watchcap studio

Privacy

What we store, who else touches it, and how to get it back or get rid of it.

Effective 29 July 2026 · Last updated 11 August 2026

The short version

What you make in our software is yours. We do not sell it, we do not advertise against it, we do not train anything on it, and we do not pool it with anyone else's. Some of what we make never sends us your work at all. The one thing we would ever ask for is permission to show something you made in our own marketing, and we will ask you first every time.

The rest of this page is the long version, written plainly, because you should be able to check the claim.

Who we are

Our software is made by BTTY LLC, doing business as WatchCap Studio. When this page says "we," it means that company. Write to us at hello@watchcapstudio.com.

What this covers

Everything the studio publishes: our applications, for whatever device they run on, and our websites, together with the services behind them. That includes what we release in the future, from the day it ships.

We keep one privacy page rather than one per app, so there is a single place to check. A product may add its own page later, where what it does needs more detail than belongs here. If it has one, read that too, and treat it as the more specific answer.

The cost of one page is that not every section applies to every product. Where a section only applies to some, it says so at the top, and it reaches nothing that lacks the thing it describes.

The two kinds of product we make

This distinction decides almost everything below, so it comes first.

The kind that keeps your work on your device

Some of what we make writes to your own machine and sends us nothing. We do not have your words, cannot read them, and do not know you are using it. There is no account and no server holding your work. The only thing that ever reaches us is a bug report you choose to send.

The kind that holds your work for you

Other products keep your work on our servers, so it follows you between devices and survives a lost laptop. That requires an account, and it means we hold your content. Everything in the next section about accounts, storage, and other companies applies to this kind.

What we store

Your account

Applies where a product has accounts

You sign in with Apple, with Google, or with an email address. We receive an account identifier, your email address, and whatever display name the sign-in provider passes along. We never receive or store your password.

Your work

Applies where we hold your work

Whatever you put in, and whatever the product keeps on your behalf: the things you save, the passages you keep, the notes you write, the drafts you have not finished, pictures and recordings you attach, transcripts of those recordings, and the ordinary state that makes an app feel like yours, such as where you left off.

Your public profile

Applies where a product publishes

If you publish, we store the public name you claim, a display name, and a bio, and we record who follows whom. None of it is required to use the product privately.

A service you connect

Applies where a product connects to one

If you connect an outside service, we store the access token it issues, encrypted at rest with a key held outside the database, and we use it only to move your own data between that service and ours. Disconnecting stops the exchange and deletes the token.

Where a product uses your location

Applies where a product uses location

Some products answer a question about where you are, so they need to know where that is. You grant location through your device's own controls, and the product uses it to fetch the conditions for that spot. A place you save is kept so the product can return to it. We build no history of your movements, and a location is used only for the job you gave it.

Where a product sends you alerts

Applies where a product sends notifications

Some products watch for something and tell you when it happens, which needs two things. The first is a token from Apple or Google that addresses a notification to your particular device. The second, where the alert depends on a place, is the place you asked us to watch, held alongside a lasting per-device identifier so the alert can reach the same device again tomorrow. That identifier is separate from the throwaway number our analytics uses, and because it lasts, the rules in Apple's stores and in Europe treat what is tied to it as personal even with no name attached. We keep it to run the alerts and for nothing else. Turning off notifications, or removing a watched place, ends it.

Where a product is paid

Applies where a product charges

Some products cost money, once or by subscription. The payment itself runs through Apple or Google and we never see your card. To know what you are entitled to, and to give it back when you reinstall or move to a new device, we keep a record of what you bought and whether it is still active, tied to the same per-device identifier above. RevenueCat, listed below, keeps that record for us.

Bug reports

When you file a report from inside an app, we receive what you write and, where the app captures one, a picture of the screen at that moment. Those pictures go to a private store only we can read. If the screen showed something you would rather we not see, cancel the report and write to us instead.

Usage

We record that an action happened: which app, which platform, the name of the action, and when. We never attach the content the action was performed on. That is the whole of our analytics. There is no third party analytics service, no advertising identifier, and no tracking across other apps or websites.

What identifies the action depends on the app. Where you have an account, it is your account. Where you do not, it is a number the app invented on your device that is attached to nothing about you, and we deliberately keep it in a form that cannot be followed from one day to the next. In that case we can see how many people used the app on a given day, week, or month, and nothing else. Not who, not where, not whether it was the same person twice.

Email you hand us

If you ask for an invitation or otherwise give us an address, we keep it until it has served its purpose or you ask us to drop it.

Our websites

Our host keeps ordinary server logs, including IP addresses, for security and debugging, and discards them on its own schedule. We set no advertising or analytics cookies.

