This Privacy Policy describes how the following apps ("the Apps") handle information:
- Clara Sky — a weather app for macOS and iOS with current conditions, a forecast, and an AI meteorologist you can ask questions
- God in All Things — a spiritual companion app featuring podcasts, meditations, blog content, and an interactive prayer guide
- Riff — an iOS app that turns topics, articles, and pasted text into AI-generated two-host podcast episodes
- WordRev — a word puzzle game that uses AI-generated clues
- Letter Stream — a solo word game playable entirely offline
- Switchboard Chaos — a solo puzzle game playable entirely offline
- Flashback — a macOS app that records your screen and lets you search back through it, with optional AI features you enable yourself
- Codex — a macOS menu bar encyclopedia that answers questions using an AI provider you choose and supply a key for
- SmarterChild — a macOS chat window in the style of the old instant-messaging bots, answered by an AI service you supply a key for
- Recent — a macOS side panel listing the files and folders you opened in the last week
- Scratch — a single scratchpad note for macOS and iOS, kept in step across your devices through your own iCloud account
- The Dock — a macOS replacement dock with a clock, weather, now playing, and your pinned apps and files
We are committed to your privacy. None of our Apps sell your data, display advertising, or require account registration.
1. Information Collection and Usage
Clara Sky (Internet-Connected App)
Clara Sky requires an internet connection to fetch forecasts and processes the following:
- Location: Clara Sky uses your device's location — or a location you search for and save — to retrieve the local forecast from Apple WeatherKit, the National Weather Service, and the Storm Prediction Center. Location is used only to fetch weather data and is not collected, logged, or shared by us.
- Saved locations and settings: Your favourite locations, units, text size, and notification preferences are stored on your device only.
- Notifications: If you enable the daily briefing or severe weather alerts, Clara Sky schedules local notifications on your device, generated on-device from forecast data already retrieved. No push service or third party is involved in delivering them.
Clara Sky does not use analytics, advertising identifiers, or crash-reporting services.
Riff (Internet-Connected App)
Riff requires an internet connection to generate episodes and processes the following:
- Episode inputs: The topics you type, the text you paste, and the contents of links you provide are sent to Anthropic and Google (see Section 2) solely to research, write, and voice your episode. We never see this content — requests go directly from your device to those providers.
- Episodes and settings: Generated episodes, artwork, and your preferences are stored on your device only.
- Notifications: When an episode finishes generating, Riff schedules a local notification on your device. No push service or third party is involved.
Riff does not use analytics, advertising identifiers, or crash-reporting services, and does not require an account.
God in All Things & WordRev (Internet-Connected Apps)
These two Apps require an internet connection and process the following data:
- Analytics and Usage Data: We use Apple's standard App Analytics to understand how the Apps are performing. This includes aggregated, anonymous data on app launches, session duration, and feature engagement. This data is only shared with us if you have opted in via your device's privacy settings.
- Diagnostic Data: The Apps may collect anonymous crash reports and technical logs via Apple to help us identify and resolve software issues.
Letter Stream & Switchboard Chaos (Offline Apps)
These Apps function entirely offline and do not transmit any data over the internet. No analytics, diagnostic data, or any other information leaves your device.
God in All Things (Additional: Local Storage)
To enable offline playback of podcast episodes and meditations, the God in All Things App requires permission to access your device's local storage to save and retrieve audio files. This data remains on your device and is never transmitted.
Flashback (macOS — Local App with Optional AI)
Flashback continuously records your Mac's main display and builds a searchable index of the text that appears on screen. Because of what it records, it is worth being precise about where that material goes: it stays on your Mac. There is no account, no sync, and no server we operate that receives it.
- Screen recordings: Captured frames are written only to a folder on your Mac, readable only by your user account. They are never uploaded or transmitted anywhere.
- Recognised text: Text recognition runs entirely on your Mac using Apple's Vision framework. Nothing is sent away to be read. The resulting search index is stored locally alongside the recordings.
