Privacy policy.
Plain English, no jargon, because privacy matters too much to hide behind it.
We believe in clarity. This policy is written in plain English that anyone can understand.
If you use the Catchlight app: we hold none of your data. None. Your notes, reminders and privacy phrase live on your device and, if you choose, in a cloud folder you own. Considus never sees them.
If you write to us or join the mailing list: we hold what you chose to send. Your message, your email address if you gave one, and nothing else.
If you are just reading this website: it sets no cookies, keeps only the light or dark setting you choose, and serves its own typefaces, so loading a page makes exactly one request outside this domain. That request is the analytics, which counts pages rather than people. The app itself has no analytics at all.
That is it. Everything below is the legal detail behind those three points.
Who we are
Considus is a sole trader based in England. References to "we", "us", and "our" in this policy mean Considus.
Contact address: Considus, Unit 168318, PO Box 7169, Poole, Dorset, BH15 9EL, United Kingdom.
We are the data controller for the limited personal data we process in connection with this website, our marketing emails, and any support enquiries you send us.
For questions or requests, contact us at privacy@considus.com.
We are not a data controller for any data you create inside the Catchlight app, because we never receive it.
What this website does not do
- Set cookies of any kind, or keep anything on your device beyond the light or dark setting you choose.
- Collect names, email addresses, or any other personal data, other than what you choose to send us through the support form or by joining the mailing list.
- Build a profile of you, or recognise you when you come back.
- Follow you to any other website.
- Use advertising networks or third-party marketing tools on this site.
- Load fonts from a third-party server.
Cookies
catchlight.app sets no cookies. The one thing it keeps on your device is the light or dark setting, and only if you change it yourself using the toggle, so the site can remember your choice next time. It holds the word "dark" or "light" and nothing else. Your browser stores it, it is never sent to us, and you can clear it whenever you like in your browser settings. Because that is a preference you asked for rather than anything that tracks you, it needs no cookie banner and you will not see one. If we ever keep anything beyond it, we will update this policy and ask you first.
Typefaces and third-party resources
The typefaces used here (Cormorant Garamond and DM Sans) are served from this site itself. Nothing is fetched from Google Fonts or any other external service.
Loading a page on this site causes your browser to make exactly one request outside this domain, for the analytics script described below, which is served by Cloudflare. Nothing else is fetched externally. Earlier versions of this site did load its typefaces from Google Fonts, which disclosed visitor IP addresses to Google LLC. That was changed in July 2026.
Hosting
This site is hosted and delivered through Cloudflare Pages (Cloudflare, Inc.). To serve and secure the site, Cloudflare processes basic technical data on our behalf, including visitors' IP addresses in its server logs, as part of its CDN and DDoS protection. We rely on our legitimate interest in running a secure, working website, and we do not use this data to identify or track you. Considus does not have access to Cloudflare's server logs. Cloudflare's processing is governed by its Privacy Policy.
Analytics
This site uses Cloudflare Web Analytics. It is worth being specific about what that is, because it works differently from the analytics most websites run.
It sets no cookies and writes nothing to your device. In Cloudflare's own words, it "does not use any client-side state, such as cookies or localStorage, to collect usage metrics", and does not "fingerprint individuals via their IP address, User Agent string, or any other data". There is no identifier that recognises you on a second visit, and nothing that follows you to another website.
What it records is about pages rather than people. Which page was requested, the site you arrived from, the country the request came from, the browser and device type, the HTTP status code, and how quickly the page rendered. That is the whole of it. We see counts and trends, never individuals, and Cloudflare does not sell the data.
To collect this, your browser loads a small script from static.cloudflareinsights.com and sends the measurements to cloudflareinsights.com. Both are Cloudflare domains, and this is the one third-party request the site makes.
Because nothing is stored on or read from your device, this does not require a consent banner under the Privacy and Electronic Communications Regulations, and you will not see one. Where a country is derived from an IP address, we rely on our legitimate interest in knowing whether the site works and whether anyone is reading it. Cloudflare acts as our processor under its Privacy Policy. If you would rather not be counted, any standard tracker blocker will stop the script loading, and the site will work exactly as before.
This applies to catchlight.app only. The Catchlight app itself contains no analytics of any sort, as set out below, and nothing you write in the app is ever measured.
If you contact us
If you use the support form on this site, we receive the message you write and, if you choose to give one, your email address so we can reply. The form writes directly to our own database, hosted by Cloudflare. No email service and no third-party form provider is involved. If you email us instead, your message arrives in our mailbox, which is hosted by Proton (Proton AG) in Switzerland.
- Legal basis: legitimate interests (UK GDPR Article 6(1)(f)), namely receiving and dealing with your enquiry, and keeping a short record of issues so we can fix them. Giving your email is optional and is used only to reply to you.
