Privacy
The short version: we don’t have your data.
No accounts, no servers, no analytics in the apps. What follows is the same sentence, said carefully enough to be checked — first what is true of every app, then each app on its own.
1Common to every UnBuild app
Who this is from
All the apps listed below are designed and built by UnBuild.me, Bengaluru, India. Questions about this policy, or about your data in any of these apps: hi@unbuild.me.
What is true of all of them
- No accounts. None of these apps has a sign-in, so there is no profile, no password and no record of you as a user of them.
- No UnBuild server. We do not operate a backend that these apps send your content to. Where an app makes a network request at all, the specific request is named in that app’s section below, along with who receives it.
- No analytics, no advertising, no tracking. No analytics SDK, no advertising identifier, no attribution or marketing SDK, and no third-party tracking library of any kind. We do not know how many times you opened an app, which screens you used, or how long you stayed.
- Nothing is sold or shared with data brokers. Not now, and not as a change of mind later — see If this policy changes.
- What you create stays on your device unless that app’s section says otherwise, and unless you export it, share it, or turn on a backup feature that writes to a folder you chose, as that app’s own section describes. A backup you turned on yourself, writing where you told it to, is still your own act; it isn’t the same as us moving your data somewhere.
What we ask the operating system for
Apps may ask for permissions — notifications, microphone, speech recognition, Siri, camera, photos, location. Each is asked for at the moment it is needed and can be refused; refusing it turns off that one feature and nothing else. What each app asks for, and why, is in its section.
Permissions are granted to the app on your device. A permission is not a transfer of data to us.
Children
These apps do not knowingly collect personal information from anyone, including children under 13, because they do not collect personal information from anyone. There is no account to create.
Your rights, and how to use them
Because your content stays on your device, the usual rights resolve on the device itself rather than through a request to us:
- See your data — it is in the app, and where an app offers an export, in the file that export writes.
- Take your data — use that app’s export, if it has one.
- Delete your data — delete the items, use that app’s reset if it has one, or delete the app. Deleting the app removes its container from your device.
If you are in a jurisdiction that grants you rights of access, correction, portability, erasure or objection (the GDPR, the UK GDPR, the CCPA/CPRA and others), those rights apply to personal data a controller holds about you. Through the apps, we hold none. For what we can hold — an email you sent us — see section 6. If you believe we hold something else, write to us and say what you think it is; we will answer.
If this policy changes
If an app gains an optional account, backup or sync feature, this page is updated with a new effective date before that feature ships, and the change is described plainly rather than folded into a blanket rewrite. The same goes for a new app: its section appears here before it is on the store.
2Pop Task (iPhone)
Swipe through your day, one task at a time. A day planner that keeps your tasks, notes, reminders, photos and voice recordings on your iPhone.
The short version
Pop Task has no account, no server of ours, and no analytics or advertising software. Everything you create is stored only on your iPhone. We cannot see it, and we do not try to.
What is stored, and where
Your tasks, notes, reminders, photos, voice recordings, calendar subscriptions and settings are written to Pop Task’s own data store on your iPhone. None of it is transmitted anywhere as part of normal use.
The four things that touch the network, and exactly when
Pop Task works fully offline. Four specific actions cause a network request:
| What you do | What is sent | Who receives it |
|---|---|---|
| Attach a place to a task or note, so the app can show its name | The coordinate | Apple, through its reverse-geocoding service |
| Look at a card showing a small map of an attached place | The coordinate of that place | Apple, through its map-snapshot service |
| Search for a place by name in the location picker | The text you typed | Apple, through its place search |
| Paste a link into a note or task, with link previews on | The address you pasted, to fetch its title and image | The website that link points to |
None of these goes to an UnBuild server, because there is not one. The first three are handled entirely inside Apple’s own frameworks, under Apple’s privacy policy.
