Privacy Policy
Effective date: August 31, 2026
Alune ("the App") is a personal productivity and wellness companion built
by Ahmed Diab. Your privacy is fundamentally important to us.
On-Device Data
Everything you create in Alune is stored
on your device using Apple's SwiftData framework and
is not uploaded to any server. This includes:
- Habits and habit logs
- Goals and milestones
- Journal entries (text, mood, energy, tags)
- Notes
- Medicine and supplement schedules and dose logs
- Reading log items and categories
- Saved memories the Assistant can reference
- App settings and preferences
Calendar events and reminders are managed by iOS itself through Apple's
EventKit framework. Alune reads from and writes to the calendars and
reminder lists you grant access to. The data lives in your iOS Calendar
and Reminders, not on Alune's servers.
Data Sent to Servers
Certain features require network communication. When you use these
features, limited data leaves your device as described below. You are
asked to confirm AI usage in-app before any Assistant chat or voice
transcription request is sent.
-
AI Assistant (text): When you send a message to the
AI assistant, the text of your conversation is transmitted over HTTPS
to Alune's secure server-side proxy hosted on Supabase. The Supabase
proxy forwards the request to OpenRouter, which routes it to Google's
Gemini models through a Zero Data Retention Google Vertex route
for processing. When the Assistant uses tools to
answer your question, items it explicitly fetches (such as the title
and time of a calendar event, the text of a journal entry, a note, a
habit, a goal, a medicine schedule, or a reminder you ask about) are
included in the request. No personally identifiable information beyond
the text you type and the item content the Assistant pulls is attached,
and nothing else from your device is sent automatically.
Assistant requests are routed exclusively to providers with
Zero Data Retention agreements. Neither Alune, our Supabase
proxy, OpenRouter, nor the routed AI provider stores your prompts or
completions after processing. Alune may store anonymous quota counters
and security records such as App Attest sessions, and may log
privacy-safe operational telemetry such as model name, provider,
status, latency, token counts, and estimated cost. These logs do not
include prompts, completions, tool arguments, calendar or reminder
contents, note contents, journal contents, or user identifiers.
-
Memory privacy: If the Assistant pulls memories you
have saved (the small "remember this" notes shown in Settings), every
personal name, place, organization, and email address in them is
replaced on your device with anonymous placeholder tokens (for
example, "Sara" becomes "[P1]") before the request leaves the device.
The model never sees the original values.
-
Voice transcription: When you use the voice input
feature, your audio recording is transmitted over HTTPS to the same
Supabase proxy. Production App Store traffic uses ElevenLabs Scribe v2
Realtime, with captured-audio Scribe v2 as the fallback. ElevenLabs
processes this audio under our Zero Retention Mode agreement and does
not use it for advertising or model training. Separately verified
internal Beta builds may use an OpenAI speech-to-text route; those
builds identify the provider in-app before audio is sent. Alune does
not retain audio or transcripts on its servers.
-
Subscription management: Alune uses RevenueCat to
manage in-app purchases and subscriptions. RevenueCat receives your
anonymous App Store purchase receipts and a randomly generated
anonymous user identifier to verify subscription status. No personal
data such as your name or email is shared with RevenueCat. See
RevenueCat's Privacy
Policy.
-
Apple Ads attribution: If you install Alune after
interacting with an Apple Ads campaign, Apple's AdServices framework may
provide privacy-preserving attribution data such as campaign, ad group,
keyword, country, and conversion type. Alune sends the attribution token
to RevenueCat so we can understand whether Apple Ads lead to purchases.
This is not used to display ads in Alune, fingerprint your device, or
track you across apps or websites owned by other companies.
-
Advertising measurement (Meta): Alune includes the
Meta (Facebook) SDK to measure the performance of our advertising
campaigns on Facebook and Instagram. With your permission, requested
through Apple's App Tracking Transparency prompt, Alune shares a device
advertising identifier and an anonymous Meta identifier, together with
conversion events such as beginning a purchase or subscribing, with
Meta (delivered through RevenueCat). This helps us understand which ads
lead to installs and subscriptions and allows Meta to measure and
optimize our campaigns, which may include linking these events to your
Meta account. We never share the content you create in Alune (notes,
journal, habits, medicine and health data, messages, or saved memories)
with Meta. If you decline the tracking prompt, no advertising identifier
is shared; limited aggregated conversion measurement may still occur
through Apple's privacy-preserving SKAdNetwork. See
Meta's Privacy
Policy.
-
Anonymous usage counters: To understand where new
users drop off (for example, how many people reach the subscription
screen), Alune increments anonymous, aggregate counters such as
"onboarding completed" on our server. These counters contain only an
event name, a date, and app version/build. They include no user
identifier, device identifier, or content, and cannot be linked to you.
-
Product analytics (PostHog): Alune enables
privacy-safe product analytics by default and sends usage events (such as static
screen names, feature outcomes, app version, and a random per-install
identifier) to
PostHog, hosted in the United
States. Alune does not send screenshots, session replays, touch
coordinates, view hierarchies, or typed text to PostHog. These events
can include static screen and action tokens, feature outcomes,
failure-stage categories, bounded operation counts, and timing
measurements. They never include text you enter, transcripts, AI
responses, titles, tool arguments, calendar or reminder contents,
native item identifiers, or free-form error messages. These analytics
use a pseudonymous random per-install identifier, not your
name, email, account, advertising identifier, or content. They are
never used for advertising and are never sold. Where applicable, Alune
processes these events for its legitimate interests in understanding
feature adoption, diagnosing reliability and performance, and improving
the App. You may object at any time by tapping Turn Off Usage
Analytics at the bottom of the in-app Privacy Policy. This does
not remove or limit any App feature.
