Privacy Policy
Your content belongs to you. Here's how each app handles data.
Last updated: August 19, 2026
Who We Are
Folding Sky Co. is a company based in Nevada, United States of America. We develop applications for iOS and macOS, including Alarmist (LiDAR-powered motion detection), Busybody (website screenshot widgets), Cumbersome (direct API access to AI providers), Dense (widget-first news digests), and Endemic (on-device local LLM chat). The specific data handling and privacy practices vary by app, with details provided in this policy.
What This Policy Covers
This policy explains what information we process, how data flows, and your choices when using our apps and websites. It also applies to future Folding Sky products that link to it. If a product provides an additional privacy notice, that notice controls for the product where it differs from this policy. We will describe materially different data collection before or when it begins. For information about usage rules and restrictions, see our Terms of Service (folding-sky.com/terms).
App-Specific Privacy
Each of our apps has different data handling practices. This section covers the privacy details for each app.
Alarmist
Architecture: Alarmist operates with no Folding Sky backend. All LiDAR motion detection processing happens entirely on your device. LiDAR frames and detection history never pass through Folding Sky's servers. We do not create or manage user accounts.
Data Storage: Settings are stored locally on your device. Detection events (timestamps, detection metrics, and captured photos) are stored on your device using SwiftData. iCloud sync is enabled by default and syncs detection history across your devices through CloudKit using your personal iCloud account. Folding Sky does not operate a backend that reads this data. You can disable iCloud sync at any time in the app's settings to keep new detection history local only. Alarmist also offers configurable auto-retention that deletes old detection events after 30, 60, or 90 days. Uninstalling the app removes local data. Synced data remains in your iCloud container until you remove it through your device's iCloud storage settings.
Silent Detection Mode: Alarmist includes an optional silent detection mode that disables the audible alarm and flashlight while continuing to detect motion, capture photos, and log events. This mode is primarily useful in lighted or dim conditions where the camera can capture a usable image without the flash. It does not record audio or video. You are solely responsible for ensuring that your use of silent detection complies with all applicable laws. See our Terms of Service (folding-sky.com/terms) for important legal requirements.
Permissions: Requires camera/LiDAR access for motion detection. Photos are captured locally; you can optionally save them to your Photos library. Alarmist also requests App Tracking Transparency (ATT) consent on first launch to support ad conversion measurement. You can decline this prompt with no effect on app functionality.
Ad Conversion Tracking: Alarmist uses third-party SDKs to measure the effectiveness of advertising campaigns. These SDKs are used solely for attribution: understanding whether someone who saw an ad went on to install or purchase Alarmist Pro. The SDKs integrated are:
- Firebase Analytics (Google) for Google Ads conversion tracking: policies.google.com/privacy (opens in new tab)
- TikTok App Events SDK for TikTok Ads conversion tracking: tiktok.com/legal/privacy-policy (opens in new tab)
Data collected by these SDKs: Device identifiers (IDFA when you grant ATT consent and a provider can access it, plus pseudonymous app-instance or vendor identifiers), app install events, purchase events (product ID, price, and currency for the Alarmist Pro in-app purchase), and basic engagement data (session starts and user engagement duration).
What we do not do: We do not build user profiles from this data. We do not sell data to third parties. Alarmist does not collect account information such as your name or email, and it does not record audio or video. App functionality is identical regardless of tracking consent.
Other Third-Party Services: All LiDAR motion detection processing uses native iOS capabilities. Alarmist does not use any AI services.
Your Choices: Manage camera and LiDAR permissions in Settings → Privacy & Security → Camera. Choose whether to save captured photos to your Photos library. Enable or disable iCloud sync for detection history in Alarmist's settings. Configure auto-retention to control how long detection events are kept. You can decline the App Tracking Transparency prompt at first launch. If declined, the SDKs cannot access your device's advertising identifier, but they may still process the limited non-IDFA information described above. The app works identically either way.
Busybody
Architecture: Busybody operates with no Folding Sky backend. Website screenshots are captured and stored locally on your device. Your URLs and screenshots never pass through Folding Sky's servers. We do not create or manage user accounts.
Data Storage: URLs, screenshots, site configurations, and most settings are stored locally on your device. Limited preferences, such as appearance settings, may sync across your devices through Apple's iCloud Key-Value Store. Uninstalling the app removes local data. A synced preference may remain in your iCloud account until it is replaced or removed through Apple's controls.
Permissions: No special device permissions required. Screenshots are captured using a standard embedded web browser.
