Privacy Policy

Updated 29 September 2026

The short version

None of our apps shows ads, tracks you or includes analytics, and none asks you to make an account with us. What you put in them stays on your devices, or in your own iCloud for the apps that sync. Where an app does send something elsewhere, its part below says exactly what, where and why.

Every app

What's true of all of them

Our apps are made by Mann Badal ("we", "us"), who publishes them on the App Store. This policy covers each of them, and this website.

  • No advertising, and no advertising identifiers.
  • No tracking you across other companies' apps and websites.
  • No analytics, telemetry or third-party tracking code.
  • No account with us: you never sign up or sign in.
  • We don't sell your data, or share it with anyone for marketing.
  • Purchases and subscriptions are handled by Apple through the App Store. We never see your payment details; an app learns only what you're entitled to.
  • An app asks for a permission, such as the camera or notifications, only for a feature that needs it, and you can change your mind in your device's Settings at any time.

Apple's services that our apps use on your behalf, such as iCloud, the App Store, notifications and Siri, are covered by Apple's Privacy Policy. Your device's own backups, to iCloud or a computer, may include an app's data, as they do for any app.

Each app's part below says what it keeps and where, and anything it sends elsewhere.

Last Stop

Updated 28 September 2026

Last Stop collects no personal information. It has no accounts, no ads, no analytics and no tracking, and it never connects to the internet.

Your progress and settings are kept only on your device, in the game's own storage, and are never sent to us or to anyone else. Deleting the game deletes them. Your device's own backups (iCloud or a computer) may keep a copy, as they do for any app.

This is the same on iPhone, iPad and Apple TV, and for every player, children included.

On iPhone and iPad, the support link in the game's settings opens this site in your browser, where this website's part applies. Apple TV has no browser, so there the game shows this site's address instead.

If this policy ever changes, the new version will be posted here and shown in the game's settings, with a new date.

Managerr

Updated 28 September 2026

Managerr is an independent app that connects directly to the services you set up. It has no server of its own, no account, and no advertising, tracking code or analytics, so nothing about you or your servers comes to us.

On your device

Server names, addresses, preferences and calendar reminder choices are stored on the device. API keys and custom header values are kept in device-only Keychain entries that don't sync. Saved snapshots of your servers, with their media, request and playback information, let you browse offline.

Artwork is cached briefly in memory. Turn on Image Cache to keep smaller copies on the device, up to 500 MB. Cached images are left out of backups, and are removed when you remove their service or turn Image Cache off. Widget summaries are shared on the device with Managerr's widget extension.

Managerr doesn't offer iCloud sync. Your device's backups may include its configuration and preferences, but not its secrets, depending on your backup settings; cached snapshots are left out. Device-only Keychain entries don't move to another device, so each device is set up on its own. API keys and custom headers leave the device only in a backup you make yourself, encrypted with a passphrase the app doesn't keep.

Requests to your services

When you connect, refresh or act, Managerr sends the request straight to the server you set up. That server, and any reverse proxy or VPN between you, may receive and log your IP address, your API authentication, the paths requested and the details of the action. Their privacy practices are separate from ours.

Managerr supports HTTP for your own servers, which doesn't encrypt credentials or data, and uses the device's normal certificate checks for HTTPS. It refuses authenticated redirects to a different scheme, host or port, and allows redirects within the same origin. Your service keys and custom headers are never sent to outside artwork hosts.

Artwork and discovery

Posters may load from your servers, or from HTTPS artwork providers those services name, including The Movie Database's image service for Seerr. Those providers receive your IP address and the image request. Seerr discovery and search go to your Seerr server, which may use its own metadata providers. Indexer searches go to your Prowlarr server, which queries the indexers you've set up there; Managerr doesn't contact those indexers itself.

