---|---|
| Handle | Identifies the account. Legal basis: performance of a contract. Kept until you delete the account. |
| Password | Stored only as a one-way hash by our authentication provider; not readable by us. Performance of a contract. Kept until you delete the account. |
| What Oni calls you | Free text, often blank, never used to identify you. Performance of a contract. Kept until you delete the account. |
| Recovery email, if you gave one | Used for password resets you ask for and nothing else. Consent, withdrawable by clearing the field. Kept until you clear it or delete the account. |
| Account creation date | Support and abuse handling. Legitimate interests. Kept until you delete the account. |
| Entitlement — Keeper or Custodian | So a paid feature works on a new phone. Performance of a contract. Kept until you delete the account. |
| Subscription term, status and period end | So the app knows whether the subscription is live. Performance of a contract. Kept until you delete the account. |
| Billing provider identifier | An opaque string that lets a renewal be matched to your account. Not a card number, not an email. Performance of a contract. Kept until you delete the account. |
| Server logs | Written automatically when the app calls our API. Security and debugging. Legitimate interests. Deleted after 30 days. |
There is no other column and no other table. Accounts cannot see each other — no social graph, no leaderboard, no directory, and no way to look up another keeper.
What we do not collect at all
- No advertising identifier, and no advertising.
- No third-party analytics or tracking SDK of any kind.
- No location, at any precision.
- No contacts, photos, calendars, health data or microphone access.
- No device fingerprint, and no cross-app or cross-site tracking.
- No card number — Apple handles payment and we never receive one.
Under Apple’s App Privacy categories, this makes Onus Data Not Linked to You: none, Data Used to Track You: none, and, for anyone who opens an account, Data Linked to You limited to contact info (a recovery email, if given), user ID (the handle) and purchases (the entitlement above).
Notifications
Reminders are scheduled with iOS on your own phone. They are not push notifications: nothing is sent from a server, so there is no push token to store and no delivery record anywhere. The text of a reminder is passed to iOS, because iOS is what displays it, and to no one else. Permission is requested the first time you set a reminder rather than on first launch, and can be withdrawn in Settings → Notifications → Onus without affecting anything else in the app.
Who else touches it
Three processors, each doing one thing, each bound by a data processing agreement:
- Supabase — hosts the account database and the authentication service. Data resides in the European Union.
- RevenueCat — reconciles App Store subscription receipts so the app knows what you are entitled to. Receives the opaque identifier above, never your ledger.
- Apple — takes the payment and delivers the app. Apple acts as its own controller for that, under Apple’s privacy policy rather than ours.
Nobody else. No data is sold, and no data is shared for anybody else’s purposes. Where a processor operates outside the UK or EEA, transfers are covered by the standard contractual clauses.
Security
Everything travels over TLS. Account rows are protected by row-level security so one account cannot read another’s, passwords are hashed by the authentication provider rather than held by us, and no administrative interface exposes the ledger because the ledger is not there to expose. On the device, data sits in the app’s private container, protected by the phone’s own encryption whenever it is locked.
Getting it back, or getting rid of it
Delete the account: in the app, at More → Account → Delete account. The profile row and the subscription record are removed immediately and permanently. No grace period, no archived copy.
Delete the ledger: delete the app. The ledger was only ever on the phone, so removing the app removes it. That is the trade this design makes, and it is worth saying plainly: complete privacy and effortless portability are opposites, and Onus chose privacy.
Ask us: write to privacy@onusapp.co.uk for a copy of everything held about you, a correction, or erasure. We answer within 30 days, and usually the same week, because there is very little to look up.
Your rights
In the UK, EU and EEA you have the right to access, rectify, erase, restrict, export and object to the processing of your personal data, and to withdraw consent where consent is the basis. Almost all of them resolve to the one button described above. You can also complain to your national supervisory authority — in the UK, the Information Commissioner’s Office.
Nothing here is used for automated decision-making or profiling. Onus is not directed at children under 13 and we do not knowingly hold anything from them.
Changes
If a new field is collected, it appears in the table above and the date at the top changes in the same release. A change that moved your ledger off your device would be announced before it happened, not after — and would not ship without asking you first.