Every app
What applies to every app
- No accounts — with one exception. Only dumb FEED has accounts, because receipts need an address to reach you: a username you invent and a password, nothing else. No DUMB app ever asks for your email, phone number or identity.
- No analytics or tracking. The apps contain no analytics tools, no advertising SDKs and no third-party trackers, and we do not link data to your identity or use it for advertising as defined by Apple's App Store privacy rules.
- Your device is the database. Settings, edits and history are stored locally on your iPhone and are removed when you delete the app.
- Apple services. Where an app offers dictation, speech may be processed by Apple's speech recognition service; where an app sends notifications, delivery goes through the Apple Push Notification service. Apple's own privacy policy governs those services.
Each app
What each app does with data
dumb MESSAGE — shared drawing canvas
Shared canvases are relayed through a small server operated by the developer. To make that work, the server stores:
- the display name you choose (any text you like — it is not verified and does not identify you),
- the contents of canvases you draw on, including photo stamps and dictated-text stamps you choose to place,
- if you allow notifications: a push token and the list of canvases you recently joined, so the server can tell you when a watched canvas changes.
Canvases are private to whoever has the canvas ID or link; there is no public feed or search. The camera is used only to place a photo stamp on the canvas; the microphone only while you dictate text to place. Clearing a canvas erases its pixels for everyone; to request deletion of a stored canvas snapshot, email us the canvas ID.
dumb RADIO — internet radio tuner
The developer collects nothing. Audio streams travel directly between your device and the radio stations' own servers. If you tune one of the two LOCAL dial positions, the app asks for approximate location and uses a single fix for one query to the community station directory radio-browser.info to find broadcasters near you; the coordinates are not stored by the app or the developer. Station edits you make live only on your device.
dumb FEED — receipts between friends
dumb FEED prints photos and notes as 1-bit receipts and delivers them to friends you name. It is the one DUMB app with an account, and receipts travel through a small relay server operated by the developer. What that involves:
- Your account is a username you invent (letters and digits — it does not have to identify you) and a password. The server stores the username and a salted cryptographic hash of the password (PBKDF2), never the password itself. No email, phone number or real name is asked for or stored.
- Receipts you print are dithered to 1-bit on your phone. When you print to friends, the receipt image with its title, comment, timestamp and optional city line is relayed through the server to the usernames you chose. The server holds each receipt only until the recipient's phone confirms it has saved it — then the copy is deleted from the server. Receipts are never public; there is no feed, search or discovery.
- Location is optional and coarse: if you allow it, a single fix per session stamps your approximate city on the receipt, like a store address line. Precise coordinates never leave the phone.
- Notifications. If you allow them, a push token is registered so arriving receipts can alert you (including on the Lock Screen and in the Dynamic Island). Tokens are used for delivery only and are removed when the account is deleted.
- Delete your account any time, in the app. The account, any receipts still queued for you on the server, and your push registrations are removed immediately and the username is freed. Receipts you already printed onto friends' rolls stay on their devices, like letters you have mailed. You can also email apps@mattjakob.com with your username for any deletion request.
dumb MUSIC — click-wheel player
The app connects to a streaming service you already use. With Apple Music, playback and library access run through Apple's MusicKit under your Apple account. With Spotify, you sign in to Spotify directly (OAuth) and the app remote-controls playback; sign-in tokens are stored in the iOS Keychain on your device only. When you open lyrics, the current song's title, artist and duration are sent to the community lyrics service LRCLIB to fetch them. The developer receives none of this data.
Retention
Data retention and deletion
On-device data disappears when you delete an app. Developer-held data is limited to dumb MESSAGE's canvas relay and dumb FEED's accounts and in-transit receipts, both described above, kept only to operate the service. dumb FEED accounts are deleted in-app; for canvas snapshots email apps@mattjakob.com from any address with the canvas ID, and for anything else email us too.
Children
Children
DUMB apps are not directed at children under 13, and we do not knowingly collect personal information from children. All DUMB apps are rated 4+ on the App Store because they contain no objectionable content.
Your rights
Your rights
Depending on where you live (for example under GDPR or the CCPA), you may have rights to access, correct or delete personal data. Because DUMB apps hold almost nothing, most requests are satisfied by deleting the app — but for anything server-side, or any question at all, email apps@mattjakob.com and we will respond promptly.
Changes
Changes to this policy
If an app's data practices ever change, this page changes first and the app's App Store privacy label is updated with it. Material changes will be noted in the app's release notes.
Last updated: July 25, 2026