Legal
Privacy policy
Most app content stays on your device or in your own iCloud. Some games relay messages and chosen photos through our infrastructure. Signing in alone uploads no projects; Tondo sync requires a separate explicit choice. We never sell personal data.
On this page
1 The short version
Your app data follows the storage and sharing choices described here. Saved work lives on your device. Where an app offers iCloud sync, it uses your Apple account. Some games also relay messages and chosen photos through our Cloudflare infrastructure so opponents can receive them. Some apps carry adverts served by Google; a one-time ad-free purchase stops ad requests. These separate data flows are explained in §3.
This website uses Cloudflare Web Analytics to measure page visits and loading performance without cookies or tracking individual visitors. The personal data we process to operate the site is described below. Because the portfolio spans different kinds of app, the recurring phrase here is “some apps”: where a clause applies only to certain apps, the app’s own App Store privacy label and its in-app About screen tell you which.
2 Who is responsible (controller)
The data controller for every oomny app and for this website is:
- Legal name
- Oomny B.V. (Besloten Vennootschap)
- Registered office
- Le Mairekade 77, 1013 CB Amsterdam, Netherlands
- Chamber of Commerce (KvK)
- 88737365
- VAT identification (btw-id)
- NL864757062B01
- support@oomny.eu · privacy: privacy@oomny.eu
- Phone
- +31 70 221 2442
For any privacy matter, write to privacy@oomny.eu and a real person answers. We are not required to appoint a Data Protection Officer and have not done so.
For an app that syncs to iCloud (see §3), Apple acts as our processor for the synced data — it stores that data in your own iCloud on our behalf. We remain the controller; the data still never reaches an oomny server.
3 Where your app data lives
Local app content: your saved notes, charts, cards, entries and game rounds are stored on your device. In-game messages and shared photos use the separate relay described below. Tondo and its store purchases remain usable without a Tondo account. If you choose a Tondo account, we process the Apple or Google identifier, your Tondo account identifier and session security data to provide the requested service (Article 6(1)(b) GDPR). We do not receive your Apple or Google password. Linking sign-in methods requires separate verification; matching email addresses do not merge accounts. Signing in alone uploads no projects; Tondo sync requires a separate explicit choice.
Some apps sync your data to your own iCloud so it appears across your iPhone, iPad and Mac. When an app does this, the data is replicated through your Apple account’s iCloud, where Apple acts as the processor; it is governed by Apple’s privacy policy and never passes through a server of ours. Where an app lets you share something with another person, only the part you choose to share is synced; the rest stays on your device. The app’s App Store privacy label and its in-app About screen tell you whether it syncs.
Some apps generate text or structure, such as a suggested reply, a tidy timeline or a draft, using on-device intelligence. That processing happens on your phone or tablet, with Apple's on-device model on an iPhone or iPad and Google's on-device model on an Android device that has one. Your input is not sent to oomny, to Apple, to Google or to any third-party AI service for that feature. Like any generated text, the result can be imperfect, so check anything that matters.
Some apps can write out what you say with a better speech model that you choose to download. The model is downloaded once, only when you start it, from Hugging Face, a public host for open AI models, and then runs on your device. The download request carries no account or identifier and never passes through an oomny server, and nothing you say or write is sent with it. Hugging Face handles the download request under its own privacy policy.
Some apps show a frost or weather forecast for your garden. The app asks the Norwegian Meteorological Institute (MET Norway) for the forecast at the garden’s location, rounded to about 1 km. The request carries no account or identifier and never passes through an oomny server; MET Norway handles it under its own privacy policy.
An invoicing app used by a seller based in Spain sends each invoice’s billing record to the Spanish tax agency. Spanish law requires it (VERI*FACTU, Real Decreto 1007/2023): the record carries the invoice number and date, the seller’s and the client’s names and tax numbers, and the amounts. The app sends it straight from your device to the Agencia Estatal de Administración Tributaria (AEAT), authenticated with your own electronic certificate, which stays on your device. The record never passes through an oomny server; the AEAT handles it under its own privacy policy. A seller outside Spain sends nothing.