Notifications, widgets and Shortcuts

Release reminders are optional and scheduled on the device with Apple's notification framework, from the dates the app last fetched. Optional alerts (a grab, a finished download or upgrade, something new in Plex, a stream, a new request, a health warning) are posted by the app itself after a background check that goes straight from your device to your own services. An alert about a title carries its poster, fetched in the same check from your service or the artwork provider it names, and iOS keeps that poster with the notification until the notification is cleared.

Widgets read a local snapshot and never use your credentials to contact servers. Shortcuts open places or searches in the app. Your use of Siri and other system features is also covered by Apple's privacy practices.

Demo mode

The demo uses fictional media and separate in-memory services. It needs no credentials, makes no network requests, schedules no real reminders and labels its widget summaries as demo content. Leaving the demo brings back your saved services.

Your choices

Remove a service in Settings to remove its credentials, cached snapshots, reminders and widget entries from that device. You can turn reminders off in the app, and notifications off in your device's Settings. Because nothing about you is collected, sent to us or stored away from your devices, there's nothing for us to access, correct or delete.

My List

Updated 28 September 2026

My List has no server of its own. There's no account to create, no analytics, no advertising and no third-party code in the app. Your lists are stored on your devices and, if you're signed in to iCloud, in your own private iCloud storage. We can't read them.

What the app stores

Only what you put into it:

  • The names of your lists.
  • The text of each item, and whether it's ticked off.
  • The order you arranged your items in.
  • Any picture you attach to an item.
  • The colour you choose for a list, if you choose one.
  • A list's reminder schedule, if you set one: its date, time, repeat setting and weekdays.
  • Each list's suggestion history: the item text, how often it was used, and when it was last used or removed.
  • Your app theme and appearance setting, kept on the device and mirrored to its widgets and your paired Apple Watch.
  • Which reminders you've silenced, kept only on that device.

The app doesn't collect your name, email address, contacts, location, device identifiers or usage statistics.

Where it's stored

Your data is written to a database on your device. When you're signed in to iCloud, it also syncs to the private CloudKit database of your Apple Account, in the container iCloud.app.mylist.ios. That storage is operated by Apple and governed by Apple's Privacy Policy, and it counts against your iCloud storage, not against any service of ours. If you're not signed in to iCloud, the app works normally and keeps everything on the device.

To be precise about what this means: data in your private CloudKit database is encrypted in transit and at rest, and we have no access to it. It isn't described here as end-to-end encrypted, because whether CloudKit data is end-to-end encrypted depends on your Apple Account settings, such as Advanced Data Protection.

Shared lists

When you share a list, iOS creates an iCloud share and sends the invitation through the standard share sheet. From then on:

  • The people you invite can see that list's name, colour, items, ticked state, order, reminder schedule, reusable item history and any attached pictures.
  • If you gave them can edit access, they can also change the list's colour, and change, add or remove items.
  • If you gave them view only access, they can see the list but not change it.
  • Apple shows the people in a share the name associated with each one's Apple Account, as it does for any iCloud share.

Only the lists you share are visible to anyone else; your other lists stay private. You can change someone's access, or stop sharing, at any time from the share sheet in the app.

Photos and camera

When you choose an existing picture, Apple's photo picker gives the app only the image you select, not access to your photo library. When you tap Take Photo, My List asks iOS for camera access, and uses the camera only while the camera screen is open. It doesn't record video or use the camera in the background. You can also paste a picture straight into the item field.

Pictures you attach are resized and stored with the item they belong to. They aren't uploaded anywhere except your own iCloud storage, and to the people in a list you've shared.

What the app doesn't do

  • No analytics, telemetry or usage tracking.
  • No advertising, and no advertising identifiers.
  • No third-party SDKs, crash reporters or trackers.
  • No accounts, passwords or sign-up.
  • No selling or sharing of data: there's none to sell.
  • No network connections other than Apple's iCloud services on your behalf.

