Privacy Policy.
Plain English, no jargon, because privacy matters too much to hide behind it.
We believe in clarity. This policy is written in plain English that anyone can understand.
If you use the Catchlight app: we hold none of your data. None. Your notes, reminders, and privacy phrase live on your device and, if you choose, in a cloud folder you own. Considus never sees them.
If you signed up to hear from us: we hold your email address in MailerLite so we can send you updates you asked for. You can unsubscribe at any time.
That’s it. Everything below is the legal detail behind those two sentences.
Who we are
Catchlight is published by Considus, a sole trader based in England. References to “we”, “us”, and “our” in this policy mean Considus.
Contact address: Considus, Unit 168318, PO Box 7169, Poole, Dorset, BH15 9EL, United Kingdom.
We are the data controller for the limited personal data we process in connection with our marketing emails and any support enquiries you send us. We are not a data controller for any data you create inside the Catchlight app, because we never receive it.
For questions or requests, contact us at privacy@considus.com.
The separate relationships
Depending on how you interact with Catchlight, different privacy considerations apply. We separate them clearly because they are genuinely different.
2.1 Catchlight app users
Considus holds zero data about you.
Catchlight is designed on a zero-knowledge, offline-first architecture. This is not a marketing claim, it is a structural constraint built into every layer of the app.
- Your notes, activity types, and reminders are stored only on your device, encrypted at rest using AES-256-GCM with a key derived from your privacy phrase. Considus has no copy of this key.
- Your privacy phrase (a 12-word mnemonic) is generated on your device during setup and stored in the iOS Keychain, protected by Apple’s hardware security. It is never transmitted anywhere.
- Unlocking the app is handled by iOS. If you choose to lock Catchlight, it opens only after your device passcode, Face ID or Touch ID, checked by iOS on your device. Considus receives nothing from that check.
- Cloud sync is optional and user-directed. If you enable it, your encrypted data is written to a folder in iCloud Drive or Dropbox. That folder belongs to you and is governed by your agreement with that provider. The data is encrypted before it leaves your device. Considus has no access to that folder.
- No third-party analytics or crash SDKs. The app embeds no analytics service, no crash-reporting service, and no advertising or tracking code. Catchlight keeps a small diagnostics log on your device to help with troubleshooting. It records events and timestamps only, never the content of your Takes, and nothing from it reaches us unless you choose to attach it to a support report.
- What Apple may share. If you have turned on “Share With App Developers” in iOS Settings, Apple may give us aggregated crash and usage data for the app that is not linked to you. This comes from Apple, never contains your Takes, and you can turn it off in iOS Settings at any time. We collect no device identifiers, IP addresses or usage profiles ourselves.
Because we hold no data, we cannot breach it, sell it, or lose it. That is the point.
What Apple and the App Store process
Catchlight is free to download from the App Store. When you download it, Apple processes data in accordance with Apple’s own privacy policy. We have no control over or access to that data.
Catchlight offers an optional paid subscription. Any purchase is handled entirely by Apple as the seller, and we never see your card or payment details. Apple gives us only aggregated sales and subscriber figures through App Store Connect, which do not identify you.
When you use Face ID or Touch ID to unlock the app, that check is performed locally by iOS on your device. Neither Considus nor Apple’s biometrics frameworks receive the biometric data itself.
Local device storage
| Storage | What it holds | Who can access it |
|---|---|---|
| iOS Keychain | Your privacy phrase (encrypted) | You, on this device only |
| SQLite database | Your encrypted notes and reminders | You, on this device only |
| UserDefaults / App Group | UI preferences, cloud folder bookmark | You, on this device only |
The SQLite database is protected with NSFileProtectionCompleteUntilFirstUserAuthentication, meaning it is inaccessible until you have unlocked your device for the first time after a restart.
2.2 Marketing subscribers
If you opted in to receive news and updates from Considus, for example, via the Catchlight website, we hold your email address for the purpose of sending those communications.
- Legal basis: Consent (UK GDPR Article 6(1)(a)).
- Data held: Your email address. We do not collect a name, payment information, device identifiers, or any data derived from your app usage.
- Processor: We use MailerLite to manage and send our email list. As a UK customer, our contract is with MailerLite Limited, an Irish company based in Dublin, which acts as a data processor on our behalf and stores our subscriber data on servers in the European Union. See MailerLite’s privacy policy and data processing agreement.
- How long we keep it: Until you unsubscribe or ask us to delete it. We do not retain subscriber data for longer than necessary.
2.3 Support and issue reports
If you use our “Report an issue” form, or the app sends you to it, you can send us a short message, optionally your email address, and optionally a diagnostics log. The diagnostics log records events and timestamps only, never the content of your Takes. You can also email us directly if you prefer.
- Legal basis: Legitimate interests (UK GDPR Article 6(1)(f)), namely receiving and dealing with your enquiry. Giving your email is optional and is used only to reply to you.
