Privacy policy
One policy for all apps and for this website. The short version: I run no servers that hold your data, show no ads and do no tracking.
Last updated 6 October 2026
Who is responsible
Georgios Stavropoulos, an independent developer based in Greece, is responsible for the apps and website listed here. You can reach me through the support page or the contact form.
This policy covers FocusFence, Deltion, Sthenos, Panoptes, Hex!s, NC User Admin, iCard Store, Krasis, Periplous, TrustSign, AI Usage Limits (iOS and macOS), Masque, the Pinwatch website and scanner, and this website.
What is true for every app
- The apps have no accounts and no developer-run database. I cannot see what you store in an app. The one exception in this policy is the Pinwatch waitlist, described in the table below.
- No advertising, no advertising identifier, no cross-app tracking, and I never sell or share your data.
- No analytics or crash-reporting services. The only third-party services inside any app are the ones named for Krasis in the table below.
- What you create stays on your device or in your own iCloud. The apps ask your permission before reading Photos, Health, Screen Time, the camera, notifications or Face ID, and you can withdraw it any time in iOS Settings.
- Payments are handled by Apple. I never see your payment details.
- Nothing is sent to me unless you choose to send feedback, write to me, or join the Pinwatch waitlist.
What each app does with your data
Below, "leaves your device" lists everything the app sends anywhere, and to whom. Apps that offer iCloud sync use your private iCloud space, which only you and your devices can read.
| App | What it reads | Where it is kept | What leaves your device | Third-party code |
|---|---|---|---|---|
| FocusFence | Screen Time selections (opaque tokens from Apple’s picker), usage thresholds, Focus mode state | On the device. No iCloud. | In-app feedback form (public GitHub issue); purchases via Apple | – |
| Deltion | Documents and photos you import, Apple Health (read and write), Face ID | Encrypted on the device; keys in the Keychain. Optional iCloud sync (off by default). | Cloud AI only if you add your own key and ask it to analyse something: Anthropic, OpenAI or Google receive the document text and, for scanned pages, page images. iCloud if enabled. In-app feedback form (public GitHub issue). Purchases via Apple. | – |
| Sthenos | Apple Health data used for the energy score and fitness age, including heart, sleep, activity, body-composition and vitals measures, plus date of birth and sex | On the device. The computed score is passed to your Watch through your iCloud. | iCloud key-value store (your own iCloud, between your devices). In-app feedback form (public GitHub issue). | Offline calculation package, no network access |
| Panoptes | The App Privacy Report files you import | On the device. Optional iCloud sync with Pro. | Bundle identifiers to Apple’s iTunes Lookup. Optional reachability checks connect directly from your device to domains listed in your report. iCloud if enabled. Purchases via Apple. | – |
| Hex!s | Apple Health (read-only), Screen Time thresholds, Face ID | On the device, with iCloud sync (on by default; can be turned off). | iCloud. In-app feedback form (public GitHub issue), which includes the app version, iOS version and device model. Purchases via Apple. | – |
| NC User Admin | Your Nextcloud address, username and password (Keychain); the users and groups your server returns | Credentials in the Keychain. User and group lists cached on the device for up to one hour. | Only to the Nextcloud server you configure, over HTTPS. In-app feedback form (public GitHub issue). | – |
| iCard Store | Card numbers, security codes and PINs you enter or scan with the camera, Face ID, Reminders | Card number, code and PIN in the Keychain. Other card details in the app, with optional iCloud sync. | The first six digits of a card number go to binlist.net when the bundled issuer table has no match. Card fill into a page in the in-app browser sends those details to that site. iCloud if enabled. In-app feedback form (public GitHub issue). | – |
| Krasis | The meals you type | On the device. | OneSignal (push token, notification events, coarse usage tags). RevenueCat (anonymous ID, receipts, device model, OS and store country). Open Food Facts (a single food word, only if you switch food lookup on and tap it). Purchases via Apple. | OneSignal, RevenueCat |
| Periplous | Date, location and camera model of photos in your library; small thumbnails used for colour, discarded afterwards | On the device. Mirrored to your private iCloud if you are signed in. | iCloud. Apple’s geocoder receives a coordinate to name a stop when you open it. Purchases via Apple. | – |
| TrustSign | The PDF you choose to sign. Your certificate, read locally from your smart card or USB token through a card reader. Your card PIN, entered to unlock the card for one signature. | On the device only. The PIN is not stored, logged or transmitted. The signed copy goes only where you share it. | When the “Trusted timestamp” option is on (the default), a SHA-256 hash of the signature value goes to a public time-stamp authority, currently DigiCert (timestamp.digicert.com), to obtain an RFC 3161 timestamp. It never receives the document or its content, but it can see your device’s IP address and the hash. If you choose to export diagnostics (the card reader state and card command log, with the PIN removed), they leave the device only when you email them yourself. | No analytics or advertising code |