Link previews can be switched off entirely in Settings, which also deletes anything already cached for them. While on, a preview is fetched only over a secure connection, only while the note or task is on screen; the cache is excluded from your backups and from anything you export, and a failed fetch is remembered for a day so it is not retried needlessly.
Voice notes are transcribed on your iPhone and nowhere else
Pop Task asks iOS for on-device speech recognition only. Where your iPhone has no on-device model for your language, it does not transcribe at all: the recording is saved and plays back with no transcript. No audio is sent anywhere, ever — not to Apple, not to us.
What Pop Task asks permission for
| Permission | What it is for | If you refuse |
|---|---|---|
| Notifications | Your daily briefing, reminders and break alerts | Those show inside the app when you open it, and nowhere else |
| Microphone | Recording a voice note | No voice notes; everything else is unaffected |
| Speech recognition | Turning a voice note into text, on the device | The recording is kept and played back without a transcript |
| Camera / Photos | Attaching a picture to a task or note | No photo attachments |
| Location | Attaching where you are to a task or note | You can still pick a place on the map by hand |
Location is used only when you attach a place. Pop Task does not track your location in the background, and it has no geofences or location-triggered reminders.
Your control
- Export writes everything — tasks, notes, history, photos and voice recordings — to a single file you choose the destination for, whenever you like. That file is not encrypted, so keep it somewhere you trust.
- Restore replaces what is on your phone with a previously exported archive.
- Start over deletes everything Pop Task keeps on this iPhone and returns it to first-run setup.
- Delete the app removes its container, and with it everything above.
What Pop Task does not have
No account, no sign-in, no UnBuild server, no analytics, no crash-reporting SDK that leaves the device, no advertising identifier, no third-party tracking library, and no sharing of your tasks or notes with anyone.
3Tiny Habits (iPhone)
Do one small thing. Then another. A deck of small activity cards — three to ten minutes each — dealt fresh every day and grown by what you actually finish, never by a streak.
The short version
Tiny Habits has no account, no server, and no analytics or advertising software. There is no networking code anywhere in the app — not a library, not a dependency, not a line that opens a connection. Everything you do is stored only on your iPhone.
What is stored, and where
Tiny Habits keeps two separate on-device stores, plus your photo.
- Your activity. Your daily deals, the cards you finish, undo or skip, your love votes, pauses and resumes, your chosen anchor cue and time, and your life-shape and optional name are written as an append-only event log to the app’s own on-device database, which has no iCloud or CloudKit configuration.
- Your preferences. Interface and pace choices — card scheme, appearance, the “mix up the kinds” toggle, card backdrop, when your day starts, whether you’ve seen the reminder offer and the intro — are kept separately in the app’s own settings store, along with an install identity that seeds your card deals so the same phone deals the same cards after a relaunch. That identity is not an account and is not a fact about you.
- A profile photo, if you add one, is stored as a plain file in the app’s own container, deliberately kept out of the event log.
Network requests: there are none
Tiny Habits does not merely work offline — it has no networking code to turn on, and no third-party dependency of any kind. It makes zero network requests, and sends nothing to anybody.
Nothing is transcribed or recognised
The app’s “coach” turns your own pace, read from your local event log, into plain-English lines using a fixed set of rules. It runs entirely on your iPhone: no machine-learning model, no server, no network call, and no free-text field to type into. Tiny Habits does not record audio and uses no speech, vision or other recognition framework.
What Tiny Habits asks permission for
| Permission | What it is for | If you refuse |
|---|---|---|
| Notifications | One daily reminder naming your first three cards, at the cue and time you set | No reminder; everything else is unaffected. It is never asked for during setup — only later, in context, and only once |
That is the only permission Tiny Habits asks for. Setting a profile photo uses Apple’s photo picker, which runs outside the app — the app receives only the image you pick, never access to your library. Tiny Habits asks for no camera, microphone, speech recognition or location access, and never asks where you are.