Deleting your data

Deleting a list in the app removes it and its items from your device and your iCloud storage, and from the devices of anyone you shared it with. Deleting the app removes the copy on that device; to remove the iCloud copy as well, delete your lists in the app first, or manage the app's iCloud data in Settings → your name → iCloud on your device.

If this part changes, its date is updated, and material changes are also described in the app's release notes.

Proofy

Updated 28 September 2026

Proofy is a vault for receipts, invoices, warranties and related documents, and it's local-first: saved proofs and their documents stay available on your device. With Proofy Pro and iCloud sync turned on, Proofy also keeps a copy in your private iCloud database, so it can sync across your Apple devices and support recovery. Proofy shows no ads, doesn't track you across apps or websites, and doesn't need a Proofy account.

Information you add

You may add proof details such as store names, item names, prices, purchase dates, warranty dates, notes, text read from your documents, model numbers, serial numbers, and attached images or PDFs. Proofy uses them to create, search, show, edit, export and share your vault.

Camera, photos and files

Proofy asks for camera access to scan receipts, invoices and warranty documents, and for photo library access when you choose to import images. You can also choose files from inside Proofy. Imported documents are copied into Proofy's storage on your device, so they stay available in your vault.

iCloud sync and recovery

iCloud sync and 30-day recovery of deleted proofs come with Proofy Pro. When they're on, proof details and eligible attached documents are stored in the private CloudKit database of your Apple Account. They count toward your iCloud storage, and Apple handles them under your iCloud terms and settings.

Proofy never receives your Apple Account credentials, and doesn't need an account of its own. If you turn sync off in Settings, the copies already on your device and in iCloud stay where they are. If your paid access ends, Proofy pauses uploads and ongoing sync, and still lets you recover an existing iCloud vault.

Deleted proofs stay in Recently Deleted for 30 days. After that, Proofy removes their documents, and keeps a compact record of the deletion for up to 90 more days, so an older device that was offline can't bring the deleted proof back.

New attachments are limited to 49 MB, to stay within CloudKit's limit. Larger documents you already have stay on the device, and Proofy marks them as not eligible for iCloud sync.

AI extraction

Everyone can use 10 free AI reads online, and Proofy Pro subscribers can keep using AI extraction. When you use it, Proofy sends the proof document you chose, and the text read from it, to Proofy's extraction service over HTTPS (proofy-worker.mannbadal.com). This may include the image or PDF, images of its pages, its text, the file type, the currency you expect, and your locale and time zone. The service passes what's needed to the AI extraction provider it's set up with, such as OpenCode or OpenAI, to produce draft suggestions like the store, date, total, item names and title. They're only suggestions: you review and edit the draft before saving it in your vault.

Proofy uses an anonymous install identifier to count free AI reads. For Proofy Pro requests, Proofy may send signed App Store transaction information to confirm that an active subscription unlocks the feature. The service stores its usage and rate-limit counts under hashed identifiers. It's designed to answer each request and move on, and it doesn't intentionally store the documents it receives. Cloudflare, which hosts the service, and the AI provider may process and briefly keep request information or content under their own terms, as needed to run the service, keep it secure, prevent abuse, keep it reliable and meet legal obligations.

Proofy doesn't use proof documents, their text, AI extraction content, install identifiers or subscription information for advertising, marketing, data brokerage or tracking across apps.

Purchases

Proofy Pro is handled by Apple through the App Store. Proofy receives the status of your purchase from Apple so that the app and Proofy's service can unlock what you've bought and apply service limits. Proofy never receives your payment card details.

Store logos

When Store logos is on and Proofy needs to find a merchant's website, including when you choose an automatic logo for a store without one, Logo.dev receives the store's name as a search. When Proofy loads the automatic logo, Logo.dev receives the merchant's domain, your IP address and the time of the request, to deliver the image, measure usage, protect its service and keep it reliable. Logo.dev handles this under its privacy policy.

Proofy saves the merchant domain it found, so it can reuse the same logo without searching again. Automatic logo images aren't stored in Proofy's service. You can turn Store logos off, correct a store's website, choose your own logo (kept with your vault), or use Proofy's store icon.

