Nothing you write or open ever leaves your device. There is no account, no sign-in, no advertising, and no TwoUp server. Your workspaces, notes, imported documents and saved sites stay on the iPhone they were made on.
The app does send anonymous usage statistics — which screens are reached and which buttons are pressed — so we can see where people get stuck. It carries none of your content and is not tied to your identity. You can turn it off in the app: Menu → App → Share usage data. Section 2 says exactly what is and is not sent.
This policy describes how the TwoUp iOS app ("TwoUp", "the app", "we") handles information. It applies to the app as distributed on the Apple App Store. Because the app has no backend, most of this document explains what does not happen.
Anonymous usage statistics, and nothing else. Measured against the categories Apple asks developers to declare:
| Category | Collected |
|---|---|
| Contact info (name, email, phone, address) | No |
| Identifiers (user ID, device ID, advertising ID) | A random app-install identifier only. No advertising identifier — the app cannot read it — and no account, because there is none. |
| Usage data, product interaction, analytics | Yes — anonymous, and only if “Share usage data” is on |
| Diagnostics and crash logs | No |
| Location | No |
| Contacts, photos, health, financial info | No |
| User content (your notes, documents, browsing) | No — stays on device |
| Purchase history | No — held by Apple |
We do not build a profile of you, and we do not sell or share anything. Nothing that reaches us identifies you, and none of your content reaches us at all.
The app keeps the following inside its own storage area on your iPhone, where only TwoUp can read it:
None of this is uploaded, and none of it is synced between your devices. Copies of imported documents are deliberately excluded from your iCloud backup: a large file you already keep in Files should not be duplicated into every backup you make.
TwoUp's web pane uses WKWebView, the same web engine Safari uses. When you open a page, your device contacts that website directly, just as any browser would. That website — and anything it embeds — receives your IP address and may set cookies, and its own privacy policy governs what it does with that.
What we want to be exact about: your traffic does not pass through us, we do not inject any tracking into the pages you view, and your browsing history is not recorded off your device. Website data lives in the app's storage and is removed when you delete the app.
When you save a site as a shortcut, TwoUp requests that page over HTTPS to read its title and icon so the shortcut is recognisable. Only the address you asked for is contacted; the request uses a temporary session that keeps nothing on disk, and no third party is involved.
TwoUp Pro is sold through Apple's In-App Purchase. Apple processes the payment — we never see your name, your Apple Account or your card. What the app receives is Apple's answer, on your device, to a single question: whether Pro is currently unlocked. Apple's handling of the transaction is covered by Apple's Privacy Policy.
TwoUp uses Google Analytics for Firebase to count how the app is used. It is the only third-party code in the app. There is no advertising, no attribution and no other SDK.
What is sent — a short list of things that happen, with no content:
What is never sent:
To do the counting, Firebase assigns a random identifier to the installation. It is not your name and not your device's permanent identifier; deleting the app discards it. The advertising identifier is not used — the app is built with the Firebase variant that cannot read it — which is why TwoUp never shows the App Tracking Transparency prompt. Nothing here is used for advertising or shared with advertisers, and nothing is combined with data from other apps.
Turning it off: open Menu in the app, scroll to the App card, and switch off Share usage data. Collection stops immediately, and on later launches the analytics component is not started at all.
Google acts as our processor for this data and holds it on our behalf; their handling is covered by Google's Privacy Policy. The events described above are retained for up to 14 months and then deleted automatically.
The app requests no system permissions — no camera, photo library, microphone, contacts or location. Documents arrive through the system file picker, which grants access only to the file you personally choose.
TwoUp is not directed at children under 13. It collects no personal information from anyone of any age: the usage statistics in section 7 identify nobody, and they can be switched off in the app.
Everything the app holds lives on your device and is under your control. Delete an individual workspace, note or document inside the app; delete the app itself and all of it — including saved website data — is removed with it.
Rights under the GDPR, the CCPA/CPRA and comparable laws — access, correction, deletion, portability, objection — apply to personal data a company holds about you. We hold none, so there is nothing for us to export, correct or erase, and no data broker to opt out of. If you would like that confirmed in writing, ask us and we will confirm it.
Your data sits inside the app's sandbox, protected by iOS and by your device passcode and encryption. Network requests the app makes are HTTPS only, enforced by App Transport Security. No system is perfectly secure, but keeping data off the internet removes most of what could go wrong with it.
If TwoUp ever gains a feature that touches your data — syncing, for instance — this policy will be updated before that feature ships, and the "Last updated" date above will change. Material changes will be announced in the app.