What we never do

  • We do not sell or rent your personal information, and we never have.
  • We do not show ads, and we do not share your data with advertisers.
  • We do not use your work to train machine learning models.
  • We do not combine your work with other people's to build a product out of the aggregate.
  • We do not track you across other apps or websites.

None of those five has an exception, and permission does not unlock them. We will not sell your work because you said we could.

The one thing we will ask for

If we want to show something you made, in a screenshot, on a website of ours, or in anything else that amounts to us advertising our own software, we will ask you first and wait for a yes. No is a complete answer, it costs you nothing, and we will not ask twice about the same thing.

Saying yes covers that one use, not everything after it. You can change your mind and we will stop, though we cannot pull back something already printed or already out in the world.

Who else touches it

We are a small operation standing on other people's infrastructure. These are the companies that process data on our behalf, and the only reason each one gets anything. Not every product uses every one.

CompanyWhat it handles
SupabaseThe database, file storage, and sign-in. Where a product holds your work, it lives here. Hosted on Amazon Web Services in the United States.
PowerSyncKeeps your devices in step with the database, so the same library is on your phone and your Mac.
ElevenLabsTurns text into speech where a product reads to you, and speech into text where a product takes voice notes. It receives that one passage or that one recording for that one job.
ResendSends the few emails we send.
VercelServes our websites and the pages behind public links, and keeps the server logs described above.
GitHubHosts the installer and update files for our desktop apps, so it sees the request when your app checks for a new version.
Apple, GoogleSign-in, where a product offers it. Apple also answers lookups for artwork where a product needs it. Where a product is paid, they run the purchase and hold the card; we never see it.
RevenueCatKeeps the record of what you bought and whether it is still active, where a product is paid, so it can restore your purchase on a new device. The payment runs through Apple or Google; RevenueCat never sees your card.

Each acts on our instructions and is not permitted to use your data for its own purposes.

Treat the table as current rather than final. It names the companies that handle personal data for what we run today, and we update it when that changes, but a new product can bring in a service before this page catches up, and a product may draw on a public data source that receives nothing about you. If you want to know exactly what a particular product touches, ask us and we will tell you.

What becomes public, and when

Our software is private by default. Nothing you write is visible to anyone else until you take an action that publishes it.

  • Links you hand out. Sharing generates a page at an unguessable address. Anyone holding that link can read it, and a search engine could index it if someone posts it publicly. You can stop the page from working, but you cannot recall a link that has already been passed along.
  • A public name. If you claim one, the page at it, and anything you list there, is public to anyone who visits.
  • Following. If you follow someone, that is visible to them.

Everything else is visible only to you, and to the small number of people who operate the service. We look only when we are fixing something or you have asked us to.

Where it sits

Our infrastructure is in the United States. If you use our software from elsewhere, your data is transferred there and handled under this page and the safeguards our providers offer for such transfers.

How long we keep it

We keep your work for as long as your account exists, because that is the point of it. Bug reports and usage records are kept while they are useful and pruned when they are not.

Deleting something in an app marks it deleted and hides it from you immediately, and it is cleared from our systems in the ordinary course after that. Encrypted backups may hold a copy for a short period before they roll over.

Getting a copy, and getting rid of it

There is no delete-my-account button in our apps yet. Until there is, write to hello@watchcapstudio.com from the address you signed up with and ask. We will:

  • Send you a copy of everything we hold, in a form you can read, within 30 days.
  • Correct anything that is wrong.
  • Delete your account and its contents within 30 days, backups excepted as described above.

These are your rights under the GDPR and the UK GDPR if you are in Europe or the United Kingdom, and under the CCPA if you are in California. We extend them to everyone, because drawing a map of who deserves them seemed worse than just honoring them. We will not charge you or degrade the software for asking. If you are in Europe or the UK, our lawful basis is the contract between us for providing the service, and our legitimate interest in keeping it working and free of abuse.

For a product that keeps your work on your device, there is nothing for us to send or delete. Removing the app removes the work, so keep your own copy of anything you want to survive it.

Security

Traffic between your devices and our servers is encrypted. A token for a service you have connected is separately encrypted at rest. The database enforces per-user access rules, so one account cannot read another's rows. Screenshots from bug reports sit in a private store reachable only with a short-lived signed link.

None of that is a guarantee. No service can promise perfect security, and we will not pretend otherwise. If we discover a breach affecting your data, we will tell you what happened and what we are doing about it.

Children

Our software is not intended for anyone under 13, or under 16 in the European Economic Area and the United Kingdom. We do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.

Changes

If this page changes in a way that matters, we will date the change here and, if it is significant, tell you in the app or by email. Continuing to use our software after that means the new version applies.

Contact

Questions, requests, or a correction to something on this page: hello@watchcapstudio.com. A person reads it.

The agreement itself: Terms of Service.