Privacy policy
Effective October 4, 2026. The short version: four of our nine apps collect nothing, your chats, trips, workouts and documents are stored on your device, and the table below says exactly what the rest send.
1. Who we are
Haplo, LLC (“Haplo,” “we,” “us”) makes the apps listed below and runs the website at haploapp.com. This policy explains what each one collects, what it doesn't, and what rights you have. It replaces our previous privacy notice dated August 11, 2026.
Haplo, LLC · 1402 N Steiwer Ln, Newberg, OR 97132 · support@haploapp.com
2. What each app collects, at a glance
| App | Account? | What Haplo receives |
|---|---|---|
| Bilbo | No | Anonymous usage events, through Google Analytics for Firebase. Never your trips, places, photos or anything you type, which stay on your device. See Section 7. |
| Cinder | No | None of your workouts, health or route data. Those stay on your device and in Apple Health. |
| Haplo AI | No | Nothing about you. Chats and generated images are saved on your device. Its web search, maps and browser tools send content to other services when they run. See Section 6. |
| Haplo AI Investing | No | The tickers you open, plus your watchlist and holdings when the app analyses them, sent to our server to build each page. Not tied to you. See Section 6. |
| Barrier | No | Device and advertising identifiers, ad interactions, usage events and crash reports, through Google AdMob, AppLovin and Firebase. See Section 7. |
| ShipHappens, Markdown2PDF, EasyLogo, Annot8 | No | Nothing. |
“Nothing” means exactly that: those apps have no Haplo server to send your content to. They do make ordinary network requests to third parties for specific features, which are listed in Section 6. Each app’s App Store privacy label is the official summary of the same thing.
3. The website
haploapp.com uses Google Analytics 4. Its cookies are set only if you agree to them in the
cookie banner. With them, it tells us which pages people read, roughly where they are (country and city), which device
and browser they use, and how they arrived, such as from a search engine or a link. It does this with
first-party cookies named _ga and _ga_<ID>, which we set to expire
after 13 months. Google processes this data for us; Google Analytics 4 does not log or store IP
addresses. We keep the reports for up to 14 months, and we have not turned on advertising features,
Google signals, or user IDs.
If you say no, or never answer, the Google tag still loads but Analytics sets and reads no cookies:
it sends Google a cookieless ping for each page, with no identifier, which Google uses only to estimate
how many people visit (Google calls this consent mode). You can change your answer at any time
with Cookie settings at the bottom of every page; saying no removes
the _ga cookies. Your choice is stored in your browser, not on our servers, and we ask again
after six months.
We use no advertising trackers and do not use cookies to profile you. If you create an account or sign in, we set a session cookie that keeps you signed in; it is strictly necessary and expires when your session does.
Our web host records standard server logs, including IP address, request time, and user agent, for security and reliability. Some pages load app icons, screenshots, and ratings directly from Apple's iTunes API, so Apple receives those requests.
If you contact us, sign up for an update list, or submit a support request, we keep what you send us so we can respond.
4. Health and fitness data
Cinder and Haplo AI can read from and write to Apple Health (HealthKit) with your permission. Cinder uses heart rate, calories, workouts, and route data to show live metrics and track training. Haplo AI can read health data so you can ask questions about it in conversation.
Haplo never receives your health data. It stays on your device and in Apple Health. We do not upload it, store it on our servers, sell it, share it with advertisers or data brokers, or use it for advertising, marketing, or model training. Apple's HealthKit rules prohibit those uses and we follow them.
You can review or revoke health permissions at any time in Settings → Privacy & Security → Health, or inside the Health app. Revoking access does not delete data already written to Apple Health; you can delete that in the Health app.
If you connect Strava in Cinder, that is a direct link between your device and your own Strava account, authorised by you through Strava's sign-in. Data you push goes to Strava under Strava's privacy policy, not to us. You can disconnect it in Cinder's settings or from your Strava account.
5. Location, photos, microphone
Location. Cinder uses precise location while in use to record running and cycling routes and calculate distance. Routes are stored on your device and in Apple Health. We do not receive them. Location is only accessed while you have an outdoor workout active and you have granted permission.
Photos. Bilbo can scan your photo library's location metadata, on your device, to award passport stamps for landmarks you have already visited. It reads metadata only, the scan runs locally, and neither your photos nor the results are transmitted anywhere.
Speech. Bilbo can transcribe videos you share with it to pull out places and plans. Transcription runs on your device.
Approximate location. The analytics in Bilbo and Barrier (Section 7) can include a rough location, such as your country or city, that Google works out from your IP address. Bilbo never sends your GPS position or the places in your trips.
Every one of these is permission-gated by iOS. You can grant or revoke each independently in Settings, and the app keeps working without them, minus that feature.
6. Third parties our apps contact
- Wikipedia / Wikimedia (Bilbo): Bilbo sends a place name to fetch that location's photograph. Wikimedia sees the request and your IP address, so it can see which places appear in your itinerary. It does not receive your itinerary, your account (there isn't one), or anything else.
- Hugging Face (Haplo AI): hosts the AI models you choose to download. It sees the download request and your IP address, not your prompts.
- Search engines, Apple Maps and the sites a task visits (Haplo AI): Haplo AI's language model runs entirely on your device, and no Haplo server receives your prompts or replies. Its web search, maps and browser tools do send content out whenever they run. A search sends that message's text to DuckDuckGo (or to Bing if DuckDuckGo fails) and loads the top result pages; maps sends a search term with your location or the place you named to Apple; the browser visits the sites a task needs and can fill in and submit their forms. A tool runs when you pick it for a message, and on a Mac, an iPhone 16 Pro or Pro Max, or any iPhone 17, Automatic Tools (on by default) can also choose one for you when a supported model is loaded. When an answer cites web sources, Google's icon service loads those sites' logos, so it sees the sites' names. Calendar, Health and chart tools work on the device.