- What is never recorded: Any app you add to the exclusion list is filtered out before a frame is written, rather than captured and discarded afterwards. Password managers and major streaming services are excluded by default. Recording also stops while a window whose title you have blocked is in front, on screen lock, on display or system sleep, and during fast user switching. Flashback does not record its own windows.
- Screen Recording permission: Required for the App to function. macOS asks for it on first launch, you grant it yourself in System Settings, and you can revoke it at any time. While recording is active, macOS shows its own indicator in your menu bar.
- Automation permission (optional): If you allow it, Flashback reads the web address of your front browser tab so it can stop recording on sites you have blocked. This is used for nothing else, and declining it simply leaves site blocking matching on window titles instead.
- Deletion and retention: You can delete any stretch of history from within the App, and doing so removes the underlying recordings rather than only the index entries pointing at them. You can also set an age or size limit, after which the oldest material is removed automatically.
- Diagnostic logging: Nothing derived from what was on your screen is written to the macOS system log — not window titles, not web addresses, not your search terms. The log records only counts, states, and timings.
Flashback does not use analytics, advertising identifiers, or crash-reporting services, and does not require an account.
Flashback (Buying a Licence)
Flashback is free to try and then requires a paid licence. Purchases are handled by Lemon Squeezy, which acts as the merchant of record — meaning they, not we, are the seller for the transaction and are responsible for collecting any sales tax or VAT due in your country.
- Payment details: Your card details are entered on Lemon Squeezy's checkout and handled entirely by them and their payment processor. We never see, receive, or store them.
- What we receive: Your email address, the name you gave at checkout, and an order number. These are used to issue and send your licence key, and to answer you if you write to us about the purchase.
- Your licence key: Generated on our web host from your email address and order number, emailed to you, and recorded in a log of issued orders so that a repeated notification cannot send you a second key. The key is verified by the App on your own Mac and is never sent anywhere by the App.
- What we do not do: There is no purchase-related tracking, no marketing list, and no sharing of your details with anyone beyond what is described here. We do not know which Macs a licence has been used on, because the App never reports that.
Codex (macOS — Bring Your Own Key)
Codex sits in your menu bar and answers questions using an AI provider you choose and supply your own API key for. It has no account, no server we operate, and until you enter a key it makes no network requests at all.
- What you search: The words and questions you type are sent to whichever provider you have selected — Anthropic or Google — to produce the entry you asked for. Requests go directly from the App on your Mac to that provider. We never see them.
- Search history and settings: Your recent searches, chosen model, theme, text size, and hotkey are stored on your Mac only, and are never transmitted.
- System permissions: Codex asks for none. It does not use your location, your camera or microphone, screen recording, or macOS Accessibility, and it cannot see what you are doing in other apps — you bring text to it by typing.
Codex does not use analytics, advertising identifiers, or crash-reporting services, and does not require an account.
SmarterChild (macOS — Bring Your Own Key)
SmarterChild is a chat window styled after the instant-messaging bots of the early 2000s. What you type is answered by Google's Gemini API using a key you supply yourself. There is no account, and no server we operate is involved in any part of it.
- Your conversation: Messages you type are sent to Google to be answered. Each request carries the whole of the current conversation, not only your latest message, so the reply makes sense in context — together with the screen name you have chosen, which forms part of the instructions sent with it. Requests go directly from the App on your Mac to Google. We never see them.
- Conversations are not saved: Your chat lives only in memory while the App is open. It is never written to disk, and quitting or clearing the window discards it. There is a Clear button in the App to end a conversation sooner.
- How your API key is stored: Your Gemini key is kept in the App's own local browser-style storage on your Mac, not in the macOS Keychain, and it is not encrypted at rest. It is sent to Google with each request as part of the web address, which is how that API expects to receive it. It is never sent to us. If you would rather not keep a key stored this way, remove it in Settings and the App will stop contacting Google.