- Data held: Your message, your email address if you provide one, and any diagnostics log you attach. Nothing else.
- Where it goes: A report from the form is saved to our own database, hosted by Cloudflare (Cloudflare, Inc.). No email or third-party sending service is involved. If instead you email us directly, your message arrives in our mailbox, which is hosted by Proton (Proton AG, Switzerland).
- How long we keep it: Only as long as we need it to resolve your issue and keep a short record, then we delete it.
Cookies, hosting and the Catchlight website
catchlight.app may use essential cookies necessary for the site to function. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. If we add any non-essential cookies in future, we will update this policy and seek your consent.
The website is hosted and delivered through Cloudflare (Cloudflare, Inc.). To serve and secure the site, Cloudflare processes basic technical data on our behalf, including visitors’ IP addresses in its server logs. We rely on our legitimate interest in running a secure, working website. We do not use this data to identify or track you, and we keep no analytics of our own.
Children’s privacy
Catchlight is rated 4+ on the App Store. It is suitable for all ages. Because we collect no personal data from app users, no special consideration for children is required in that context. Our marketing email list requires opt-in consent; we do not knowingly collect email addresses from children under 13.
Your rights under UK GDPR
As a data subject under UK law, you have the following rights in relation to personal data we hold. These apply to our marketing subscribers and to anyone who has contacted our support. App users have no personal data held by us to exercise rights over.
- Right of access, you may request a copy of the personal data we hold about you.
- Right to rectification, you may ask us to correct inaccurate data.
- Right to erasure, you may ask us to delete your data. We will comply promptly unless a legal obligation requires us to retain it.
- Right to restrict processing, you may ask us to pause processing your data in certain circumstances.
- Right to data portability, you may request your data in a portable format.
- Right to object, you may object to processing based on legitimate interests.
- Right to withdraw consent, where we process data on the basis of consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, or to unsubscribe from marketing emails, contact us at privacy@considus.com. We will respond within one calendar month.
You also have the right to complain to us directly if you think we have mishandled your personal data. Use our complaints and issues form and choose “Data protection complaint”, telling us what happened and what you would like us to do. We will acknowledge your complaint within 30 days, look into it, and give you a full response within one calendar month. If we need longer, we will tell you why and keep you updated.
If you are not satisfied with our response, you can escalate your complaint to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Data transfers
The small amount of personal data we process is handled by a few providers, one based in the United States (Cloudflare), one in Ireland (MailerLite) and one in Switzerland (Proton), with some data stored in the European Economic Area. Where a provider transfers UK personal data outside the UK, that transfer is protected by the safeguards UK data protection law requires, as set out below.
- MailerLite (MailerLite Limited, Ireland) stores our subscriber data on servers in the European Economic Area. Transfers of personal data from the UK to the EEA are permitted under the UK’s data protection adequacy regulations, so no additional transfer safeguards are required for this. Where MailerLite uses its own sub-processors outside the EEA, it applies the safeguards required by UK and EU data protection law, as set out in its data processing agreement.
- Cloudflare (Cloudflare, Inc., US) hosts the website and the database that holds support reports, under the Standard Contractual Clauses together with the UK International Data Transfer Addendum. Cloudflare is also certified under the UK Extension to the EU-US Data Privacy Framework.
- Proton (Proton AG) hosts our email in Switzerland, which the UK recognises as providing an adequate level of data protection, so no additional transfer safeguards are required.
Catchlight app data is never transferred to us, so no international transfer consideration applies to it.
Security
For marketing subscriber and support data, we rely on our providers’ security practices and put appropriate organisational measures in place on our side, including using a dedicated privacy contact address and limiting who can access it.
For Catchlight app data, security is structural. Your data is encrypted on your device, with a key only you hold, before it is written anywhere, including before any optional sync ever leaves your phone. There is nothing in our possession to secure or breach.
Changes to this policy
We may update this policy from time to time. We will post the updated version at the canonical URL provided by the App Store and on the Catchlight website. Material changes that affect marketing subscribers will be communicated by email. Continued use of the app after a non-material update does not require fresh consent, because we hold no app user data to begin with.
The version number and effective date at the top of this document indicate which revision you are reading.
Governing law
This policy is governed by the laws of England and Wales. Any disputes arising under it are subject to the exclusive jurisdiction of the courts of England and Wales.
Contact
Privacy enquiries and data subject requests should be directed to:
Email: privacy@considus.com
Complaints: use our complaints and issues form (choose “Data protection complaint”)
Publisher: Considus
We aim to respond to all enquiries and formal data subject requests within one calendar month. If your contact is a complaint about how we handle your personal data, we will acknowledge it within 30 days and give you a full response within one calendar month.
Catchlight is built on the principle that your private thoughts are yours alone. This policy reflects that commitment, not as a legal obligation, but as the natural consequence of how the app is built.