Logos provided by Logo.dev. Store logos are trademarks of their owners, used only to identify the store; showing one doesn't mean the merchant sponsors or endorses Proofy.

System search and Shortcuts

If Spotlight and Siri visibility is on, Proofy indexes proof and store details on your device, so you can find saved proofs through Apple's system search and app shortcuts. You can turn this off in Proofy's settings.

Exporting and deleting data

You can export your active proofs' details and their documents from Proofy. Deleting a proof moves it to Recently Deleted for 30 days, where you can restore it or delete it for good. Deleting it for good removes the proof and its documents from the device and, when sync is on, from iCloud.

Deleting the Proofy app removes its data from that device. A synced iCloud vault may remain available to restore, unless you've permanently deleted its contents.

TextGrab

Updated 28 September 2026

TextGrab turns what you select into text without turning your screen into anyone else's data. We don't collect, receive, sell, share or transmit personal data, usage data, diagnostics, identifiers or captured content from TextGrab. It has no account system, advertising or analytics code, online AI provider or developer-operated server, and no network access of its own.

What it reads, and when

TextGrab reads content only when you ask it to: when you capture a region of the screen, choose image or PDF files, recognise an image or PDF on the clipboard, or take a photo with a nearby iPhone or iPad through Continuity Camera.

Screen regions, imported images, PDF pages, clipboard images and PDFs, and Continuity Camera photos are processed in memory with Apple Vision. TextGrab doesn't keep those images or pages after recognising them.

Local history

After a successful capture, TextGrab can keep the recognised or edited text, with a few details about it, in its own storage on your Mac: when it was captured, its source, the language detected, the recognition confidence, the barcode type, whether it's pinned, and translations you ask for.

Screenshots, imported files, clipboard images and PDFs, and Continuity Camera photos are never copied into history. You can search, edit, pin, delete or clear your history at any time. You can also save a single capture as a text file, or export all of your history as a CSV file, to a place you choose with the standard macOS Save dialog.

Additive Clipboard

When you turn on Additive Clipboard, TextGrab keeps the combined captured text in its preferences on your Mac, so the collection is still there after you quit. Turning Additive Clipboard off stops adding to it but doesn't delete it; remove it with Clear Additive Clipboard or Clear History.

Translation and speech

Translation and speech use macOS itself, which may download a language or voice through Apple when you first ask for one. Your captured text is processed on your Mac, and isn't sent to any service of ours.

Your choices

Because we never receive your captures or personal data, there's no profile, account or record of yours on a server for us to access, correct or delete. You control the text TextGrab keeps on your Mac through its history, export and clipboard controls.

If TextGrab's data practices change, this part and its App Store privacy details will be updated before the change takes effect.

This website and the support form

Updated 29 September 2026

This site has no cookies, analytics, ads, or third-party scripts or fonts, and it looks the same for everyone, apart from the appearance you choose. Links in our apps open it in your browser, where this part applies. Our host, Cloudflare, handles technical information such as your IP address to deliver the pages and protect them from abuse; we don't keep logs of visits.

The site follows your device's light or dark setting. If you choose Light or Dark at the foot of a page, your browser keeps that one word on your device (in its local storage, not a cookie) so the next page matches. It's never sent to us, and choosing System clears it.

When you contact us

The form emails what you write to our support inbox so we can reply: which app it's about, your email address, your name if you give it, and your message. It isn't stored on this site, added to a mailing list, or used for anything but answering you. Our hosting and email providers (Cloudflare, and Apple's iCloud Mail) handle it only to deliver it.

We keep emails only as long as we need them to help you, and we'll delete yours if you ask.

Changes and questions

If this policy changes, the new version will be posted here with a new date, on the page as a whole and on each part that changed.

Questions about privacy? Send us a message from the support page, and choose the app.