Privacy Policy
The short version: ioths is offline-first. Your notes stay on your device. We never read them, sell them, or use them to train any model. Link previews are on by default and can be turned off.
Who we are
ioths is an iOS note-taking app built and operated by an independent developer. References to "we", "us", or "our" in this policy mean the developer of ioths.
Your notes
Notes are stored as plain Markdown files on your device. They never leave your device unless you explicitly activate one of the optional vault modes described below.
We have no server that receives, stores, or processes note content. We have no ability to read your notes.
Optional sync — your choice, your data
ioths supports two opt-in storage destinations beyond your device. Neither is enabled by default.
- An external folder you choose. You can point ioths at a folder selected through the iOS Files picker — an iCloud Drive folder, an Obsidian vault folder, or a folder belonging to another Files provider you use. Your notes and attachments are then written directly into that folder and handled by that provider under your own account, terms, and privacy policy. We have no access to it.
- GitHub sync. If you connect a GitHub repository, ioths sends and receives supported vault files directly between your device and one dedicated repository path under your GitHub account. This can include note content, filenames, YAML frontmatter, attachments, Archive files, Trash files, and the ioths Library marker. Authorization uses the GitHub App guided flow or, as an advanced fallback, a personal access token. Credentials are stored in the iOS Keychain on your device. We never receive the credential, repository details, or synced content.
Anyone with access to the selected GitHub repository can read the files stored there. If the repository is public, the synced files are public. Stopping GitHub sync in ioths stops network access and removes the saved connection and credential from the device while keeping local notes. GitHub authorization remains active until you revoke it through GitHub.
Diagnostics and analytics
ioths collects anonymous usage signals via TelemetryDeck, a privacy-first analytics platform. Signals are hashed on your device before transmission — TelemetryDeck cannot identify individual users, and neither can we.
We collect signals for:
- Note creation — type only (plain, task, camera, or voice), never the content
- Note archiving and moving to trash
- Search being used — a count, not the query text
- Editor mode toggled between natural and markdown view
- Appearance setting changed
- Feature tour opened from Settings
- GitHub authorization started, completed, or failed — only a coarse result category, never an account, repository, path, code, or credential
No signal ever includes note content, note titles, tags, or any data derived from what you write. TelemetryDeck's own privacy policy is at telemetrydeck.com/privacy.
Analytics are optional. You can turn them off completely in the app under Settings → Privacy → Share anonymous analytics. When off, no signals are sent — not even the session signal — until you turn it back on.
No ioths account required
ioths requires no developer-operated account or sign-in. Optional providers may require their own account and authorization: GitHub sync requires a GitHub account, and Files providers may require an account with that provider. We do not receive your provider credentials.
Link previews
ioths can show rich previews for notes that contain web links on the notes list. This feature is on by default and can be turned off under Settings → Privacy → Load link previews.
While enabled, ioths contacts the website named by a link in your note to fetch public page metadata such as title, description, site name, and site icon. The request goes directly from your device to that website. The website may receive the URL, your IP address, and ordinary web request metadata.
ioths does not send surrounding note content, note titles, tags, filenames, photos, recordings, or search queries. Fetched link metadata and site icons are cached locally on your device. Full preview images are not fetched.
Third-party services
ioths uses the following third-party services:
- TelemetryDeck — anonymous usage analytics as described above. Governed by TelemetryDeck's Privacy Policy.
- Your chosen Files provider (if you select an external folder) — for an iCloud Drive folder this is Apple, governed by Apple's Privacy Policy. If you choose a folder belonging to a different provider, that provider's own privacy policy governs the files you place there.
- GitHub (if you enable GitHub sync) — governed by GitHub's Privacy Statement.
Unless you turn off link previews, websites linked from notes receive ordinary web requests for the linked URLs. No other third-party service receives your data.
Data retention and deletion
Because we do not collect personal data or note content, there is nothing for us to delete on your behalf.
Deleting the app removes the note data stored locally on your device. It does not delete copies already written to an external Files-provider folder or to a GitHub repository — those copies stay with the provider under your own account. Delete them there if you want them gone.
Children
ioths is not directed at children under 13. We do not knowingly collect personal information from children beyond the optional analytics and contact processing described in this policy.
Changes to this policy
If we make material changes, we will update the effective date at the top of this page and, where appropriate, note the change in the app's release notes. Continued use of the app after a change constitutes acceptance of the updated policy.
Contact form data
If you use the contact form, we collect the message you write and your email address if you choose to provide one. This data is stored as a private GitHub issue in our source repository, accessible only to the developer. It is used solely to respond to your enquiry and is deleted when the issue is resolved.
Legal basis: legitimate interest (responding to your enquiry). Data processors: Cloudflare (transit only, nothing persisted) and GitHub/Microsoft (issue storage). You may request deletion at any time by contacting us via the form itself.
The contact form is protected against bots by Cloudflare Turnstile (invisible mode). Turnstile may collect limited telemetry to assess whether a visitor is human. This is governed by the Cloudflare Turnstile Privacy Addendum. No data collected by Turnstile is used for advertising or sold to third parties.
Trademarks
ioths names services such as Apple, iCloud, Obsidian, GitHub, TelemetryDeck, and Cloudflare only to identify optional integrations and the processors described above. Those names and logos are trademarks of their respective owners. ioths is independent and is not endorsed by, sponsored by, or affiliated with any of them.
Contact
For privacy requests, feedback, or any other enquiry, use the contact form.