The short version
The Nut Tracker keeps what you log on your phone. Not on a server, because there is not one. There is no account, so there is nothing with your name on it.
We never see what you log. Not the count, not the rating, not the tags, not the mood, not your notes, not your Partner Book, not the times of day. None of it reaches us, and none of it reaches anyone else, unless you deliberately share it yourself.
Two things do leave your phone in the public version of the app, and both are optional and anonymous: crash reports, and a short list of usage events such as “a log was created”. Never what was in it. You can turn both off in Settings, Privacy.
Nut Pro is paid for through the App Store or Google Play. They handle your payment. We only learn that an anonymous install has an active plan, never your name or your card.
This website keeps it short too. Our host keeps basic server logs for a little while. Google Analytics only loads if you click Accept on the cookie banner. If you reject it or ignore it, the analytics script never loads.
No ads. No ad networks. We do not sell data. We could not sell your logs if we wanted to, because we do not have them.
The rest of this page is the detail, because the short version is not a legal basis.
1. Who we are
The Nut Tracker and thenuttracker.com are made by Kallos Labs LLC (“we”, “us”). For data protection purposes Kallos Labs LLC is the controller of the small amount of data described in sections 4, 10 and 11.
Registered address: [CONFIRM] Dima to insert the registered address for Kallos Labs LLC.
Contact for anything on this page, including a privacy request: support@thenuttracker.com
EU and UK representative under Article 27 of the GDPR: [CONFIRM] Dima to confirm with counsel whether one is required and, if so, to name them here.
Data protection officer: none appointed. [CONFIRM] that this is correct for the scale of processing, which we believe it is.
2. Who this app is for
The Nut Tracker is for adults only. You must be 18 or over to use it. The app asks you to confirm this before it lets you do anything, and the terms prohibit use by anyone under 18.
We do not knowingly collect any data from anyone under 18. We could not identify a user under 18 from the anonymous data we receive, which is why the age gate and the terms do that job instead. If you believe a minor is using the app, email us and we will act on it, although in practice the remedy is on the device: deleting the app removes everything.
See section 15.
3. What the app stores, and where
Everything you create in The Nut Tracker is written to a local SQLite database on your device, inside the app’s own private storage. The operating system prevents other apps from reading it. It is included in your device backup if you have one enabled, which is your backup, held by Apple or Google under their terms, not ours.
This is what lives there:
| What | Detail |
|---|---|
| Your logged entries | Date and time, count, optional rating, optional duration, optional mood, optional tags |
| Squirrel Thoughts | Your private free text note on an entry. Encrypted at rest. |
| The Partner Book | An optional nickname you give a partner and its own rating. Encrypted at rest. Off by default. |
| Dry Days | Entries that record that nothing happened, so a gap is not mistaken for a forgotten day |
| Your streaks, badges, quests, ranks and Acorn balance | Calculated on your device from the entries above |
| Your settings | Mode, chosen mascot, reminder times, app lock preference, the two toggles in section 5 |
| Your consent record | That you confirmed you are 18 or over, that you gave the consent in section 6, which version of the wording you saw, and when |
The encryption on your notes and your Partner Book uses a key held in your device’s secure keychain, which the app cannot export and we never see.
None of this is transmitted to us. There is no sync, no upload, no cloud copy, and in version 1.0 no server at all. If you put your phone in airplane mode, logging works exactly the same.
4. What leaves your device
Two optional streams, both off in development builds and both switchable in the released app, plus the purchase records described in section 10. None of them ever carries the content of a log.
4.1 Crash reports
Processor: Sentry (Functional Software, Inc., trading as Sentry).
When the app crashes, we receive a stack trace so we can fix it. Specifically: the error type and message, the code path that failed, the app version, your operating system version and your device model.
We have deliberately turned off everything Sentry can optionally attach:
- No screenshot of the app at the time of the crash.
- No view hierarchy, which could otherwise carry text that was on screen.
- No console logs, which could otherwise echo a rating or a note.
- No network request or response bodies.
- No IP address and no personal identifiers.