Third-Party Services: Busybody does not use any AI services. It loads third-party websites that you specify directly from your device using an embedded web browser. Those sites receive ordinary web-request information, such as your IP address, browser request headers, and the requested page, under their own privacy policies. Busybody uses a nonpersistent browser data store for screenshot capture. We do not control the sites or their privacy practices.
Cumbersome and Endemic
Cumbersome and Endemic are Folding Sky's AI-powered apps. Neither app has a Folding Sky backend for AI processing. Folding Sky does not see, store, or process your prompts or AI outputs through either app. We do not create or manage user accounts for either app.
Cumbersome (Cloud AI Client): Cumbersome facilitates direct communication between your device and third-party AI providers (OpenAI, Anthropic, Google AI Studio, and others you choose). You provide your own API keys or other authentication values. When you send a message, your prompt text, conversation history, any attached images or files (including filename and file type), model settings, app-authored instructions, enabled tool definitions, and relevant tool calls or results are transmitted directly from your device to the AI provider using your credentials. That conversation content does not pass through Folding Sky servers.
Camera Attachments (Cumbersome): When you choose to capture a photo inside Cumbersome, the app requests camera access and adds the captured image to your pending message. The image is sent to the selected AI provider only if you send that message. If the conversation is saved, the attachment can sync through your personal iCloud account with the rest of the conversation.
Question Cards (Cumbersome): Cumbersome includes a local Question Cards tool. The selected model can call it once per user turn to ask up to three structured questions before answering. The provider receives the tool definition, and the model supplies the question text, choices, and control types. Cumbersome returns your answers, or your decision to skip, to the provider as the tool result. That result can be stored with the conversation. A synced setting controls whether the tool is available. Its instructions say not to request secrets or use the questions to confirm an external action, but model instructions cannot guarantee appropriate questions. Do not enter credentials or other secrets into a Question Card.
Browser and Tool Data (Cumbersome): On iOS 26, iPadOS 26, and macOS 26 or later, Cumbersome provides three local web tools. Local Web Search sends an AI-generated query to a search engine and returns result links and snippets. Local Web Browser loads one page, can run AI-generated JavaScript once, extracts readable content, and then discards that page. Web Agent is a visible browser that keeps page and navigation state for multi-step work in the active chat, including sites you choose to sign into. Availability, settings, and initial defaults vary by app version and can change over time. Search and single-page reading can run without displaying a browser window.
The selected AI provider receives each available tool's description and may generate its search terms, URLs, JavaScript, and other action arguments.
Each Local Web Browser call uses a fresh page and does not preserve an open page or navigation sequence for the next call. WebKit may still retain ordinary website data, such as cookies or cached resources, outside that page's lifetime. Stateless browsing does not mean anonymous or private browsing.
Search engines and websites receive requests directly from your device. They can receive information ordinarily exposed by web requests, such as your IP address, browser request data, cookies or temporary session state, search terms, URLs, and any content included in a submission or other request. Page content, JavaScript results, and other tool results can be returned to the selected AI provider so it can continue the response.
All three tools can process untrusted webpage content. A webpage can contain instructions intended to influence an AI system. In unusual or unintended cases, the model could generate a browser action that sends information from your prompt, conversation, or the current page to another website or service.
If you sign into a site within Web Agent, the AI may be able to inspect information available to that signed-in browser session and run JavaScript in the page. Cumbersome tells the AI not to inspect password, payment, passkey, or authentication fields, but this instruction and provider safeguards cannot guarantee that sensitive information will never be accessed or transmitted.
Web Agent uses a nonpersistent WebKit data store, which keeps its browser data in memory instead of writing it to the persistent browser store. The Web Agent browser session and its temporary state are destroyed when you close it, disable it, or leave the chat. Nonpersistent storage does not prevent a website or the selected AI provider from receiving information while the browser session is open, and closing it cannot retract information already sent.
Remote MCP Servers (Cumbersome and Endemic): Both apps may let you configure remote Model Context Protocol (MCP) servers or similar tool services. When you enable and invoke a remote tool, the app sends tool requests and arguments directly to the server you configured. Those arguments may include information from your prompt, conversation, attachments, or model-generated content when needed for the requested tool. Server results may be added to your conversation and, in Cumbersome, returned to your selected AI provider as tool results. Server configurations may sync through iCloud Key-Value Store, while saved authorization values are stored in Keychain and may sync through iCloud Keychain. Each server's privacy policy governs its processing. Folding Sky does not receive this traffic or control a user-configured server unless we specifically identify it as a Folding Sky service.