- Appearance files loaded at startup: Each time it opens, the App loads its fonts and styling from three public content delivery networks (Tailwind, Cloudflare, and Google Fonts). As with any web request, those services receive your device's IP address. Nothing you type is included.
- Camera, microphone, and Bluetooth: SmarterChild does not use them. macOS may list permission text for them because of the framework the App is built with, but no such request is ever made.
SmarterChild does not use analytics, advertising identifiers, crash-reporting services, or automatic updates, and does not require an account.
Recent (macOS — Entirely Offline)
Recent shows the files and folders you have opened in the last week in a panel at the edge of your screen. It makes no network requests whatsoever — not to us, not to anyone. Nothing it reads leaves your Mac.
- What it reads: Recent asks macOS's own Spotlight index for items used in the last seven days, which returns names, paths, and dates. It does not open or read the contents of your files.
- Folder access: On first launch it touches your Desktop, Documents, Downloads, and any cloud storage folders so that macOS shows you its permission prompts. You can decline any of them, and you can add folders to an exclusion list in Settings so their contents never appear in the panel.
- What it stores: Only the panel width and your folder exclusion settings, on your Mac. The list of recent items is read fresh from Spotlight each time and is never saved by the App.
- Diagnostic logging: The App writes to the standard macOS system log on your own machine, which can include file names. This log stays on your Mac and is never transmitted.
Recent has no analytics, no third-party components of any kind, no account, and no network access.
Scratch (macOS & iOS — Syncs Through Your Own iCloud)
Scratch is a single note you can reach from your Mac's menu bar and your iPhone. So that the same note appears on both, its text is stored in your own private iCloud account — this is the one thing worth understanding before you type anything sensitive into it.
- What syncs, and to where: The text of your note and the time you last changed it are saved to your personal iCloud storage using Apple's CloudKit, in the App's private database. Private means exactly that: it lives in your Apple account, under Apple's encryption, and we cannot read it. We operate no server, and the note is never sent to us or to any third party.
- Nothing else is sent: No identifiers, no device details, no usage information — only the note's text and its timestamp.
- On your device: A copy of the note, your chosen text size, and the window size are stored locally so the App works offline.
- Turning sync off: Scratch syncs through the iCloud account already signed in to your device. Signing out of iCloud, or turning iCloud Drive off for the App in your device settings, stops it. Deleting the note's text and letting it sync removes it from iCloud as well.
Scratch does not use analytics, advertising identifiers, or crash-reporting services, has no third-party components, and requires no account beyond the iCloud one already on your device.
The Dock (macOS)
The Dock replaces the macOS dock with a panel showing a clock, calendar, weather, what is playing, and your pinned apps and files. Its only outbound requests are for weather. It has no account and no server we operate.
- Location, for weather: If you allow location access, your coordinates are sent to Open-Meteo to fetch the forecast. If you search for a city by name instead, that search text is sent to Open-Meteo's geocoding service. If you ask for current-location weather but have declined the location permission, the App falls back to estimating your rough location from your internet address using ipwho.is or ipapi.co — which necessarily means those services see your IP address. Declining location and setting a city manually avoids this entirely.
- Accessibility permission (optional, off by default): Two features ask for it — keeping other windows clear of the dock strip, and showing the notification badges that appear on your real dock. Used this way, the App reads only the position and size of other apps' windows, never their titles, their contents, or the documents they have open. Both features are switched off until you turn them on.
- Automation permission (optional): Used to ask Music and Spotify what is currently playing, to open Finder windows, and to check whether the Trash is full. Track details are shown on screen and go nowhere else. Declining it simply leaves the now-playing panel empty.
- What it stores on your Mac: The apps, files, and folders you have pinned (their names and locations), the city and coordinates last used for weather, the order of recently used apps, and your appearance preferences. All of it stays on your Mac and none of it syncs anywhere.
The Dock does not use analytics, advertising identifiers, crash-reporting services, or automatic updates, and does not require an account.