- No performance traces.
4.2 Usage events
Processor: PostHog (PostHog, Inc.).
A short, fixed list of events telling us that something happened, never what it contained. The complete list, which is enforced in the code and cannot be added to at runtime:
app_opened, onboarding_started, onboarding_step_completed,
onboarding_completed, age_gate_passed, age_gate_failed, mode_selected,
reminder_permission_result, app_lock_enabled, app_lock_disabled,
log_created, log_updated, log_deleted, screen_viewed, badge_unlocked,
settings_changed, export_started, data_wiped.
[CONFIRM] The list above has no paywall or purchase events. If events such as a paywall view or a trial start are added to the allowlist in the app, they must be listed here before that build ships.
log_created means a log was created. It does not carry the rating, the tags,
the mood, the note, the duration, the partner nickname or the time of the entry.
None of the Partner Book can reach an event, by construction.
Session recording, screen recording, automatic tap capture and rage click detection are all turned off. A screen recording of this app would be the exact thing we promise not to collect.
PostHog assigns your installation a random identifier so that repeat events from the same device group together. It is not your name, your email or your advertising ID, and we never connect it to anything. IP based location lookup is disabled.
4.3 That is the whole list
No advertising SDK. No attribution or install tracking SDK. No Facebook, Google or TikTok SDK in the app. No location. No contacts. No camera, photo library or microphone. No Apple Health or Health Connect. No push notification server: your reminders are scheduled locally by your own phone.
5. Your two toggles
Settings, Privacy:
[CONFIRM] These two toggles and the Withdraw consent control below are not in the app build as of 24 September 2026. They must ship before launch, because consent has to be as easy to withdraw as to give.
- Crash reports. Turns section 4.1 on or off.
- Anonymous usage data. Turns section 4.2 on or off.
Turning either off takes effect immediately and nothing further is sent. Neither toggle depends on whether you have a subscription.
[CONFIRM] Dima to decide the default state for users in the EU, the UK and Switzerland. Recommendation: both toggles default to off in those territories and are offered as a clear opt in during onboarding, and default to on elsewhere with a visible toggle. Defaulting analytics on for EU users is a consent question that is cheaper to avoid than to argue about, and the volume we lose is small.
6. Legal bases, and the special category question
This section applies if you are in the EU, the EEA, the UK or Switzerland. It is useful reading anywhere.
Information about a person’s sex life is a special category of personal data under Article 9(1) of the UK and EU GDPR. Your logged entries are exactly that.
The app asks for your explicit consent before you can log anything, on its own screen, after the age gate and separate from accepting the terms. That consent is our lawful basis under Article 9(2)(a) for storing that information on your device, together with Article 6(1)(a).
We keep a record of that consent on your device: that it was given, which version of the wording you saw, and when. We keep it on your device because your device is the only place the processing happens.
The other bases we rely on:
| Processing | Legal basis |
|---|---|
| Crash reports and usage events from the app (section 4) | Your consent, Article 6(1)(a), given and withdrawn through the toggles in section 5 |
| Checking whether your install has an active plan (section 10) | Performance of the contract you entered into when you bought Nut Pro, Article 6(1)(b) |
| Website server logs kept by our host (section 11.2) | Our legitimate interests in delivering the website and keeping it secure, Article 6(1)(f) |
| Google Analytics on the website (section 11.3) | Your consent, Article 6(1)(a), given by clicking Accept on the cookie banner |
| Answering your emails | Our legitimate interest in answering you, Article 6(1)(f), and our legal obligations where your email is a statutory request, Article 6(1)(c) |
None of the streams in that table contains special category data, because none of them ever carries the content of a log.
You can withdraw your consent at any time, and it is as easy as giving it was:
- In the app: Settings, Privacy, Withdraw consent. Withdrawing deletes everything the app holds.
- For the app’s crash reports and usage events: turn the toggles in section 5 off.
- For website analytics: the “Cookie settings” link in the website footer. See the cookie policy.
Withdrawal does not make the processing before it unlawful, which in practice means very little, because after an in app withdrawal there is nothing left.