Your control
- Export writes your complete event history — every card dealt, done, skipped or loved, every pause, and the install identity — to a single file you choose where to send. Your profile photo is not included; it stays on the device.
- Import replaces what is on your phone with a previously exported file rather than merging it, and tells you so.
- Delete your data by deleting Tiny Habits. There is no in-app “erase everything” in this release; deleting the app removes its container, and with it everything above.
- “Sign out” in Settings explains that there is no account to sign out of, and that accounts and sync are not part of this release.
What Tiny Habits does not have
No account, no sign-in, no server — not ours, not anyone else’s — no analytics, no crash-reporting SDK, no advertising identifier, no third-party library of any kind, no iCloud or CloudKit sync, and no sharing of your cards, your pace or your photo with anyone.
4Pinora (Mac)
On your desk. And a real document. Pinora replaces sticky notes with floating windows that hold a real, structured note — checklists you can tick, photos, voice memos, locations and reminders — each one sitting on your desktop exactly where you left it.
The short version
Pinora has no account, no server of ours, and no analytics or advertising software. Everything you write, photograph, record or lock is stored only on this Mac. The only things that ever leave it are a map coordinate or search — sent to Apple, only when you attach, search for or look at a place — and, if you turn the feature on yourself, a backup file written into a folder you chose, which may be a folder a cloud service of yours syncs.
What is stored, and where
- Your notes — their text and every block in them (checklists, lists, code, photos, voice memos, locations, reminders, tags), each note’s window position, and your settings — are written to Pinora’s own database on this Mac, in ~/Library/Application Support/Pinora.
- Photos and voice memos are saved as separate files next to that database, referenced from the note rather than embedded in it.
- Locking a note seals its text, photos and voice memos with AES-256-GCM under a per-note key. That key is itself protected by this Mac’s Secure Enclave (for the Touch ID or Mac-password unlock) and by a password-derived recovery key (for opening the note on a different Mac). A locked note’s attachment filenames, its tags and the label you gave it stay unsealed, on purpose, so search and the tag sidebar still work.
- A per-Mac identity — a random installation ID and a signing keypair, generated once — is kept in this Mac’s Keychain, not in iCloud Keychain. It is inert groundwork for a possible future note-sharing feature; nothing in the app reads or sends it over the network. You can see it, reveal it or regenerate it in Settings → General → Identity.
- The keys that unlock a locked note are likewise kept only in this Mac’s Keychain.
- None of this touches iCloud or CloudKit. Pinora has no iCloud entitlement.
The network requests it makes, and exactly when
Pinora works fully offline for writing, locking and organising notes. Three specific actions cause a network request, all through Apple’s own frameworks — and they are the entire reason the app asks for network access at all:
| What you do | What is sent | Who receives it |
|---|---|---|
| Attach “where you are right now” to a note | Your coordinate, to look up its name | Apple, through its reverse-geocoding service |
| Search for a place by name in a location block | The text you typed | Apple, through its place search |
| Look at a note whose location block shows a map preview | The coordinate of that place | Apple, through its map-snapshot service |
None of these goes to an UnBuild server, because there is not one. All three are handled inside Apple’s own frameworks, under Apple’s privacy policy. Clicking a location block opens the Maps app to that coordinate — at that point you’ve left Pinora, and what Maps does is between you and Apple.
Voice memos are transcribed on your Mac and nowhere else
Pinora asks macOS for on-device speech recognition only, on every transcription request. Where your Mac has no on-device model for the memo’s language, it simply doesn’t transcribe: the recording is kept and plays back with no transcript. No audio, and no partial transcript, is ever sent anywhere — not to Apple, not to us. Reading a word aloud (the dictionary “speak” feature) also runs entirely on the Mac, using its own built-in voice.
