Skip to main content
Deletable

Privacy Policy

Last updated: July 12, 2026

The short version

Your vault content — notes, photos, everything you store — never leaves your device. It is encrypted with AES-256 and the key is sealed in the iOS Keychain or Android Keystore. We collect only anonymous, aggregated usage statistics tied to a random ID that we cannot trace back to you.

1. Who we are

Deletable is developed and published by DR Tech Ventures LLC. References to "we," "us," or "our" in this policy refer to DR Tech Ventures LLC.

2. What data stays on your device

The following data is stored exclusively on your device and is never transmitted to our servers or any third party:

  • All vault content: notes, photos, and any text you type
  • Your encryption master key (stored in the iOS Keychain on iOS, or the Android Keystore on Android)
  • Your categories, settings, and preferences
  • Location data associated with notes
  • Biometric authentication configuration

Your locations themselves never leave your device. We do sync an anonymous count of how many deletions were triggered by location rules — a number only, never coordinates, addresses, or geofences (see Section 3).

3. What anonymous data we collect

When the app is initialized and when vault activity occurs, Deletable syncs general anonymized usage statistics to our Supabase backend. This data is linked to a randomly generated UUID created at first launch — it has no connection to your Apple ID, Google account, name, email, or device serial number. It consists only of counts, flags, and timestamps — never your notes, photos, or any content you store. The categories are:

  • Device information — platform, device model, OS version, app version, and language
  • Usage counters — items created and deleted, storage freed, app opens, days active, and how often features like folders, manual deletion, and location rules are used
  • Current vault totals — how many items your vault holds right now
  • App state — current achievement tier, notification permission status, whether onboarding is complete or a widget is active, and related timestamps

We use this data solely to understand aggregate app usage and power the in-app statistics features.

4. Third-party services

We use Supabase to store the anonymous statistics described above. Supabase is a US-based service. No other third-party analytics, advertising, or tracking SDKs are included in the app.

5. Permissions we request

Camera
To capture photos you choose to store in the vault.
Photo Library
To import photos from your library into the vault.
Location (In-Use & Background)
To attach geofence reminders to notes. Only used when you explicitly enable Location Context in Settings.
Face ID / Touch ID / Fingerprint
To lock the app and require biometric authentication on open — Face ID or Touch ID on iOS, fingerprint on Android.
Notifications
To send optional expiry reminder alerts before items are deleted.
Background App Refresh
To purge expired items even when the app is not open.

6. Data retention

Anonymous statistics in Supabase are retained indefinitely to power aggregate statistics features. Deleting the app removes all local data. Your Supabase record (containing only anonymous statistics) will persist but cannot be linked to you by us. Contact us if you would like it removed and can provide your random device UUID (visible in the app under Settings → About).

7. Our website

This website collects a small amount of data of its own, separate from the app:

  • Contact form — if you contact us, we collect the name, email address, subject, and message you submit. Submissions are stored in Supabase and emailed to us via Resend, and are used only to respond to your inquiry.
  • Analytics & performance — we use Vercel Analytics and Speed Insights to measure aggregate page views and site performance. They do not use cookies and do not identify individual visitors.
  • Error monitoring — we use Sentry to capture site errors so we can fix them.
  • Rate limiting — contact form submissions are rate-limited by IP address to prevent abuse; IPs are held only transiently for this purpose.

8. Your rights (EU & California)

If you are in the European Economic Area, the United Kingdom, or California, you have rights over your personal data — including the right to know what we collect, to access it, to correct it, to delete it, to receive a copy of it, and to object to or restrict certain processing. California residents also have the right not to be discriminated against for exercising these rights.

In practice, the only personal data we hold is what you submit through the website contact form — the app statistics described in Section 3 are anonymous and cannot be linked to you by us. We do not sell or share your personal information as defined by the CCPA/CPRA. Where the GDPR applies, we process contact form data to respond to your inquiry (legitimate interest) and anonymous usage statistics to improve the app (legitimate interest).

To exercise any of these rights, reach out via the contact page and we will respond within the timeframe required by law. You also have the right to lodge a complaint with your local data protection authority.

9. Children

Deletable is not directed at children under 13. We do not knowingly collect any information from children under 13.

10. Changes to this policy

We may update this policy as the app evolves. The current version is always available at this URL. Continued use of the app after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this privacy policy? Reach out via the App Store / Google Play listing or the Help page.