Endemic (On-Device Local LLM): Endemic runs large language model inference entirely on your device using local model weights (GGUF format). You may download models from third-party hosts (for example HuggingFace). Network access is required to download models; inference does not require network access after models are downloaded. The download host receives ordinary network-request information, such as your IP address and request metadata. Model files are stored locally on your device and are not synced to iCloud.
Data Storage: Both apps sync via iCloud when available on your device, using separate iCloud containers:
- Credentials: Cumbersome API keys, values for custom-provider authentication headers, and saved remote-tool authorization values are stored in Keychain and may sync through iCloud Keychain when enabled in device settings
- Settings: Provider, model, and eligible tool preferences may sync through iCloud Key-Value Store
- Conversations: Conversation records and message metadata may sync through each app's private CloudKit database when iCloud is enabled
- Attachments and Large Content: Eligible attachments and oversized content may sync as sidecar files through iCloud Drive
- Model Files (Endemic only): Stored locally on your device, excluded from iCloud sync. Uninstalling Endemic removes local model files.
Apple protects iCloud data in transit and at rest. iCloud Keychain is end-to-end encrypted by default. The protection available for other iCloud categories depends on the data category, your region, and whether Advanced Data Protection is enabled for your Apple Account. Folding Sky does not operate a backend that reads your personal iCloud data. Sync happens automatically when the relevant iCloud features are enabled; turn them off in device settings to stop future sync.
Third-Party AI Services (Cumbersome): Each AI provider has its own privacy policy governing how they handle your data. We encourage you to review them:
- OpenAI: openai.com/policies/privacy-policy (opens in new tab)
- Anthropic: anthropic.com/privacy (opens in new tab)
- Google AI Studio: policies.google.com/privacy (opens in new tab)
- OpenRouter: openrouter.ai/privacy (opens in new tab)
- Z.ai: docs.z.ai/legal-agreement/privacy-policy (opens in new tab)
- Vercel AI Gateway: vercel.com/legal/privacy-policy (opens in new tab)
- Ollama: ollama.com/privacy (opens in new tab)
Cumbersome also supports adding custom OpenAI-compatible endpoints. If you connect to services beyond those listed above, your data is subject to the privacy policies of those respective services. Folding Sky does not control and is not responsible for third-party services you choose to connect.
Third-Party Services (Endemic): Model downloads are retrieved directly from third-party hosts. Folding Sky does not control those providers. When you download a model, you are subject to the host's terms and privacy policies.
Consent (Cumbersome): Cumbersome asks for your explicit permission before sending data to each AI provider. This consent is requested when you first add a credential for a provider. You can review the data sharing disclosure and the provider's privacy policy at that time.
Folding Sky does not create accounts for these apps or receive names, email addresses, prompts, AI output, API keys, or other app content. We do not build advertising profiles or sell data. Both apps send limited technical and feature-usage data to Firebase Analytics as described in the Analytics and Technical Data section below.
Security (Cumbersome): API keys and other saved authentication values are stored in device Keychain and may sync through iCloud Keychain when that feature is enabled. Other synced data receives the iCloud protections described above.
Your Choices: In Cumbersome, use or remove AI providers at any time by adding or deleting their credentials. Review and adjust available conversation, web, and data tools in Settings. Manage camera access in your device's Privacy & Security settings. When using Web Agent, review the current site and browser actions, enter credentials yourself, avoid highly sensitive accounts or pages, and close the browser session when you are done. In Endemic, download or delete models through the model management screen. Control iCloud sync via your device's iCloud settings. Turn off iCloud Keychain, iCloud Drive, or sign out of iCloud to keep data local only.
Dense
Architecture: Dense displays pre-generated news digests. Our Google Cloud backend periodically fetches and summarizes public news articles using Google's Gemini AI, then caches the results. The app retrieves these cached digests. It does not send user-created prompts or app-user information to Gemini. We do not create or manage user accounts, and we do not use Dense requests to build user profiles.
No App-User Data Sent to AI: Dense's AI processing is server-side and operates only on public news content. Dense sends our backend the fixed topic or filter needed to retrieve a cached digest. It does not intentionally send account information, user-created content, advertising identifiers, or precise location. Google Cloud and API Gateway process ordinary network and request metadata needed to serve and protect the API, such as IP address, user agent, request path, topic, time, response status, and request identifier. We use this operational data for delivery, security, reliability, and troubleshooting, not to personalize digests or build profiles. This request metadata is not sent to Gemini as model input.
Data Storage: Topic preferences, widget settings, and digest history are stored locally on your device. Limited preferences, such as appearance settings, may sync through Apple's iCloud Key-Value Store. Uninstalling the app removes local app data. Cached digests on the backend are generic, not personalized, and are not linked to accounts.