An invoicing app can send an invoice for you through an optional subscription. When you send an invoice with Counthall Verzenden, the app transmits the invoice file, the recipient’s network address and the proof of your subscription to our sending service, which passes the invoice on to the network provider for your country: Recommand for Peppol in Belgium, the Netherlands and Germany, SUPER PDP (a French plateforme agréée) for France, or Openapi for the Italian SdI. To register your business there, your business name, address, VAT or fiscal number and e-mail address go to that provider, which also checks that you may act for the business. Our service keeps no invoice content: it stores a random account identifier (as a hash), your registration at the provider, and for each invoice only its identifier and delivery status. The providers keep the invoice as their role in the network and the law require, under their own terms. Legal basis: performance of the service you ordered (Art. 6(1)(b) GDPR).
Some apps are free and carry adverts. Where an app does, the adverts are served by Google AdMob, and Google receives what serving an advert needs: device and advertising identifiers, an approximate location derived from your connection, and how you interacted with the advert. For that advertising Google decides its own purposes and acts as an independent controller, under Google’s privacy policy. No game, note or entry is ever sent with an ad request: apart from the in-game chat described below, what you create in such an app stays on your device or, where the app offers sync, in your own iCloud.
Before the first advert is requested you are asked what you agree to, through Google’s own consent form, and you can reopen that form from the app’s settings at any time to change or withdraw your answer. Buying the app’s one-off ad-free purchase stops all of it: the advertising code is then never started, so no request is made and no identifier is shared. The app’s App Store privacy label and its Google Play Data Safety entry tell you which apps this applies to.
Some games let you chat with your opponent. Messages and chosen photos are relayed and stored on our Cloudflare infrastructure so the other player can receive them. We store the message or photo, chosen display name, time sent, conversation identifier and player seat. Photos are resized and re-encoded on your device before upload, removing embedded metadata such as location. A chosen profile photo uses the same relay. Blocking stops communication in both directions. Retention and deletion are explained in §7. Legal basis: performance of the service you are using (Art. 6(1)(b) GDPR).
Notifications. If you allow notifications, the app sends us a push token from Apple or Google together with the conversation identifier and your seat, so that a move or message from your opponent can reach your device. Each installation also sends a random identifier that the app creates itself, not your advertising ID, so that a second copy of the same invitation can be told that the seat is already taken. Legal basis: performance of the service you are using (Art. 6(1)(b) GDPR).
Random opponents. If you search for a random opponent, we store your chosen display name, the language and mode you chose and the invitation to your game, without any moves, together with the app’s random installation identifier. Another player who searches for the same game receives the invitation and sees your name. A search is deleted after 7 days if nobody takes it, and 30 days after it was taken. Legal basis: performance of the service you are using (Art. 6(1)(b) GDPR).
You can report messages and profile photos and block the other player. Reports reach our support team for review within 24 hours. Deleting a stored remote game or using the app’s data-deletion control requests removal of your messages and photos for the conversations still stored on that device. A connection is needed to complete the request. Report records and copies sent to support are handled separately as described in §7.
An app may let you store information about another person, such as a partner, family member or another player. The storage and sharing rules above apply to that information too, including the relay for in-game messages and photos you choose to send. You are responsible for having any permission you need to record or share it.
Tondo sync stores knitting and fabric project documents, attachments, inventory, revisions and installation IDs with Cloudflare D1 and R2. R2 storage has EU jurisdiction; this does not guarantee that all processing takes place only in the EU. Sign-in tokens may contain a name or email address. Our identity records use provider and account IDs and security data, never your password.
The Tondo community stores profiles, accepted rules, posts, photos, comments, likes, follows, blocks, groups, events and published designs. Content is for signed-in members, subject to group restrictions. Sharing a project excludes its private documents, scans, notes and recipient; publishing your own design is a separate action. We remove EXIF and other embedded metadata from photos. Moderation processes reports, reporter IDs and rights claims. Cloudflare Email Service sends moderators excerpts and notes, plus contact details for rights claims, without reporter IDs.
For the Ravelry link, we store your username and encrypted OAuth tokens for read-only access and downloads through our proxy. Ravelry is an independent controller. Disconnecting in Tondo deletes the link and tokens; you can also revoke authorisation at Ravelry. Downloaded files remain on your device.
