Privacy Policy
Last updated September 3, 2026 · Applies to espyeon.com and all Espyeon applications
The short version: this website sets no cookies and runs no analytics or trackers, our applications collect only what they need to work, and we never sell or share your personal information. The detail below explains exactly what that means and what rights you have.
1. Scope and who we are
This Privacy Policy explains how Espyeon LLC (“Espyeon”, “we”, “us”) collects, uses, shares and protects personal information when you visit espyeon.com (the “Site”) or use any application we publish (each, an “App”, and together with the Site, the “Services”).
For the purposes of the EU and UK General Data Protection Regulation, Espyeon LLC is the data controller for the personal information described here. You can reach us at Contact@espyeon.com.
Individual Apps may collect different information. Where they do, the App publishes its own privacy disclosure — including its App Store privacy label and its Google Play Data safety section — and that disclosure applies in addition to this policy. In case of conflict, the App-specific disclosure governs for that App.
2. Our approach in one paragraph
We collect as little as we can get away with while still running working software. We do not sell or share your personal information for money or for cross-context behavioural advertising. We do not embed third-party advertising networks or cross-app tracking identifiers in our Apps. We do not build advertising profiles about you. Where a feature can run on your device instead of on our servers, we build it that way.
3. Information collected through this website
This website does not use cookies, analytics, advertising pixels, session replay, fingerprinting, or any third-party tracking technology. There are no accounts, no forms and no logins on the Site. We do not ask you for personal information here, and we do not store any in a database.
Like effectively every website on the internet, the Site is delivered by a hosting provider whose servers automatically record technical request data in order to serve pages, protect against abuse and diagnose faults. That data typically includes:
- the IP address the request came from;
- the date and time of the request and the page or asset requested;
- the referring URL, where your browser sends one; and
- your browser user-agent string and approximate region.
These logs are generated and retained by our hosting provider under its own policies, are used only for delivery, security and troubleshooting, and are not used by us to identify you or to build a profile. If you email us using an address on this Site, we receive your email address and whatever you choose to put in the message, and we keep that correspondence for as long as we need it to handle your request and to keep a record of it.
4. Information collected through our applications
What an App collects depends on what it does. Across all of our Apps we commit to the following, and each App’s store listing states the specifics:
- Content you create — notes, entries, settings and similar data stay on your device by default. Where an App offers sync, it is optional, it is described in the App, and it is transmitted over encrypted connections.
- Account information — where an App offers accounts, we collect only what authentication requires, typically an email address and a cryptographically hashed password or a platform sign-in identifier. We never store passwords in plain text.
- Diagnostics — where an App reports crashes, reports are aggregated and technical (device model, OS version, stack trace) and are used solely to fix defects. Where the platform offers it, this is opt-in.
- Purchases — handled entirely by Apple or Google. We receive a confirmation that an entitlement exists. We never receive your payment card number.
We do not collect contacts, precise location, photos, health data, biometrics, browsing history in other apps, or the advertising identifier, unless a specific App feature requires it, that App discloses it prominently, and you grant the permission. Permissions you grant can be withdrawn at any time in your device settings, and the App will keep working with the corresponding feature disabled.
5. How we use personal information
We use personal information only for these purposes:
- to provide, operate and maintain the Services and the features you use;
- to authenticate you and keep your account secure;
- to respond to your support requests and other correspondence;
- to detect, investigate and prevent fraud, abuse, security incidents and technical faults;
- to fix defects and improve reliability, using aggregated or de-identified information wherever that is sufficient; and
- to comply with legal obligations and to establish, exercise or defend legal claims.
We do not use your personal information to train machine-learning models, to profile you for advertising, or for automated decision-making that produces legal or similarly significant effects.
Legal bases (EEA/UK). Where GDPR applies, we rely on: performance of a contract to deliver the Services you asked for; legitimate interests to secure our systems, prevent abuse and improve reliability, balanced against your rights; consent for anything optional, such as opt-in diagnostics, which you may withdraw at any time; and legal obligation where the law requires us to retain or disclose information.
7. Retention
We keep personal information only as long as we need it for the purpose it was collected for. Account data is retained while your account is active. When an account is deleted it is removed from our live production systems within thirty (30) days, and ages out of our encrypted rolling backups within thirty (30) days of that. Support correspondence is generally retained for up to twenty-four (24) months. Diagnostic data is retained in aggregated form for up to twelve (12) months. Encrypted backups roll off on a defined cycle of no more than thirty (30) days after deletion. Where the law requires longer retention — for tax or accounting records, for example — we keep only what the law requires, for only as long as it requires it.
8. Security
We protect personal information using encryption in transit (HTTPS/TLS) and at rest, least-privilege access controls, multi-factor authentication on administrative systems, dependency and vulnerability monitoring, and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant regulators as required by applicable law and without undue delay.
9. Children’s privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under the age of digital consent in your jurisdiction, where higher). Any App we publish that is directed to children will comply with the Children’s Online Privacy Protection Act, Apple’s Kids Category requirements and Google Play’s Families policy, and will say so clearly on its listing. If you believe a child has provided us with personal information, contact Contact@espyeon.com and we will delete it promptly.
10. International data transfers
We are based in the United States and our service providers may process data in the United States and other countries whose data protection laws differ from those in your country. Where we transfer personal information out of the EEA, the UK or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum, together with supplementary technical measures such as encryption. You may request a copy of the relevant safeguards from Contact@espyeon.com.
11. Your privacy rights
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access and portability — to know what we hold about you and receive a copy in a portable format;
- Correction — to have inaccurate information corrected;
- Deletion — to have your information erased;
- Restriction and objection — to limit or object to certain processing, including processing based on legitimate interests;
- Withdrawal of consent — at any time, without affecting processing already carried out;
- Opt out of sale, sharing or targeted advertising — which for us is automatic, because we do none of those things; and
- Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights.
How to exercise them. Email Contact@espyeon.com from the address associated with your account, or use the in-App controls where available. We will verify your request, respond within the period required by applicable law — generally 30 days under GDPR and 45 days under California law, extendable where the law allows — and we will not charge you for a reasonable request. An authorised agent may submit a request on your behalf with written proof of authorisation.
California residents. The categories of personal information we collect are described in sections 3 and 4. We collect them for the business purposes in section 5, and disclose them only as described in section 6. We do not sell or share personal information as those terms are defined by the CCPA as amended by the CPRA, and we do not knowingly sell or share the personal information of consumers under 16. We honour Global Privacy Control signals, which is trivially true given we set no cookies and run no advertising.
EEA, UK and Swiss residents. You have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
12. Do Not Track
There is no consistent industry standard for responding to “Do Not Track” browser signals. Because we do not track visitors across sites or over time in any case, the question does not arise for us in practice: whether or not you send the signal, we behave the same way.
13. Changes to this policy
We may update this policy to reflect changes to our practices, our Services or the law. When we do, we update the “last updated” date at the top of this page. For material changes that affect how we handle information already collected, we will provide additional notice — for example an in-App notice or an email — and, where required by law, we will ask for your consent before the change applies to you. Previous versions are available on request.
14. Contact us
For any privacy question, request or complaint — including a request to access, correct, export or delete your personal information — email Contact@espyeon.com. Our full company details are on the About page.
Questions about this document? Write to Contact@espyeon.com. See also our Terms of Service, Privacy Policy, EULA and Acceptable Use Policy.