7. Sharing, or rather not sharing
We do not sell your data. We do not share it with advertisers, data brokers, insurers or anyone else. There is no advertising in The Nut Tracker on any tier, and there never will be.
The only third parties who process anything on our behalf, as our processors under contract and only for the purposes described on this page:
| Who | What for | Section |
|---|---|---|
| Sentry (Functional Software, Inc.) | App crash reports | 4.1 |
| PostHog, Inc. | Anonymous app usage events | 4.2 |
| Our in app purchase provider [CONFIRM] | Checking and restoring your Nut Pro entitlement | 10 |
| Vercel Inc. | Hosting the website | 11.2 |
| Google (Google Analytics 4) | Website analytics, only after you accept | 11.3 |
[CONFIRM] No purchases SDK is installed in the app yet. The product plan names RevenueCat. Replace “our in app purchase provider” with the provider’s legal name once it is integrated, and add it to the Apple privacy label and the Play data safety form.
Apple and Google process your payment for Nut Pro as the sellers of record, under their own privacy policies, not as our processors. See section 10.
We would disclose data if we were legally compelled to. We would have almost nothing to give: anonymous crash traces, anonymous event counts, anonymous entitlement records and short lived website logs. Your logged entries are not ours to hand over.
If Kallos Labs LLC is ever sold or merged, the same applies. There is no database of user logs to transfer.
8. Sharing you choose to do
Some things you do deliberately send data out of the app. These are the only ones:
- Share cards. You can generate an image of a statistic, such as your current streak, and share it wherever you like. It carries no note text, no partner nickname, no exact timestamp and no location. Once you have shared it, where it goes is up to the app you shared it into.
- Export. You can export your whole history as JSON or CSV. The exported file is yours. The Partner Book is excluded unless you explicitly opt in to including it.
- Emailing us for support. Whatever you put in that email, we read. Please do not paste your log history into it.
9. Partner sharing, which does not exist yet
We are planning an optional partner sharing feature for a future version. It is not in the app today.
When it arrives it will be strictly opt in, it will require both people to accept a pairing, and it will be revocable in one tap from either side. If it ships, a partner would see only a count, a streak or dry spell, and daily entries with rating and tags.
Your notes and your Partner Book would never be part of it. They are excluded from any sync path in the code by construction, not by a setting that could be flipped.
That feature will require an account, which will mean a server, which will mean this policy changes. We will tell you before it does, and we will ask for consent again rather than assuming the consent you gave today covers it.
10. Subscriptions and purchases
Nut Pro and the optional cosmetic packs are sold through the App Store or Google Play. The plans and prices are in the subscription terms.
The store handles the payment. Your card, your billing address and your Apple ID or Google account details stay with Apple or Google. We never receive them. Apple and Google act as independent controllers for that data under their own privacy policies.
What we, or our in app purchase provider, receive so the app knows whether to unlock Nut Pro:
- An anonymous app user identifier, generated for the purchase system. It is not your name, your email or your store account, and it is not linked to your logged entries or to the PostHog identifier in section 4.2.
- Your entitlement status: which plan or pack is active, and when it started, renews or ends.
- Store transaction identifiers and the product bought, so a purchase can be verified and restored.
We do not receive card numbers or any other payment details, and nothing you log is ever part of a purchase record.
[CONFIRM] Dima to confirm with the chosen provider exactly which fields it stores (for example country, currency, price paid, and the IP address of the request that checked the entitlement) and for how long, and to list them here.
Restoring a purchase asks the store for your purchase history and checks it again. It restores your plan. It cannot restore your logged entries, because those were never anywhere but your device.
11. The website
This section covers thenuttracker.com, including its articles.
11.1 What the website collects
There are no accounts, no forms and no waitlist on the website. You cannot type anything into it that is sent to us. To contact us you email support@thenuttracker.com, and section 8 applies to that email.
What the website does collect is limited to the server logs in section 11.2 and, only if you accept, the analytics in section 11.3.
11.2 Hosting and server logs
Processor: Vercel Inc., which hosts the website.