2. AI-Powered Features
Clara Sky — Ask Clara & Daily Briefing
Clara Sky includes an "Ask Clara" feature and an automatically generated daily briefing, both powered by the Claude API (Anthropic), using an API key you supply and manage yourself. When you use these features:
- Interaction Data: Questions you type, and the current forecast data needed to answer them (conditions, alerts, forecaster discussion, and similar), are sent to Anthropic to generate a response.
- Your API Key: Your Anthropic API key is stored only in the macOS/iOS Keychain on your device. It is never sent to us or stored on any server we control — requests go directly from the app to Anthropic.
- Optional Web Search: If a question can't be answered from the forecast alone, or if you enable "local expertise," Clara may use Anthropic's web search tool to look up authoritative sources such as weather.gov or NOAA.
- Privacy of AI Inputs: Under our agreement with Anthropic, data you provide during these interactions is not used to train or improve their AI models.
- Data Retention: Interaction logs are typically retained by Anthropic for a limited period (generally up to 30 days) for trust, safety, and troubleshooting purposes, after which they are deleted.
Riff — Episode Generation
Riff generates every episode using two AI services, each accessed with an API key you supply and manage yourself: the Claude API (Anthropic) researches your topic and writes the conversation, and the Gemini API (Google) voices the hosts and draws the episode artwork. When you generate an episode:
- Interaction Data: Your topic, pasted text, or the contents of a link you provide are sent to Anthropic to research and write the script (Anthropic's web search tool may look up sources on the open web), and the finished script is sent to Google to synthesise the audio and artwork.
- Your API Keys: Your Anthropic and Google keys are stored only in the iOS Keychain on your device. They are never sent to us or stored on any server we control — requests go directly from the app to each provider.
- Your Provider Relationship: Because you use your own API keys, your use of these services is governed by your own agreements with Anthropic and Google, including their data retention and model training policies. Consult the Anthropic and Google privacy policies for details.
God in All Things — Interactive Prayer Guide
The App includes an interactive prayer guide powered by the Claude API (Anthropic). When you use this feature:
- Interaction Data: Text you input into the prayer guide is sent to Anthropic to generate a response.
- Privacy of AI Inputs: Under our agreement with Anthropic, data you provide during these interactions is not used to train or improve their AI models.
- Data Retention: Interaction logs are typically retained by Anthropic for a limited period (generally up to 30 days) for trust, safety, and troubleshooting purposes, after which they are deleted.
WordRev — AI-Generated Clues
WordRev uses the OpenAI API to generate clues for word puzzles. This process happens in the background; you do not interact with the AI directly, and no personal input is sent to OpenAI. The game submits game-generated word data to the API solely for the purpose of clue generation.
- Privacy of AI Inputs: Under our agreement with OpenAI, data submitted during clue generation is not used to train or improve their AI models.
- Data Retention: Logs are typically retained by OpenAI for a limited period (generally up to 30 days) for trust, safety, and troubleshooting purposes, after which they are deleted.
Flashback — Smart Search & Ask
Flashback includes two optional features that use the Claude API (Anthropic), each a separate switch because they send different things. Both are off until you enter an API key you supply and manage yourself. With no key entered, Flashback makes no network requests at all.
- Smart Search: Sends only the words you type into the search box, so they can be expanded into related terms that may have appeared on screen. Your recordings and your index are not sent.
- Ask: Sends the recognised text from the period of history you select, so a question about that period can be answered. Images and recordings themselves are never sent — only text. The App can show you exactly what would be sent before you enable the feature.
- Your API Key: Stored only in the macOS login Keychain on your Mac. It is never sent to us or stored on any server we control — requests go directly from the App to Anthropic.
- Your Provider Relationship: Because you use your own API key, your use of the service is governed by your own agreement with Anthropic, including their data retention and model training policies. See the Anthropic privacy policy for details.
Codex — Entries, Definitions & Optional Web Search
Everything Codex shows you is generated by an AI provider at the moment you ask, and you choose which one. Selecting a Claude model (Opus, Sonnet, or Haiku) sends your request to the Claude API (Anthropic); selecting Gemini Flash sends it to the Gemini API (Google). Each requires a key you supply and manage yourself, and only the provider behind the model you have selected receives anything.
