Transparency and terms

UNTIL privacy notice

Local data, expiry, sharing and user control in UNTIL.

Version, effective date and scope identify the text that applies.

1. Scope and contacts

This notice applies to the UNTIL iPhone app, including the Share Extension and widgets supplied with the app. The person responsible for the product and the privacy contact is Davide Mori, promoter of the independent RelaunchLab project.

For privacy questions: privacy@relaunchlab.it. For support: support@relaunchlab.it.

2. Summary

UNTIL processes content on the user’s device. It does not create accounts or remote identifiers, has no backend, does not synchronise content and does not integrate analytics, advertising, tracking, remote crash reporting or third-party SDKs. Saved content is not transmitted to Davide Mori or RelaunchLab.

Content leaves the UNTIL boundary only when the user chooses to export or share it through iOS functions.

3. Content processed locally

Depending on the functions selected, UNTIL may retain text, URLs, photographs, QR codes or barcodes, measurements, tickets, PDFs, documents, titles, expiry dates, thumbnails and preferences. These data are processed to display, organise, protect, remind and delete temporary items according to the user’s choices.

  • Selected Photos and Files are copied into the app container: the original is not changed or deleted.
  • Where the format and re-encoding path allow it, imported images are re-encoded to remove GPS, EXIF and IPTC metadata; thumbnails are generated from decoded pixels.
  • The clipboard is read only after an explicit “Paste” action.
  • The app does not access contacts, calendars, location, the microphone or the full Photos library, and it does not automatically open URLs or decoded values.

4. Permissions and iOS functions

  • Camera: requested in the context selected by the user to capture or scan content.
  • Local notifications: disabled by default and for each individual item; permission is requested only after a reminder has been selected. The text is generic and no remote push notifications are used.
  • Device authentication: the optional lock uses Face ID, Touch ID or the device passcode through the Apple system. UNTIL receives only the authentication result and does not access or retain biometric templates or its own PIN.
  • Widgets: Lock Screen widgets are generic; Home Screen previews depend on a separate setting and use the available redaction protections. iOS controls widget caches and update timing, so the immediate removal of every system-managed copy cannot be guaranteed.

5. Protection, backups and logs

Metadata, attachments, thumbnails, transaction journals, sharing packages and private snapshots use complete file protection. The generic state needed by widgets does not contain titles, text, URLs, file names, decoded values or images. The interface is covered when the app becomes inactive to reduce exposure in multitasking snapshots.

UNTIL configures its data roots so that they are excluded from system backups and does not integrate iCloud, CloudKit or other synchronisation functions. A file exported to Files, iCloud Drive or another app instead follows the settings and privacy rules of the destination.

Local logs contain only fixed operation names and error types: they do not include titles, text, URLs, decoded values, file names, UUIDs or paths and are not transmitted by UNTIL.

6. Retention and deletion

  • An active item remains available until the expiry selected by the user; an item the user chooses to keep remains until it is deleted or a new duration is set.
  • After expiry, an item remains recoverable for 24 elapsed hours. After that window it is no longer displayed and the physical copy is removed at the next execution opportunity allowed by iOS; the operating system does not guarantee execution at an exact time.
  • Manual deletion starts removal of the UNTIL copy. If protected files are temporarily unavailable, the operation remains local and is retried without making the content visible again.
  • Corrupted import packages or journals are isolated in a protected area and removed after 30 days during the next successful maintenance operation.
  • Temporary files abandoned during capture or import are normally removed after approximately one hour; an incomplete sharing session may remain for up to 24 hours to allow recovery.
  • A small technical receipt containing no content, consisting of local identifiers and the import date, remains on the device after a completed import to prevent the same package from being imported again. It has no automatic expiry and is removed with the app data.

Uninstalling the app asks iOS to remove the associated container. UNTIL does not promise sector-by-sector secure physical deletion and cannot control copies already exported or caches managed by the system.

7. Apple and platform data

Apple independently processes the data necessary for distribution, the App Store and operation of the system under its own terms. If the user has enabled the sharing of analytics and diagnostics with developers, Apple may make aggregated statistics or technical reports available; those data are collected by Apple, not by a telemetry component in UNTIL. Content saved in UNTIL must not be included in the app’s logs.

8. Support and data submitted voluntarily

UNTIL does not automatically transmit data to the controller. If the user voluntarily submits a support request through the website, the email address, app, category, description and any app and iOS versions are processed; attachments are not accepted. Do not submit items stored in the app, credentials or unnecessary sensitive data.

The controller for this processing is Davide Mori. The purpose is to manage the request connected with the app, on the basis of Article 6(1)(b) GDPR, and to protect the channel against abuse on the basis of Article 6(1)(f). Data are accessible to authorised persons and to Aruba S.p.A. for hosting, database and email services when enabled; they are not sold or used for marketing. Identifying data and the message are redacted 12 months after the last activity; only the technical trace described in the website privacy notice remains, which supplements this section in relation to security, recipients, transfers and rights.

9. Rights

Because content remains on the device and cannot be accessed remotely, Davide Mori cannot view, identify, extract or delete it on the user’s behalf. Management, export and deletion are carried out through the app’s local controls. No additional identifiers are collected solely to respond about data that the controller does not possess.

For data actually received through support, the rights described in the website privacy notice remain exercisable and a complaint may be lodged with the Italian Data Protection Authority.

10. Children, automated decisions and updates

UNTIL is a utility for a general audience, is not designed specifically for children, does not ask for age and does not carry out automated decision-making or profiling. The app does not use consent as a legal basis for transmitting personal data because it does not carry out such transmissions.

The introduction of networking, accounts, cloud services, new SDKs, analytics or recipients will require a new assessment and updates to this policy, the privacy manifests and the App Store declarations before distribution.

Have a question?

Need clarification about this document?

Contact RelaunchLab