Like every web server, Vercel records each request so it can deliver the page and protect the site from abuse: your IP address, your browser’s user agent string, the page or file requested, the time, and the response. These logs are held by Vercel for a short period and then deleted. We use them only to run and secure the site, and we do not combine them with anything else.
[CONFIRM] Dima to check the log retention period on the Vercel plan in use and state it here, and to confirm that Vercel Web Analytics and Speed Insights are not enabled.
[CONFIRM] Article images may be served from the storage bucket of the content database that holds the articles (Supabase). If they are, that provider also sees the IP address of a browser loading an image, and it should be named in this section and in section 7.
11.3 Google Analytics, only with your consent
We use Google Analytics 4 to understand which pages people read, so we know which articles are useful. It is set up like this:
- Nothing loads until you click Accept. The site uses Google’s Consent Mode v2 with all storage denied by default. If you click Reject, or close the banner, or ignore it, the Google Analytics script is never loaded.
- We honour Global Privacy Control. If your browser sends a GPC signal we treat it as a Reject and do not load analytics.
- What it collects, once you accept: pages viewed, how you arrived (for example the referring site), approximate location derived from your IP address, device type, browser and screen size, and basic engagement such as time on page. Google Analytics 4 does not log or store full IP addresses.
- What it does not do: we have not enabled Google Signals, advertising features, remarketing or data sharing for advertising. We do not use it to identify you and we do not combine it with anything from the app.
- Cookies: it sets
_gaand_ga_<container-id>, each lasting up to two years. The full list is in the cookie policy.
You can change your mind at any time through the Cookie settings link in the website footer.
[CONFIRM] Dima to set the Google Analytics data retention period in the GA4 property (2 months or 14 months) and state it in section 12.
11.4 Your consent choice
Your Accept or Reject is remembered in your own browser’s local storage, under
the key ntt-consent, so we do not ask on every page. It stays until you change
it or clear your browser’s site data. It is never sent to us. See the
cookie policy.
11.5 Articles and links
Articles on the website are general information, not medical advice. See the disclaimer. Links to other websites take you to services with their own privacy policies, which we do not control.
12. Keeping it
Retention on your device. Your entries stay until you delete them. There is no automatic expiry, because a tracker that silently forgets your history is a broken tracker. You are in control of how long it lives. We never delete your data for you, including when a subscription or trial ends, because we never had it.
Crash reports. Sentry holds them for up to 90 days, then they are deleted.
Usage events. PostHog holds the anonymous event records for up to [CONFIRM] 12 months, subject to Dima confirming the retention setting on the PostHog project. After that they are deleted or aggregated beyond identification.
Purchase and entitlement records. Kept for as long as the purchase needs to be verified and restored, and for as long as tax and accounting rules require. [CONFIRM] the provider’s retention period.
Website server logs. Kept by Vercel for a short period, see section 11.2.
Website analytics. Kept in Google Analytics for the retention period set in section 11.3. The cookies themselves last up to two years unless you clear them or withdraw consent.
Support emails. Kept for as long as we need them to deal with your request, and then for no more than [CONFIRM] 24 months, unless the law requires longer.
The anonymous records above cannot be traced back to you individually, so a deletion request for them is one we will honour on a best efforts basis using the device identifier if you can give it to us. In practice, turning the toggles off stops them at the source.
13. Deleting your data
Everything you log can be deleted from inside the app, instantly, without asking us. This works whether or not you have an active subscription or trial. A lapsed subscription never locks you out of your own data.
Deleting one entry. Swipe it in History, or open it and delete. Immediate and permanent.
Deleting the Partner Book on its own. Settings, Privacy, Open the Partner Book, then delete one name or the whole book. It goes without touching the rest of your history.
Deleting everything. Settings, Your data, Delete everything. This drops the local database and the encryption key. It is immediate, it is permanent, and there is no copy anywhere for us to restore, which is the point. Deleting the app from your phone has the same effect, minus the confirmation screen.
Step by step instructions, including withdrawing consent and turning off the two toggles, are on the delete your data page.