Your AI choice
Before Alune sends any Assistant text, relevant planner item, or voice
recording to the processors described above, the App identifies the data
and providers and asks for your explicit permission. You may decline or
turn off the Assistant later in Settings without losing Alune's non-AI
features. Product analytics is separate from this AI permission and does
not include your Assistant or planner content.
Third-party AI providers
The third-party services that process content on Alune's behalf are
listed below. Alune never sells your data, and never shares the content
you create (notes, journal, habits, medicine and health data, messages,
or saved memories) for advertising or model training. (Separately, with
your App Tracking Transparency consent, Alune shares advertising
identifiers and subscription conversion events with Meta for advertising
measurement, as described under "Advertising measurement (Meta)" above.)
Alune uses these providers only where their
processing commitments provide protection equivalent to this policy for
the data they receive, including encrypted transport, no advertising use,
no model training on your AI request content, and the zero-retention or
no-retention commitments described above:
-
OpenRouter, AI request
routing for the Assistant. OpenRouter receives Assistant text and
model-visible tool results routed through the Supabase proxy.
-
Google, runs Gemini
models through a Zero Data Retention Google Vertex route for
Assistant replies. Google receives the Assistant request routed through
OpenRouter.
-
ElevenLabs, runs the
Scribe v2 model for voice-to-text. ElevenLabs receives microphone audio
only when you use voice input.
-
OpenAI, runs
speech-to-text and realtime transcription for Alune builds or settings
that use the OpenAI voice route. OpenAI receives microphone audio only
when you use voice input.
-
Supabase, hosts the
request-routing edge functions for AI chat and voice transcription and
stores only anonymous request counters used to enforce daily limits.
Device Permissions
Alune may request the following permissions, each used solely for the
stated purpose:
-
Calendar & Reminders, to display your schedule and
create events or reminders on your behalf.
-
Microphone, to enable voice dictation so you can speak
instead of type.
-
Notifications, to send local habit reminders at times
you choose. No push notifications are sent from any server.
You can revoke any permission at any time in iOS Settings.
AI Assistant Limits
-
Free access: Free users receive a limited allowance
for Quick Add, voice transcription, and Alune AI. Current limits are
shown in the app. Failed, cancelled, clarification-only, and duplicate
operations do not consume a successful use.
-
Pro subscribers: Assistant is included with up to
150 chat messages and 300 voice transcriptions per day (or the
limits shown in the app).
-
We may adjust daily limits for security, stability, or fair use.
Current limits are always described in the app.
Third-Party Services
Alune does not display ads inside the app and does not use cookies. To
measure the performance of our advertising campaigns, Alune includes the
Meta (Facebook) SDK, which, with your App Tracking Transparency consent,
shares device advertising identifiers and subscription conversion events
with Meta as described under "Advertising measurement (Meta)" above. Aside
from that advertising measurement, the only other third-party services are
those described above (AI processing via OpenRouter and Google, voice via
ElevenLabs or the internal-Beta OpenAI route, subscription management via
RevenueCat, privacy-safe product analytics via PostHog, and Apple Ads
attribution through Apple's AdServices framework and RevenueCat).
Data Retention & Deletion
All personal data (habits, goals, journal entries, notes, medicine logs,
and reading lists) is stored exclusively on your device. Alune does not
maintain any server-side copy of this data.
-
Delete all data: To delete all your data, simply delete
the Alune app from your device. All locally stored data will be removed
immediately.
-
AI conversations: Message text sent to the AI assistant
is routed only through providers with Zero Data Retention agreements
and is not retained after processing. Alune keeps only anonymous quota,
security, and privacy-safe operational records as described above.
Conversation history stored on your device is deleted when you delete
the app.
-
Voice recordings: Alune does not store audio on its
servers. ElevenLabs transcription uses Zero Retention Mode. OpenAI
batch transcription has no abuse-monitoring retention; OpenAI realtime
transcription may be retained by OpenAI for up to 30 days solely for
abuse monitoring unless Zero Data Retention is enabled for Alune's
account. Voice API audio is not used for advertising or model training.
-
Subscription data: Anonymous purchase receipts held by
RevenueCat are subject to
RevenueCat's data
retention policy. You may contact RevenueCat directly to request
deletion of your anonymous receipt data.
-
Product analytics: Tapping Turn Off Usage Analytics at
the bottom of the in-app Privacy Policy stops future collection and
removes Alune's queued local PostHog data and random installation
identifier. PostHog is configured to retain delivered event data for 12
months; contact Alune support to request deletion where applicable.
To request deletion of any data associated with your use of Alune, contact
us at [email protected].
Children's Privacy
Alune is not directed at children under 13. We do not knowingly collect
information from children.
Changes
We may update this policy from time to time. Any changes will be reflected
in the app with an updated effective date.
Contact
If you have questions about this policy, please contact us at
[email protected].