| AI Usage Limits (iOS) | Sign-in tokens for Claude, ChatGPT, Grok, Cursor and OpenRouter, obtained through Safari | Keychain on the device. No iCloud. | Each token goes only to its own provider. Tips via Apple. | – |
| AI Usage Limits (macOS) | The Claude Code credential in your Keychain and the Codex credential file | Nothing of its own. | Tokens go only to Anthropic and OpenAI. | – |
| Masque | Your Apple Account sign-in and two-factor step, including hardware security keys | Session in the Keychain. | Apple only. | – |
| Pinwatch (website and scanner) | On the website: your answers to the scope check, which stay in your browser unless you join the waitlist. On the waitlist: your email address, whether you would pre-pay, whether you want help with supplier security questionnaires, your scope answers and the page that referred you. The open-source scanner reads only the dependency files of the project you point it at. | Scope answers in your browser’s local storage. Waitlist entries on my own server in Greece. Your IP address is used briefly in memory, as a salted hash, to limit abuse, and is not stored. Entries stay until you ask for removal, or for 12 months after the paid plans open if you do not become a customer. The scanner keeps nothing of its own on a server. | Joining the waitlist sends the form to api.pinwatch.dev, reached through Cloudflare. The scanner sends the names and versions of your dependencies to public vulnerability sources (OSV, NVD, CISA, ENISA and EPSS) and nothing to me. When paid plans open, payments will be handled by Paddle. To have a waitlist entry removed, use the contact form on this site. | None. The Pinwatch website serves its own fonts and loads nothing from third parties. |
TrustSign: feedback and diagnostics
TrustSign has no accounts and I collect nothing through it. If you want to send feedback, or choose to share an exported diagnostics file (the card reader state and the card command log, with the PIN removed), use the contact form. Anything you send is used only to answer you and to fix the problem.
Feedback forms are public
FocusFence, Deltion, Sthenos, Hex!s, iCard Store and NC User Admin have a feedback form. Sending it passes your message through a small relay (a Cloudflare Worker) that opens an issue in the app's public GitHub repository. The issue contains what you type, including your name and email if you fill them in, plus the app version and platform. Anyone can read it. Please never put medical, financial or login details in it. If you want an issue edited or removed, tell me and I will do it.
Health and wellbeing apps
Deltion, Sthenos, Hex!s and Krasis are tools for personal organisation and self-awareness. They are not medical devices and do not give medical advice, diagnosis or treatment.
Open-source apps and other services
AI Usage Limits and Masque are unofficial and not affiliated with Anthropic, OpenAI, xAI, Cursor, OpenRouter, Apple or Nextcloud. They use only the sign-ins you already have, and send each one only to its own service. NC User Admin talks only to your own Nextcloud server. Each service you connect has its own privacy policy.
Deleting your data
- Delete items inside the app, or delete the app to remove everything stored on the device.
- For iCloud copies, use Settings, your name, iCloud, Manage Storage.
- Apple Health data an app wrote stays in Health until you remove it there.
- AI Usage Limits has Delete all data in its settings. Revoke access at the provider as well.
- I hold no other copy of your app data. The exceptions are public feedback issues (see above), for Krasis the records kept by RevenueCat and OneSignal, and Pinwatch waitlist entries, which I will delete on request through the contact form. Ask me and I will pass your request on.
Children
The apps are not directed at children and I do not knowingly collect personal data from children.
Your rights
Because I hold almost no personal data, there is usually nothing to access or erase beyond the cases above. You have the right to access, correct, delete and port the data I do hold, to object to its use, and to complain to your data protection authority. For Greece that is the Hellenic Data Protection Authority.
This website
This website uses no cookies, analytics or advertising. The contact form sends your name, email address, company (optional) and message to me by email, only to answer you. I keep the message for as long as the conversation needs it. The site runs on a server I operate, which keeps standard server logs that can include IP addresses, used only to keep the site secure. It is delivered through Cloudflare, which sees requests in order to apply security protections.
Changes
If this policy changes, I will update the date at the top. Material changes to what an app does with your data will also be mentioned in that app's release notes.