- Data held: your message, and your email address if you provide one. Nothing else.
- How long we keep it: only as long as we need it to deal with your enquiry and keep a brief record, then we delete it.
The form on catchlight.app also lets you attach a diagnostics log from the Catchlight app. The log records events and timestamps only, never the content of your Takes, and it is only ever sent if you choose to attach it.
If you join our mailing list
If you opted in to receive news and updates from Considus, we hold your email address for the purpose of sending those communications.
- Legal basis: consent (UK GDPR Article 6(1)(a)).
- Data held: your email address. We do not collect a name, payment details, device identifiers, or anything derived from your use of our software.
- Processor: we use EmailOctopus to manage and send our email list. Our contract is with Three Hearts Digital Ltd, a UK company based in London, which acts as a data processor on our behalf and stores our subscriber data on servers in Ireland, inside the European Economic Area. See EmailOctopus's privacy policy and data processing terms.
- How long we keep it: until you unsubscribe or ask us to delete it. Every email we send carries an unsubscribe link, and you can also just ask us.
Catchlight app users
Considus holds zero data about you.
Catchlight is designed on a zero-knowledge, offline-first architecture. This is not a marketing claim, it is a structural constraint built into every layer of the app.
- Your notes, activity types, and reminders are stored only on your device, encrypted at rest using AES-256-GCM with a key derived from your privacy phrase. Considus has no copy of this key.
- Your privacy phrase (a 12-word mnemonic) is generated on your device during setup and stored in the iOS Keychain, protected by Apple's hardware security. It is never transmitted anywhere.
- Unlocking the app is handled by iOS. If you choose to lock Catchlight, it opens only after your device passcode, Face ID or Touch ID, checked by iOS on your device. Considus receives nothing from that check.
- Cloud sync is optional and user-directed. If you enable it, your encrypted data is written to a folder in iCloud Drive or Dropbox. That folder belongs to you and is governed by your agreement with that provider. Your Takes are encrypted before they leave your device, and so is the index that lists them, so the folder does not show how many Takes you hold, when you last changed one, or what you have deleted. Considus has no access to that folder.
- What your cloud provider can still see. Encryption hides what is in the folder, not that the folder is there. Your provider can count the files, see how large each one is, and keep its own record of when they arrived. That comes with putting files in someone else's storage and is not something we can encrypt away. None of those files can be read without your privacy phrase.
- Sharing a link to Catchlight fetches its preview. When you share a web link into Catchlight, the app asks that site for the page title and picture so you can see what you kept. That request goes to the site itself, never to us, and it carries nothing about you beyond the fact that a device asked. Usually you are already on the page you are sharing, so the site has seen you anyway, but if you forward a link you have not opened, this is the app contacting it. Nothing from the preview is stored, only the text you shared.
- Setting a location reminder talks to Apple. The map draws its tiles from Apple, and the search field sends what you type to Apple to be matched against real places. Turning coordinates into a street name is Apple's job too. Of everything Catchlight sends anywhere, that search text is the only piece that is something you wrote, so it is worth knowing before you type an address you would rather nobody had. Your Takes are in none of it.
- Buying or restoring a subscription talks to the App Store. That is Apple checking what you have paid for, and there is no way to sell you something without asking.
- None of those requests come to us. They go to the site whose link you shared, or to Apple. We run no server for the app to reach.
- What iOS may do inside a Take, if you let it. Catchlight has no AI in it. That does not mean your phone has none. Select some text in a Take and iOS offers you Writing Tools, and if you use them Apple may take that text away to work on it. There is a switch for it under Security in Settings, off unless you turn it on. A keyboard you installed yourself is separate. It sees everything typed into it, Catchlight included, and we do not block those, because taking away a keyboard you chose would be the same high-handedness pointed the other way.
- No third-party analytics or crash SDKs. The app embeds no analytics service, no crash-reporting service, and no advertising or tracking code. Catchlight keeps a small diagnostics log on your device to help with troubleshooting. It records events and timestamps only, never the content of your Takes, and nothing from it reaches us unless you choose to attach it to a support report.
- What Apple may share. If you have turned on "Share With App Developers" in iOS Settings, Apple may give us aggregated crash and usage data for the app that is not linked to you. This comes from Apple, never contains your Takes, and you can turn it off in iOS Settings at any time. We collect no device identifiers, IP addresses or usage profiles ourselves.
Because we hold no data, we cannot breach it, sell it, or lose it. That is the point.
What Apple and the App Store process
Catchlight is free to download from the App Store. When you download it, Apple processes data in accordance with Apple's own privacy policy. We have no control over or access to that data.
Catchlight offers an optional paid subscription. Any purchase is handled entirely by Apple as the seller, and we never see your card or payment details. Apple gives us only aggregated sales and subscriber figures through App Store Connect, which do not identify you.