Deleting your data does not cancel a subscription. Cancel it in your App Store or Google Play settings, as the subscription terms explain.
14. Your rights
If you are in the EU, the EEA, the UK or Switzerland you have the rights to access, rectify, erase, restrict, object to and port your personal data, and to withdraw consent. If you are in California you have comparable rights under the CCPA and CPRA, including the right to know and the right to delete, and the right to opt out of sale or sharing, which is moot because we do neither: nothing is sold, and nothing is used for cross context behavioural advertising. Residents of other US states with privacy laws have similar rights, and the same answers apply.
Almost all of these are self service and immediate, which we think is better than a form:
| Right | How |
|---|---|
| Access | Settings, Export. Everything, right now, no request needed. |
| Portability | Settings, Export, as JSON or CSV. Both are open formats. |
| Erasure | Settings, Your data, Delete everything. Or delete the app. See delete your data. |
| Rectification | Edit or delete any entry from History. |
| Withdraw consent in the app | Settings, Privacy, Withdraw consent. |
| Restrict or object in the app | Turn off both toggles in section 5, which stops everything the app sends. |
| Withdraw consent on the website | The “Cookie settings” link in the website footer, then Reject. Or send a Global Privacy Control signal. |
| Object to website server logs | Email us. We will consider it against our need to keep the site secure. |
Export and every form of deletion stay available whether or not you have an active subscription or trial.
For anything the app cannot do for you, email support@thenuttracker.com. We aim to answer within 48 hours and will respond substantively within 30 days, which is the statutory window. We may need to ask a question to understand which records are yours, because we hold nothing that identifies you by name.
You also have the right to complain to your data protection authority. In the UK that is the Information Commissioner’s Office. In the EU it is the supervisory authority where you live.
15. Children
The Nut Tracker and this website are not for anyone under 18. We do not knowingly collect data from children, and the app is rated 18+ on the App Store and its equivalent on Google Play.
We do not ask for your date of birth. We ask you to confirm you are 18 or over and we store that confirmation, which is the minimum that does the job.
If you are a parent or guardian and you believe a minor has used the app, email us. The fastest remedy is on the device: open Settings, Your data, Delete everything, then delete the app.
16. Security
- Your database sits in the app’s private storage, which the operating system isolates from other apps.
- Your notes and your Partner Book are encrypted at rest with a key held in the device keychain, protected by Keychain on iOS and the Android Keystore.
- You can turn on app lock, which requires Face ID, Touch ID, your device biometric or your passcode before the app opens.
- The app blurs its contents in the app switcher so a glance does not give you away.
- Notification copy is deliberately discreet and never says what it is about.
- Everything the app or the website sends travels over HTTPS only.
No system is perfect, and the honest version of this section is that the strongest security property of The Nut Tracker is that the sensitive data is not anywhere we could lose it.
17. International transfers
Your logged entries do not cross any border, because they do not leave your phone.
Kallos Labs LLC is based in the United States, and so are the processors named in section 7. The app’s crash reports and usage events, the purchase records, the website’s server logs and the website analytics may therefore be processed in the United States.
Where that involves a transfer out of the EEA, the UK or Switzerland, we rely on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where the recipient is certified under it, and on the relevant standard contractual clauses (with the UK addendum) in our agreements where it is not.
[CONFIRM] Dima to check, for each of Sentry, PostHog, the purchase provider, Vercel and Google, whether it is certified under the Data Privacy Framework or relies on standard contractual clauses in its data processing terms, and to confirm the region setting on the Sentry and PostHog projects and whether an EU region is preferred for PostHog.
18. Changes to this policy
If we change this policy in a way that matters, we will say so in the app before the change takes effect, and we will update the date at the top. If a change widens what leaves your device, we will ask for your consent again rather than treating your silence as agreement. If a change widens what the website collects, we will ask for your consent on the website again.
Previous versions are available on request.
19. Contact
Kallos Labs LLC [CONFIRM] registered address
We aim to answer support and privacy email within 48 hours, and statutory requests within 30 days.