- Interaction Data: The word, topic, or question you type is sent to the selected provider to generate the entry, along with the topic of the entry you are reading when you follow a link within it.
- Optional Web Search: If you switch web search on, the provider may use its own web search tool to look up sources on the open web before answering. It is off unless you enable it.
- Your API Keys: Your Anthropic and Google keys are stored only in the macOS Keychain on your Mac. They are never sent to us or stored on any server we control — requests go directly from the App to each provider.
- Your Provider Relationship: Because you use your own API key, your use of these services is governed by your own agreements with Anthropic and Google, including their data retention and model training policies. Consult the Anthropic and Google privacy policies for details.
SmarterChild — Chat Replies
Every reply in SmarterChild is generated by Google's Gemini API, using a key you supply and manage yourself. There is no fallback and no other provider: with no key entered, the App cannot answer at all.
- Interaction Data: Your messages, the conversation so far, and the screen name you chose are sent to Google to generate each reply.
- Search and maps look-ups: Depending on what you ask, the request may enable Google's own search or maps tools so the reply can draw on current information. This uses the words of your message; the App never reads or sends your device's actual location.
- Your API Key: Stored on your Mac in the App's local storage — see Section 1 for exactly how, as it differs from our other apps. It is never sent to us or stored on any server we control; requests go directly from the App to Google.
- Your Provider Relationship: Because you use your own API key, your use of the service is governed by your own agreement with Google, including their data retention and model training policies. Note that free-tier Google AI keys carry different terms from paid ones, including how your prompts may be used. See the Google privacy policy and the terms attached to your key for details.
3. Children's Privacy
The God in All Things App contains content specifically designed for children. We strictly adhere to the Children's Online Privacy Protection Act (COPPA):
- No Collection of Personal Data: We do not knowingly collect, request, or store any personally identifiable information from children.
- No Tracking: We do not engage in behavioural advertising or user profiling within the App, especially in sections directed toward children.
- Safe Listening: Children's content is designed for a passive listening experience and does not include social or interactive features that require personal data.
Clara Sky, Riff, Flashback, Codex, SmarterChild, Recent, Scratch, The Dock, and the three games (WordRev, Letter Stream, and Switchboard Chaos) are not directed toward children and do not contain children's content sections.
4. Third-Party Service Providers
Clara Sky
- Weather Data: Apple WeatherKit, the National Weather Service, and the Storm Prediction Center supply forecasts, forecaster discussions, active alerts, and severe weather outlooks.
- AI Services (Anthropic): Questions and optional web searches are processed by Anthropic. See Section 2 above.
God in All Things
- Audio Streaming: When streaming podcasts, requests are handled by hosting providers or platforms such as Spotify. These services may receive your IP address and device type to deliver audio.
- Website Content: Blog posts are retrieved from the God in All Things website. Standard web server logs (including IP addresses) may be generated by our web host to facilitate these requests.
- AI Services (Anthropic): Text interactions within the prayer guide are processed by Anthropic. See Section 2 above.
Riff
- AI Services (Anthropic): Episode research and script writing, including optional web searches, are processed by Anthropic. See Section 2 above.
- AI Services (Google): Voice synthesis and episode artwork are processed by Google's Gemini API. See Section 2 above.
- Linked Articles: When you paste a link, Riff fetches that page directly from its website, which may receive your IP address as with any web request.
WordRev
- AI Services (OpenAI): Game-generated word data is sent to OpenAI for clue generation. See Section 2 above.
Flashback
- AI Services (Anthropic): Only if you enable the optional Smart Search or Ask features with your own API key. See Section 2 above.
- Payments (Lemon Squeezy): Purchases of a Flashback licence are processed by Lemon Squeezy as merchant of record, who receive your payment and billing details directly. See their privacy policy. See Section 1 above for what reaches us.