When you use Face ID or Touch ID to unlock the app, that check is performed locally by iOS on your device. Neither Considus nor Apple's biometrics frameworks receive the biometric data itself.
Local device storage
| Storage | What it holds | Who can access it |
|---|---|---|
| iOS Keychain | Your privacy phrase (encrypted) | You, on this device only |
| SQLite database | Your encrypted notes and reminders | You, on this device only |
| UserDefaults / App Group | UI preferences, cloud folder bookmark | You, on this device only |
The SQLite database is protected with NSFileProtectionCompleteUntilFirstUserAuthentication, meaning it is inaccessible until you have unlocked your device for the first time after a restart.
Children's privacy
Our marketing email list requires opt-in consent, and we do not knowingly collect email addresses from children under 13.
Catchlight is rated 4+ on the App Store and is suitable for all ages. Because we collect no personal data from app users, no special consideration for children is required in that context.
Your rights under UK GDPR
As a data subject under UK law, you have the following rights in relation to personal data we hold.
- Right of access, you may request a copy of the personal data we hold about you.
- Right to rectification, you may ask us to correct inaccurate data.
- Right to erasure, you may ask us to delete your data. We will comply promptly unless a legal obligation requires us to retain it.
- Right to restrict processing, you may ask us to pause processing your data in certain circumstances.
- Right to data portability, you may request your data in a portable format.
- Right to object, you may object to processing based on legitimate interests.
- Right to withdraw consent, where we process data on the basis of consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, or to unsubscribe from marketing emails, contact us at privacy@considus.com. We will respond within one calendar month.
You also have the right to complain to us directly if you think we have mishandled your personal data. Use our support form and choose "Data protection", telling us what happened and what you would like us to do. We will acknowledge your complaint within 30 days, look into it, and give you a full response within one calendar month. If we need longer, we will tell you why and keep you updated.
If you are not satisfied with our response, you can escalate your complaint to the UK Information Commissioner's Office (ICO) at ico.org.uk.
These rights apply to our marketing subscribers and to anyone who has contacted our support. App users have no personal data held by us to exercise rights over.
Data transfers
The small amount of personal data we process is handled by three providers, one in the United Kingdom (EmailOctopus), one in the United States (Cloudflare) and one in Switzerland (Proton), with some data stored in the European Economic Area. Where a provider transfers UK personal data outside the UK, that transfer is protected by the safeguards UK data protection law requires, as set out below.
- EmailOctopus (Three Hearts Digital Ltd, United Kingdom) stores our subscriber data on servers in Ireland, inside the European Economic Area. Transfers of personal data from the UK to the EEA are permitted under the UK's data protection adequacy regulations, so no additional transfer safeguards are required. Where EmailOctopus uses its own sub-processors outside the UK and EEA, it applies the safeguards required by UK and EU data protection law.
- Cloudflare (Cloudflare, Inc., US) hosts the website and the database that holds support reports, under the Standard Contractual Clauses together with the UK International Data Transfer Addendum. Cloudflare is also certified under the UK Extension to the EU-US Data Privacy Framework.
- Proton (Proton AG) hosts our email in Switzerland, which the UK recognises as providing an adequate level of data protection, so no additional safeguards are required.
Catchlight app data is never transferred to us, so no international transfer consideration applies to it.
Security
For marketing subscriber and support data, we rely on our providers' security practices and put appropriate organisational measures in place on our side, including using a dedicated privacy contact address and limiting who can access it.
For Catchlight app data, security is structural. Your data is encrypted on your device, with a key only you hold, before it is written anywhere, including before any optional sync ever leaves your phone. There is nothing in our possession to secure or breach.
Links to other sites
This site links to other websites, including considus.com. Those sites have their own privacy policies and are not governed by this document. Considus is not responsible for the privacy practices of any linked site.
Changes to this policy
We may update this policy from time to time. If it changes, the version number and effective date at the top of this page will be updated, and changes will not be applied retroactively. Material changes that affect marketing subscribers will be communicated by email.
We will also post the updated version at the canonical URL provided by the App Store. Continued use of the app after a non-material update does not require fresh consent, because we hold no app user data to begin with.
Governing law
This policy is governed by the laws of England and Wales. Any disputes arising under it are subject to the exclusive jurisdiction of the courts of England and Wales.
Contact
Privacy enquiries and data subject requests should be directed to:
Email: privacy@considus.com
Complaints: use our support form and choose "Data protection"
Publisher: Considus
We aim to respond to all enquiries and formal data subject requests within one calendar month. If your contact is a complaint about how we handle your personal data, we will acknowledge it within 30 days and give you a full response within one calendar month.
Catchlight is built on the principle that your private thoughts are yours alone. This policy reflects that commitment, not as a legal obligation, but as the natural consequence of how the app is built.