Permissions: No special permissions required beyond network access for digest updates.
Third-Party Services: Dense uses Google Cloud to host its backend and Google's Gemini AI to generate news digests from public news sources. Scheduled AI processing involves only publicly available news content, not app-user data. The app itself does not communicate with Gemini directly. Google processes backend and AI-service data under its Privacy Policy (opens in new tab) (policies.google.com/privacy) and applicable service terms.
Information You Provide Directly
Support and Feedback: If you email us or send support, feedback, or a privacy request, we receive the contact information, message, attachments, and technical details you choose to provide. We use them to respond, troubleshoot, improve the Services, keep appropriate business records, and protect our rights.
Purchases: Current paid features use Apple's StoreKit. Apple handles your Apple Account and full billing details. Our apps receive purchase information needed to provide and restore access, such as product and transaction identifiers, purchase or expiration dates, entitlement or subscription status, storefront, and price or currency when available. Folding Sky does not receive your full payment-card number.
Analytics and Technical Data
Alarmist, Busybody, Cumbersome, and Endemic currently use Firebase Analytics for product usage or attribution. Dense does not currently include Firebase Analytics. Future products that use analytics will be covered by this section or an additional product notice. We do not use analytics to build advertising profiles or sell analytics data.
Firebase Analytics (Google): Depending on the app, device, SDK configuration, and permission settings, Firebase Analytics may process:
- Pseudonymous app-instance and device or vendor identifiers.
- App version, device model and category, operating system and version, and device language.
- IP address at collection time and approximate geographic information derived from it.
- App opens, session and engagement data, feature interactions, feature outcomes, performance measurements, and purchase metadata where applicable.
Folding Sky does not send names, email addresses, prompts, conversation text, AI responses, API keys, attached-file contents, website content, screenshots, or iCloud data to Firebase Analytics. We do not assign a Firebase user ID tied to a Folding Sky account and do not attempt to identify individual users from analytics data. Google processes this data under its Privacy Policy (opens in new tab) (policies.google.com/privacy).
Firebase Analytics retains user-level and event-level data under Google's retention controls for up to 14 months. Aggregated reports may remain available longer.
Why We Process Information
We process information to provide requested app and website functions, complete and restore purchases, answer support requests, secure and troubleshoot our Services, measure reliability and feature use, comply with law, and enforce our Terms. Where applicable law requires a legal basis, we rely on performance of a contract or steps you request, our legitimate interests in operating and securing the Services, consent where requested (including ATT), and compliance with legal obligations. You may withdraw consent at any time, but withdrawal does not affect earlier lawful processing.
Data Sharing
We do not sell or rent personal information. We disclose information only as described in this policy: to Apple for StoreKit and iCloud features; to Google for Firebase Analytics and Dense's Google Cloud and Gemini services; to TikTok for Alarmist attribution; to providers, websites, model hosts, search engines, or remote tool servers that you direct an app to contact; to professional advisers and authorities when legally necessary; and in a business change described below. Each recipient processes information under its own terms or our applicable service agreement.
Data Retention
Local and iCloud data remains until you delete it, an app's configured retention rule removes it, or Apple removes it under your settings and its policies. Firebase user-level and event-level data is retained for up to 14 months, while aggregate reports may remain longer. Dense API logs, website hosting logs, and other operational records are kept only as long as reasonably needed for security, reliability, troubleshooting, legal obligations, or the provider's configured retention period. We retain support and privacy-request correspondence as long as reasonably needed to respond, keep necessary business records, resolve disputes, and comply with law. Apple controls retention of App Store billing records.
Legal Requests and Safety
We may preserve and disclose information if we believe it is reasonably necessary to comply with law, regulation, legal process, or governmental request; to enforce our terms; or to protect the rights, property, or safety of Folding Sky Co., our users, or the public. For apps without backend servers (Alarmist, Busybody, Cumbersome, Endemic), we do not possess or have access to user content stored locally on devices or in users' personal iCloud accounts.
Business Changes
If we are involved in a merger, acquisition, reorganization, financing, bankruptcy, or sale of assets, information we hold may be transferred as part of that transaction. We will continue to protect it consistent with this policy and provide notice where required.
Third-Party Providers
Some of our apps integrate with or facilitate access to third-party providers and services. When you use such providers, your use is governed by their terms and privacy policies. We do not control those services. Review each provider's policies to understand how they handle your data.
