Privacy Policy
Last updated: 11.08.2026
Effective: 11.08.2026
1. The short version
Cookie Jar does not collect your personal data.
There are no accounts, no sign-up, and no login. We run no servers. The App contains no analytics, no advertising, no tracking, and no third-party data-collection tools. What you write stays on your device and, if you use iCloud, in your own private iCloud account — where we cannot see it.
The rest of this document explains that in detail, because you deserve specifics rather than a promise.
2. Who is responsible
Cookie Jar is published by “Plumya” Tomasz Milczarek, Warsaw, Poland. For any question about this policy, contact hello@cookiesjar.app.
Where the GDPR applies, we are the data controller for the App — but as set out below, the App is designed so that we hold no personal data about you at all.
3. What the App stores, and where
3.1 Your achievements
Everything you create in Cookie Jar consists of:
- the text note you write on each cookie,
- the appearance of each cookie (dough type, chip style, size, and position),
- the jars you create, their shape, and the labels you give them.
This is stored in two places:
On your device. A local database inside the App's own storage area, protected by iOS app sandboxing and by your device passcode and encryption.
In your private iCloud database. If you are signed in to iCloud and have iCloud enabled for Cookie Jar, iOS syncs that data to a CloudKit private database belonging to your Apple Account, so your jars appear on your other devices.
The word private is technical, not marketing. A CloudKit private database is scoped to the end user's Apple Account. We, as the developer, have no credentials, no dashboard, and no API that would let us read, list, export, or restore its contents. We do not receive a copy. We could not hand your notes to anyone even if compelled, because we do not have them.
Apple processes that data under Apple's Privacy Policy and the iCloud terms, and it counts against your iCloud storage.
3.2 Your settings
The App stores a small number of preferences locally on your device, using the standard iOS preferences store:
| What | Why |
|---|---|
| Whether reminders are on | To respect your choice |
| How many reminders per day (1–3) | To schedule the right number |
| Whether the intro screen has been shown | So it appears only once |
| A one-time data-repair marker | To avoid re-running a fix for duplicated jars |
None of this identifies you. None of it is transmitted anywhere.
3.3 What is not stored
The App does not collect, and has no code capable of collecting: your name, email address, phone number, Apple Account identifier, contacts, location, photos, health data, advertising identifier, device fingerprint, IP address, crash logs sent to us, or any usage or behavioural analytics.
4. We operate no servers
Cookie Jar makes no network requests to any infrastructure we own or rent, because we own and rent none for this app. There is no backend, no API, no database of users, and no log file with your activity in it.
The only network activity the App performs is:
- iCloud sync, handled entirely by iOS between your device and Apple.
- Loading this policy and the Terms of Service, described in Section 5.
5. Viewing this policy inside the App
When you open the Terms of Service or Privacy Policy from the App's Settings screen, the App displays the document in an embedded web view, which fetches it from our hosting provider.
Like any web request, this means the hosting provider's servers receive your IP address, the time of the request, and your device's user-agent string, and may keep them in standard server logs for a short period for security and operational purposes. We do not use those logs to identify you, we do not combine them with anything else, and we place no cookies, pixels, fonts, scripts, or trackers on those pages. The pages are static and self-contained.
If you would rather not make that request at all, simply don't open those two screens — the App works identically without them.
6. Notifications
If you allow notifications, the App schedules up to three reminders per day at fixed times, using iOS's local notification system.
These are local notifications. They are composed and delivered on your device by iOS. No server is involved, we send you nothing, and no push service of ours receives your device token or your notification content.
Reminder text quotes an achievement you have written, so your notes can appear on your Lock Screen and in your iOS notification history. If your device shows notification previews while locked, anyone looking at your screen could read them. You can turn reminders off at any time in the App's Settings screen, or restrict previews in iOS Settings → Notifications → Show Previews.
The App also requests the "remote notification" background capability. This exists solely so iOS can wake the App when iCloud has new data to sync. It is not used to send you marketing or messages.
