Foundry Privacy Policy

Effective August 24, 2026 · Español

At a glance. Foundry has no accounts and no servers of ours. What you create in the app stays on your device. We do not advertise to you, we do not track you across apps or websites, and we do not sell your data.

One thing does leave your device: to know whether your subscription is active, the app talks to our subscription provider, RevenueCat. It receives a random ID that is not linked to your identity, your purchase history, and basic device information. That is the whole of it, and it is described in detail below.

1. Who is responsible

Fabian Brussa is the data controller for the processing described here.

Alvar Nuñez C de Vaca 4263, 5009 Córdoba, Córdoba, Argentina
foundry.apps.global@gmail.com

We are a small independent developer. We are not required to appoint a Data Protection Officer, so privacy questions go to the address above and are answered by us directly.

2. What we never collect

Foundry does not ask for and does not receive your name, email address, phone number, contacts, calendar, precise or coarse location, photos, health data, or advertising identifiers. There is no sign-up and no login.

The app contains no advertising SDKs and no third-party analytics SDKs. It does not track your activity across other companies' apps or websites, which is why Foundry will never show you Apple's App Tracking Transparency prompt.

3. Data that stays on your device

The content you create in the app and your settings are written to the app's private storage on your device. We have no access to it and no copy of it.

If you have iCloud Backup enabled, iOS may include that storage in your device backup. That backup is governed by Apple's privacy policy and we cannot read it.

4. Data processed to run your subscription

If the app offers a paid subscription, two companies are involved.

Apple

Apple processes the payment itself. We never see or receive your card details, billing address, or Apple Account credentials. Apple acts as an independent controller for that transaction under its own privacy policy.

RevenueCat

RevenueCat, Inc. manages subscription state on our behalf, acting as our processor under a data processing agreement. It receives:

DataWhy
An anonymous app user ID — a random string generated on your device (for example $RCAnonymousID:…) To attach a purchase to a device without knowing who you are. It is not derived from your Apple Account, your name, or any hardware identifier, and we cannot link it to a person.
Purchase and receipt data from Apple — product identifiers, purchase and expiration dates, trial and renewal status, transaction identifiers To determine whether your subscription is currently active, and to restore your purchase on a new device.
Device and app information — platform, operating system version, app version, device model, App Store country, locale, time zone To apply the right pricing and offers, and to diagnose purchase failures.
IP address Unavoidably visible in any network request. Used to infer country and to prevent fraud. It is not used to determine your precise location.

When this happens: the app checks your subscription status when you open it, not only when you visit the purchase screen. It has to, because it needs to know which features to unlock before it draws anything. So this exchange occurs on app launch, when a check is refreshed, when you buy, and when you restore a purchase.

RevenueCat does not use this data for advertising and does not sell it. Its own policy is at revenuecat.com/privacy.

This is the only transfer of data to a third party that Foundry performs.

5. Legal bases for processing (EEA, UK and Switzerland)

An anonymous identifier tied to a device is still personal data under the GDPR, even though we cannot connect it to your name. We are transparent about that rather than claiming we hold nothing.

We do not rely on consent for any of the above, so there is no consent for you to withdraw. We do not carry out automated decision-making or profiling that produces legal effects for you.

6. International transfers

We are established in Córdoba, Argentina. Argentina is recognised by the European Commission as providing an adequate level of data protection (Decision 2003/490/EC), so transfers from the EEA to us do not require additional safeguards.

RevenueCat is located in the United States. Transfers to it are covered by the Standard Contractual Clauses included in our data processing agreement with them.

7. How long data is kept

On-device data lasts until you delete it or uninstall the app. Subscription records held by RevenueCat are retained while the subscription is active and afterwards for as long as needed to honour restores, handle refunds and disputes, and meet tax and accounting obligations. We keep no separate copy of our own.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to receive it in a portable format, and not to be discriminated against for exercising any of these rights.

The practical problem, stated honestly: because there are no accounts, an email from you does not tell us which record is yours. To make these rights usable, the app shows your anonymous app user ID in Settings, where you can copy it. Send us that ID and we can look up, export, or delete the corresponding record. Without it we have no way to identify your data — not as a policy, but as a fact.

To delete all on-device data, uninstall the app; iOS erases its private storage.

To manage or cancel a subscription, open Settings → your name → Subscriptions on your device. We cannot cancel it for you, and refunds are handled by Apple at reportaproblem.apple.com.

We respond to requests within 30 days. If you are in the EEA or UK, you may also lodge a complaint with your local data protection authority.

9. Notice for California residents

Under the CCPA as amended by the CPRA, in the past 12 months we have collected the following categories of personal information, all for the business purpose of providing and supporting your subscription:

We collect these from your device, via RevenueCat and Apple. We do not collect sensitive personal information, and we do not sell personal information or share it for cross-context behavioural advertising — so there is no "Do Not Sell or Share My Personal Information" link to provide, because there is nothing to opt out of.

You have the right to know, delete, and correct your personal information, and to be free from retaliation for exercising those rights. Requests go to foundry.apps.global@gmail.com and require the anonymous ID described in section 8. Authorised agents may submit requests with written proof of authorisation.

Residents of other US states with comparable laws — including Virginia, Colorado, Connecticut, Utah, Texas and Oregon — have substantially the same rights and may use the same contact address.

10. Children

Foundry is not directed to children. We do not knowingly collect personal information from anyone under 13, or under 16 in jurisdictions where that is the applicable age of consent. If you believe a child has provided data, contact us and we will delete it.

11. Crash diagnostics

The app includes no third-party crash reporting. If you have enabled "Share iPhone Analytics" or "Share With App Developers" in iOS Settings, Apple may send us aggregated, anonymous crash reports. That sharing is controlled by you in iOS, not by this app, and you can turn it off there at any time.

12. Changes to this policy

If this policy changes we will update the effective date above. If a change materially affects how your data is handled — for example if we ever add analytics — we will say so inside the app before it takes effect, and update our Apple privacy disclosures to match.

13. Contact

Fabian Brussa
Alvar Nuñez C de Vaca 4263, 5009 Córdoba, Córdoba, Argentina
foundry.apps.global@gmail.com