- No other third parties: Your recordings and search index are never sent to any service, including ours.
Codex
- AI Services (Anthropic): Searches are processed by Anthropic when you have a Claude model selected, including optional web searches. See Section 2 above.
- AI Services (Google): Searches are processed by Google's Gemini API when you have Gemini Flash selected, including optional web searches. See Section 2 above.
- No other third parties: Codex contacts nothing else. Your search history stays on your Mac.
SmarterChild
- AI Services (Google): Your messages and conversation are processed by Google's Gemini API, including its search and maps look-ups. See Section 2 above.
- Appearance files (Tailwind, Cloudflare, Google Fonts): Fonts and styling are loaded from these public networks at startup, which receive your IP address as with any web request. Nothing you type is included.
Scratch
- Apple iCloud (CloudKit): Your note is stored in your own private iCloud database so it appears on your other devices. Apple's handling of it is governed by their privacy policy. We cannot read it. See Section 1 above.
- No other third parties.
The Dock
- Weather (Open-Meteo): Receives the coordinates, or the city name you search for, needed to return a forecast. See their terms and privacy notice.
- Location estimate (ipwho.is, ipapi.co): Used only as a fallback when you have asked for current-location weather but declined the location permission. These services see your IP address in order to estimate a location.
- No other third parties. Your pinned items and settings are never sent anywhere.
Recent
Recent uses no third-party services and makes no network requests of any kind.
Letter Stream & Switchboard Chaos
These Apps do not use any third-party services.
5. Data Security
We value the trust you place in us and use commercially acceptable means to protect any data processed by the Apps. All network requests use HTTPS, and API keys in Clara Sky, Riff, Codex, and Flashback are held in the operating system's Keychain, which encrypts them at rest. SmarterChild is the exception: it stores its key in the App's own local storage without that encryption, as described in Section 1. Please be aware, in any case, that no method of transmission over the internet or electronic storage is 100% secure.
6. Your Rights
As the Apps do not collect personal identifiers such as names or email addresses, we are generally unable to identify specific users. You can control your privacy by:
- Adjusting your "Share with App Developers" settings in your iOS Privacy settings.
- Deleting the God in All Things App or clearing its local cache to remove any downloaded audio files.
- Removing your API key in Clara Sky's Settings at any time, which disables its AI features.
- Changing or removing your API keys in Riff's settings at any time, and deleting the app to remove all locally stored episodes.
- Denying or revoking location access for Clara Sky in your device's Privacy settings — it will let you search for a location by name instead.
- Pausing Flashback from its menu bar item, adding apps or window titles to its exclusion list, deleting any stretch of recorded history from its Settings, or revoking its Screen Recording permission in System Settings — any of which stops it recording without removing what you have already chosen to keep.
- Removing your API key in Flashback's Settings at any time, which disables its AI features and returns it to making no network requests at all.
- Removing your API key in Codex's Settings at any time, which stops it contacting any provider, or clearing your recent searches with the Clear button beside them in its search window.
- Removing your API key in SmarterChild's Settings at any time, which stops it contacting Google, and using its Clear button to end a conversation — chats are never written to disk in any case.
- Excluding folders in Recent's Settings so their contents never appear, or declining its folder permissions in System Settings.
- Signing out of iCloud, or turning iCloud off for Scratch in your device settings, to stop your note syncing. Clearing the note's text removes it from iCloud too.
- Setting a city manually in The Dock rather than allowing location access, which avoids both the location permission and the IP-based fallback; and leaving its Accessibility and Automation permissions switched off, which are off by default.
- Writing to us to ask what purchase details we hold for your Flashback licence, or to have them removed. Removing them does not deactivate a licence already issued, because the App checks it on your Mac rather than against us.
7. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services or legal requirements. Updates will be posted here with a revised Effective Date.
8. Contact Us
If you have any questions or suggestions regarding this policy, please contact us at:
- Website: andyotto.com/support.html
- Email: support@andyotto.com