7. Purchases
If you buy an in-app purchase, the transaction is handled entirely by Apple through the App Store. We never see or receive your card number, billing address, or any other payment details. Apple provides us only with aggregated, anonymised sales and download figures through App Store Connect, which cannot be traced back to an individual.
Apple's own collection of data in connection with your App Store account is governed by Apple's Privacy Policy, not by this one.
8. Purchase management provider
To validate purchases and remember that you have unlocked paid functionality, the App uses RevenueCat, Inc. as a service provider.
When you make or restore a purchase, RevenueCat receives a randomly generated identifier that we use to recognise your purchase, together with your App Store receipt and basic technical details such as device model, operating system version, and country. It does not receive your name, your email address, your Apple Account, or anything you have written in the App.
RevenueCat processes this on our behalf as a data processor under a data processing agreement, and may transfer it to the United States under the applicable EU standard contractual clauses. See the RevenueCat Privacy Policy.
The legal basis for this processing is the performance of our contract with you (Article 6(1)(b) GDPR) — we cannot deliver a purchase you have paid for without a way to verify it.
9. Legal bases for processing
Where the GDPR applies and processing occurs at all, we rely on:
- Performance of a contract (Art. 6(1)(b)) — providing the App's functionality and honouring purchases.
- Consent (Art. 6(1)(a)) — for notifications, which you grant through the iOS permission prompt and can withdraw at any time in Settings without affecting anything else.
- Legitimate interests (Art. 6(1)(f)) — for the short-lived server logs described in Section 5, in the interest of keeping our hosting secure and available.
10. Retention
Your achievements are kept for as long as you keep them. We apply no retention period, because we hold nothing to retain.
- Deleting a cookie or a jar removes it immediately and permanently, including from iCloud once sync completes. There is no undo and no archive.
- Deleting the App removes the local copy from that device. It does not delete the copy in your iCloud account.
- To remove the iCloud copy, go to iOS Settings → your name → iCloud → Manage Account Storage, find Cookie Jar, and delete its data.
11. Your rights
Where the GDPR or similar laws apply, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent.
Because we hold no personal data about you, we cannot fulfil these requests in the usual way — there is no record for us to look up, correct, or delete. Instead, you exercise them directly, and completely, using the controls described above:
- Access and portability — everything is visible in the App on your device.
- Rectification — edit or delete any cookie or jar at any time.
- Erasure — delete the App and remove its iCloud data as described in Section 10.
- Withdrawing consent — turn off notifications in the App or in iOS Settings.
For data Apple holds in connection with your Apple Account and iCloud, contact Apple through privacy.apple.com.
If you believe your rights have been infringed, you may lodge a complaint with your local data protection authority. Ours is "Prezes Urzędu Ochrony Danych Osobowych (UODO)".
12. International transfers
We transfer nothing internationally, because we receive nothing. Any transfer of your iCloud data between Apple's data centres is carried out by Apple under its own safeguards and privacy policy.
13. Security
Your data is protected by iOS app sandboxing, by device encryption tied to your passcode or biometrics, and — for the iCloud copy — by Apple's CloudKit security and your Apple Account credentials. We recommend keeping a device passcode enabled and using two-factor authentication on your Apple Account.
No system is perfectly secure. Because we store nothing, a breach of our systems cannot expose your achievements; the meaningful risks are physical access to an unlocked device and compromise of your Apple Account.
14. Children
Cookie Jar is not directed at children under 13, and we do not knowingly collect personal data from anyone. Since the App collects no data at all, it cannot collect a child's data. Parents who wish to restrict use can do so with iOS Screen Time.
15. Changes to this policy
We may update this policy when the App changes or the law does. The current version is always available in the App's Settings screen and at the address where you are reading it. Where a change is material — in particular if a future version begins collecting data it does not collect today — we will make it visible in the App before the change takes effect.
The "Last updated" date at the top always reflects the current version.
16. Contact
“Plumya” Tomasz Milczarek, Warsaw, Poland
Terms of Service: https://statuesque-coyote-456.notion.site/Cookies-Jar-App-3b7bea29e5b68077af4df5c52c8262ce