What Pinora asks permission for
| Permission | What it is for | If you refuse |
|---|---|---|
| Microphone | Recording a voice memo | No voice memos; everything else is unaffected |
| Speech recognition | Turning a voice memo into text, on this Mac | The recording is kept and plays back with no transcript |
| Location (when in use) | Attaching “where you are right now” to a note | You can still search for a place by name and drop it on the note |
| Notifications | Alerting you when a reminder you set is due | The reminder stays on the note, but nothing alerts you when it’s due |
Pinora never asks for Camera, Photos Library or Accessibility access. Pictures are added by pasting from the clipboard, which needs no permission; the app’s global hotkeys are registered without Accessibility access, the one macOS permission that could watch everything you type.
Your control
- Export writes every note — including locked ones, which stay sealed inside the file — plus their photos and voice memos, to a single .pinora file you choose the destination for. A note you never locked is not encrypted in that file, so keep it somewhere you trust.
- Scheduled backups, if you turn them on, write that same kind of file automatically (hourly or daily, your choice) into a folder you pick — which can be a folder synced by iCloud Drive, OneDrive or Google Drive. Pinora writes a local file into that folder and nothing more, so the file leaves this Mac exactly as far as the sync service you already use takes it. Once on, this runs on a timer while Pinora is open, not only when you press a button.
- Restore replaces everything on this Mac from a chosen .pinora file, or merges it in and lets the newer version of each note win.
- Delete a note from its own toolbar, any time — it, its reminders, and any photos or recordings only it used are removed immediately. There is no separate “erase everything”; deleting every note, or deleting the app, are the two ways to clear most of it.
- Delete the app removes its container — the notes and every photo and recording — but not Pinora’s Keychain items, because macOS does not remove those with the app. What stays behind is the locked-note recovery keys, a reference to the Touch ID key, and the per-Mac identity, under the Keychain names com.unbuild.pinora.mac.notelock, com.unbuild.pinora.mac.identity and com.unbuild.pinora.mac.identity.vault. None of these opens a locked note by itself, but if you gave a locked note a password hint, that hint is stored unencrypted in the same item and survives the uninstall. To remove them fully, delete these three items yourself in Keychain Access.
- Hide every note from screen sharing with one click from the menu bar, so presenting your screen doesn’t show a note’s contents on the call. This is a display control; nothing is sent or stored differently because of it.
What Pinora does not have
No account, no sign-in, no UnBuild server, no analytics, no crash-reporting SDK that leaves the device, no advertising identifier, no third-party tracking library, no iCloud or CloudKit sync of your notes, and no sharing of your notes with anyone. The per-Mac identity described above is dormant groundwork for a feature that does not exist yet.
5Car Note (iPhone)
Say it. It’s written. An iPhone app that records, transcribes and files a spoken note by voice command, hands-free, while you drive.
The short version
Car Note has no account, no server of ours, and no analytics, crash-reporting or advertising software. Your voice and your words are transcribed on your iPhone and stay there. We cannot see them, and we do not try to.
What is stored, and where
Your notes — the audio recording, its transcript, title, time, duration, place, and any reminder you’ve armed for it — along with your saved places, your phrase list and your settings, are written to Car Note’s own database and an audio folder, both inside Car Note’s own container on your iPhone. A few bookkeeping values (when you last recorded, which transcription languages you’ve used recently) live in the same on-device settings store as your preferences — never your note content, and never your transcript. None of it is transmitted anywhere as part of normal use.
The three things that touch the network, and exactly when
Car Note works fully offline. Three specific things cause a network request:
| What happens | What is sent | Who receives it |
|---|---|---|
| Location is on, and a note is recorded, a saved place is pinned, or you use the “Near me” filter | The coordinate | Apple, through its reverse-geocoding service, to turn it into a neighbourhood name |
| You open the Map tab | The area shown, to load its map tiles (Apple’s points of interest are switched off, so only your own notes appear) | Apple, through its maps service |
| You record in a language for the first time on iOS 26, and no on-device model for it is installed yet | Nothing of yours — a one-time download of Apple’s speech model for that language | Apple |
None of these goes to an UnBuild server, because there is not one. All three are handled entirely inside Apple’s own frameworks, under Apple’s privacy policy. Turning location off in Settings stops the first entirely; the other two only happen when you open that part of the app.