Cookies and Website Hosting
Our website and public Folding Sky content endpoints run on Vercel. Vercel Web Analytics (opens in new tab) (vercel.com/docs/analytics/privacy-policy) records page views and related route, referrer, approximate geography, browser, operating system, and device-category information for aggregate reports without third-party tracking cookies. Vercel derives a temporary session hash from the incoming request and says it discards that session information after 24 hours. Vercel's hosting infrastructure may separately process standard request logs, including IP address, user agent, time, and requested path, for delivery, security, and operations. Apps may also request public Folding Sky information or open links to our site, which creates an ordinary web request. Folding Sky does not use this information to build advertising profiles.
Children's Privacy
Folding Sky apps are intended for adult audiences. Cumbersome and Endemic require users to be at least 18 years old. Other current Folding Sky apps (Alarmist, Busybody, Dense) do not impose a specific minimum age beyond applicable law and App Store requirements, but are not designed for, marketed to, or intended for use by children. A future product intended for children will provide any additional notice and consent process required by law.
We do not knowingly collect personal information from anyone under 18 through Cumbersome or Endemic, or from anyone under 13 (or the applicable minimum age in your jurisdiction) through any Folding Sky app. If we learn that we have collected information from a user under the applicable minimum age, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at the address below.
Your Choices
- Use each app's deletion and reset controls before uninstalling when available. Uninstalling removes the app's local container, but Keychain values and data or preferences synced to iCloud may remain. Delete those through the app before uninstalling or through your device's Keychain and iCloud controls where available.
- Manage app settings and permissions on your device. Alarmist lets you disable detection-history sync and configure auto-retention.
- Decline or revoke Alarmist's App Tracking Transparency permission in Settings → Privacy & Security → Tracking to prevent access to your device's advertising identifier. Limited non-IDFA analytics or attribution data may still be processed.
- Manage subscriptions and request eligible refunds through Apple. Deleting an app does not cancel its subscription.
- Dense's backend caches generic news digests that are not linked to accounts. There is no personalized digest profile to delete.
Security
We implement security measures appropriate to each app. Where applicable, we design apps to minimize data exposure and use secure storage mechanisms. You are responsible for protecting access to your devices and any credentials you use with our apps. No method of transmission or storage is 100% secure. Use our apps at your own risk.
Your Rights
Depending on where you live and the information at issue, you may have rights to access, correct, delete, or receive a portable copy of personal data; object to or restrict processing; withdraw consent; appeal a refusal; and complain to a data-protection authority. These rights are not absolute and may require identity verification. Contact us to exercise a right regarding information Folding Sky or a provider acting for us holds. For content stored only on your device or in your personal iCloud account, use the app and Apple controls described above because Folding Sky cannot retrieve that content for you.
California Privacy Rights (CCPA/CPRA)
Where the CCPA applies, California residents may have rights to know, access, delete, and correct personal information; opt out of its sale or sharing for cross-context behavioral advertising; limit certain uses of sensitive personal information; use an authorized agent; and receive equal service when exercising those rights. We do not sell personal information.
Alarmist sends device identifiers and purchase events to Google and TikTok for ad conversion measurement. Applicable law may treat some of this activity as "sharing" for cross-context behavioral advertising. Declining ATT prevents access to your device's advertising identifier and reduces attribution, but limited non-IDFA information may still be processed. Contact us to submit an applicable sale or sharing opt-out request or another California privacy request. We may need information to verify your identity or an agent's authority.
Folding Sky does not maintain user accounts or receive app content from Alarmist, Busybody, Cumbersome, or Endemic on Folding Sky servers. Contact us about information that Folding Sky or a provider acting for us holds, and use the app, device, and iCloud controls described above for local or personal iCloud data.
International Data Transfers
Folding Sky and our providers may process website, analytics, support, purchase, attribution, and Dense backend information in the United States and other countries where they operate. Those locations may have different data-protection laws. Where required, we use an applicable legal transfer mechanism or rely on a provider's mechanism.
Do Not Track Signals
Our website and apps do not currently respond to browser "Do Not Track" (DNT) signals. Vercel Web Analytics does not use third-party tracking cookies. For Alarmist on iOS, Apple's App Tracking Transparency framework controls access to the advertising identifier.
Links to Other Sites
Our site and apps may include links to third-party websites or services. We do not control those sites and are not responsible for their privacy or security practices. Review each site's policies before sharing information.
Changes to This Policy
We may update this policy to reflect product or legal changes. Material updates will be noted by changing the effective date and, where reasonable, providing notice on our website.
Contact
For privacy questions or requests, contact us at: caldron.mounts-4s@icloud.com