- Haplo’s server (Haplo AI Investing): the app asks our server for each page. The request carries the ticker you opened, and your watchlist and holdings when the app shows or analyses them, so the server can build the analysis. We use it to answer that request and do not store it against you. We keep a running count of how often each ticker is viewed, with nothing about who viewed it.
- Haplo’s model list (Bilbo, Cinder, Haplo AI, ShipHappens): these apps fetch the list of AI models they can download from haploapp.com. The request carries the device type, the app's version numbers and, for Haplo AI, how much memory the device has, along with the IP address every web request carries. Nothing about you or your content.
- Financial Modeling Prep (Haplo AI Investing): supplies market data and quotes.
- Google Analytics for Firebase (Bilbo, Barrier): see Section 7.
- Strava (Cinder, optional): see Section 4.
- Apple: handles all purchases, subscriptions, and refunds. We never see your payment details. Apple gives us anonymised sales and subscription reports.
- Google AdMob and AppLovin (Barrier only): see Section 7.
7. Advertising and analytics
Barrier is the only app that shows ads. It uses Google AdMob and AppLovin to serve rewarded ads as part of how the app works, and asks your permission to track. These ad networks may collect device and advertising identifiers, ad interactions and usage data, and use them for ad personalisation under Google's policies and AppLovin's privacy policy. That is why Barrier’s App Store label lists data used to track you. You can limit this in Settings → Privacy & Security → Tracking and Settings → Privacy & Security → Apple Advertising, and through Google's ad settings. Barrier also uses Google Analytics for Firebase to count how the app is used, and Firebase Crashlytics to report crashes.
Bilbo uses Google Analytics for Firebase to count how the app is used: which screens are opened, which features are used, and errors. Events carry fixed names, counts and categories, never trip names, places, coordinates, photos, documents or anything you type. Google assigns the app a random install identifier and works out a rough location from your IP address. This data is not linked to your identity, and Bilbo does not ask to track you.
No other Haplo app shows ads. Cinder, Haplo AI, Haplo AI Investing, ShipHappens, Markdown2PDF, EasyLogo and Annot8 contain no analytics or advertising SDKs.
8. AI processing
The AI features in Bilbo, Cinder, and Haplo AI run models locally on your device. Your prompts, chats, itineraries, workouts, and generated images are processed on the device and are not sent to Haplo. We do not use your content to train any model. The exception is Haplo AI's web search, maps and browser tools described in Section 6, which send content to those services whenever they run, including when Automatic Tools runs one for you.
9. What we do not do
- We do not sell your personal information. The ads in Barrier (Section 7) can count as “sharing” under California law, because the ad networks may use device identifiers for personalised ads; you can turn that off in Settings → Privacy & Security → Tracking. No other app shares your personal information.
- We do not sell, share, or monetise health, location, or photo data, ever.
- We do not train AI models on your content.
- We do not knowingly collect information from children under 13. If you believe a child has provided us information, email support@haploapp.com and we will delete it.
10. Retention
Haplo AI Investing requests are used to build the page you asked for and are not stored against you. Earlier versions of Haplo AI Investing had accounts; if you made one, we keep its email and watchlist until you ask us to delete it, so email us and we will. Analytics data from Bilbo and Barrier is kept by Google under our Analytics retention settings. Support emails are kept as long as needed to resolve the issue and for a reasonable period afterwards. Server logs are kept short-term for security. Content that never leaves your device is under your control: deleting the app deletes it.
11. Your rights
Everyone. Email support@haploapp.com to access, correct, export, or delete anything we hold. We will not charge you or treat you differently for asking.
California (CCPA/CPRA). You have the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing (we do not sell; for the sharing in Barrier’s ads, see Section 9), and to limit use of sensitive personal information. We do not use sensitive personal information for anything beyond providing the features you asked for.
EU, UK, EEA and Switzerland (GDPR). You have rights of access, rectification, erasure, portability, restriction, and objection, and the right to complain to your local data protection authority. Where we process data, our lawful bases are performing our contract with you (answering the requests an app sends, and older accounts), consent (device permissions, tracking and ad personalisation, which you can withdraw at any time), and legitimate interests (security, reliability, and understanding how the apps are used).
Washington, Nevada, and other consumer health data laws. Health and fitness data handled by our apps stays on your device and in Apple Health. We do not collect, receive, store, share, or sell consumer health data, so there is nothing on our side to disclose, delete, or opt out of. You control the data through iOS permissions and the Health app.
12. Security
Keeping data on your device is the main protection here: most of what our apps handle never exists on a server we run. Haplo AI Investing’s requests travel over TLS, and passwords for accounts made in earlier versions are stored hashed. No system is perfect, and we cannot guarantee absolute security.
13. International transfers
Our servers are in the United States. If you use Haplo AI Investing from outside the U.S., the requests it sends, and any account data from earlier versions, are transferred to and processed there. Google and AppLovin may also process analytics and ad data outside your country. Transfers use appropriate safeguards, including Standard Contractual Clauses where required.
14. Do Not Track
This website does not track you across sites, and we do not respond to DNT headers. For tracking in apps, iOS uses its own setting, described in Section 7.
15. Changes
We will update this policy as the apps change. The effective date at the top will change, and we will flag material changes in the app or by email where we have your address.
16. Contact
Haplo, LLC
1402 N Steiwer Ln, Newberg, OR 97132
Email: support@haploapp.com