Voice notes are transcribed on your iPhone and nowhere else
Car Note requires on-device speech recognition — this is set in the app, not left to a system default. Where your iPhone has no on-device model for your language, Car Note refuses to transcribe rather than quietly falling back to a server: the recording is saved and plays back with no transcript. No audio is sent anywhere, ever — not to Apple, not to us.
Reminders are suggested from a phrase list, not a model
When your words match one of Car Note’s phrases (“call the supplier,” “book it tonight”), it offers you a reminder; nothing is scheduled until you tap to arm it. This runs entirely on your iPhone, against a fixed, editable phrase list and a date detector — there is no machine-learning model, and nothing about it is sent anywhere. If you send a reminder to your calendar instead, Car Note hands the details to Apple’s own Calendar editor, which runs outside the app; Car Note never asks for, or gets, access to your calendar.
What Car Note asks permission for
| Permission | What it is for | If you refuse |
|---|---|---|
| Microphone | Recording your voice note | Car Note cannot record |
| Speech recognition | Transcribing your note, on the device | The recording is kept and played back with no transcript |
| Siri | Starting, pausing, resuming and stopping a recording hands-free, by voice | You can still use the app’s on-screen controls |
| Location (“While Using”) | Naming the place a note was recorded, and the “Near me” filter | Notes save with no place name, and “Near me” has nothing to filter by |
| Notifications | Showing a reminder you’ve armed | The reminder is not shown; nothing else is affected |
Car Note only ever asks for location “While Using the App” — never “Always” — and takes a single fix at a time. It does not track your location in the background, and any place can be removed from a note with a tap.
Your control
- Export all notes, in Settings, writes every note — transcript as Markdown text, audio as a file, and a manifest with each note’s time, duration, place and exact coordinates — into a zip file you choose where to send or save. That file is not encrypted, so keep it somewhere you trust.
- Delete a note moves it to Recently Deleted, where it is kept for 30 days, with its audio, and then removed automatically; you can also empty Recently Deleted immediately.
- Sharing a single note sends only its title and transcript as text to wherever you choose (Mail, Messages, Calendar, or the share sheet) — never the recording.
- Delete the app removes its container, and with it everything above. Car Note has no sync or backup of its own — your notes live on exactly one phone — but they are included in your iPhone’s own device backups.
What Car Note does not have
No account, no sign-in, no UnBuild server, no analytics, no crash-reporting SDK, no advertising identifier, no third-party tracking library, no machine-learning model, no iCloud sync or backup of its own, and no sharing of your notes with anyone unless you choose to send them yourself.
6This website, email and purchases
What this website stores
This site sets no analytics cookies and runs no third-party trackers. Two things are written to your browser’s local storage, both your own choices: the appearance you picked, and the accent colour you picked. Clearing site data removes them.
The site is served as static files by Google’s Firebase Hosting. Like any web host, it may briefly log your IP address and browser details as part of serving pages and keeping the service from being abused, under Google’s privacy policy. We do not use those logs to identify or profile visitors.
If you write to hi@unbuild.me, we keep your message so we can answer it, and for as long as the thread is useful. You are not added to a mailing list; there is nothing to unsubscribe from. If you asked to be told when an app or Commotion is ready, your address is kept for exactly that and deleted once the message has been sent. For anything we hold of this kind, write to us and we will confirm, send or delete it.
Purchases and App Store figures
Purchases are handled entirely by Apple. We never see your card, your address or your Apple Account; what reaches us is a sales report with units and totals by territory. Apple also reports aggregate download and crash figures to us through App Store Connect. We cannot identify you from them, and we receive no contact details with them.