Catalogue downloads use Cloudflare; restricted downloads check your account and purchase rights. Linking a store purchase verifies its proof of purchase. Version checks send the app ID, platform and storefront country. Voice commands use the system recogniser; audio may reach Apple or the device’s speech service, never Tondo. The legal basis for requested services is Article 6(1)(b) GDPR. Moderation and security rely on our legitimate interests and applicable legal duties under Article 6(1)(f) and (c).
4 What this website processes, why, and on what basis
- Website server logs. Our host keeps standard technical access logs (IP address, timestamp, page requested, user-agent) to operate the site and keep it secure. Legal basis: our legitimate interest in running and protecting the site (GDPR Art. 6(1)(f)). Retained briefly and used for nothing else.
- Email you send us. If you email support or privacy, we process your message to answer you. Legal basis: our legitimate interest in responding to you (Art. 6(1)(f)).
- Tondo worksheets and My workspace. The worksheets on the Tondo website (/make) and the sheets in My workspace work entirely in your browser. What you type there is not sent to us or anyone else and is not linked to a Tondo account. A saved sheet stays in your browser’s local storage on this device until you delete it or clear this browser’s data for this site; we cannot see, restore or delete it for you. An exported sheet is a file on your device that you control. Because we never receive these sheets, no legal basis for processing by us is needed.
This website carries no advertising, does no profiling and makes no automated decisions, and we never sell personal data. (Some of our apps are free and carry adverts; that is described in §3 above and it does not reach this site.) Apple and Google handle store purchases. For Tondo website purchases we process your receipt email, order and invoice identifiers, amount, currency, payment status, and the terms version and acceptance time. Lava and its payment partners process payment details; our account service does not receive your full card number. Stripe and its payment partners do the same for payments in euros. To apply the right seller and tax, we also record the country you choose, the country of your card or bank as reported by the payment provider, and the country of your internet connection. We use order records to deliver the licence, resolve payment problems and refunds, and meet applicable record-keeping obligations. See our terms for the purchase arrangements.
5 Who processes data on our behalf
We use the following service providers. Their roles depend on the service: hosting is processing on our behalf, while sign-in providers, stores and payment providers also process data for their own purposes under their policies. Tondo website payments use Lava and its payment partners. Payments in euros use Stripe (outside the EU through Link, Stripe’s reseller service).
- Cloudflare hosts this website, Tondo account and licence records, and the relay and storage of in-game chat messages in apps that have a chat.
- Apple Push Notification service and Google Firebase Cloud Messaging deliver game notifications in apps that offer them. They receive the push token and the content of the notification.
- Apple — distributes and sells our apps, and, for an app that syncs, stores that app’s data in your own iCloud as our processor.
- Google distributes and sells our Android apps through Google Play, and serves the adverts in our free, ad-supported apps. For that advertising Google is an independent controller rather than our processor, which is why it is described in §3 rather than listed as one here.
- Recommand, SUPER PDP and Openapi deliver the invoices a subscriber sends with an invoicing app’s sending subscription, each on its own network (Peppol, the French platforms, the Italian SdI); Cloudflare runs our sending service in between.
- Cloudflare D1 and R2 store Tondo sync and community data, and Cloudflare Email Service sends Tondo moderation notices (see §3).
6 International transfers
Our processors are EU-based or operate EU data regions. Where a processor (for example a US-incorporated provider such as Cloudflare or Apple) may process data outside the EEA, the transfer is covered by the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses. A copy of the relevant safeguard is available on request.
7 How long we keep it
- Local app content: for as long as you keep it on your device or in your own iCloud. Removing a local copy does not automatically remove a separately synced or shared copy. Use the app’s deletion controls for those copies; in-game chat retention is described below.
- In-game chat messages and photos: messages become eligible for automatic deletion after 90 days, and cleanup runs when the chat service handles new activity. Each conversation also has a 500-message limit. Shared photos and profile photos have a 90-day storage lifecycle. App deletion controls can request earlier removal. Open reports remain until handled; resolved reports older than 90 days are cleaned up during server activity. Copies sent to support follow the support-email retention rule. A blocking record remains while the conversation is blocked so cleanup cannot reopen it.
- Push tokens and installation identifiers: a push token is deleted when the notification service reports it as invalid, when you remove the game or delete everything in the app, or after 120 days without use. An installation identifier is stored beside your chosen name and follows the same 90-day storage lifecycle.
- Account records and server logs: Tondo sessions expire after at most 30 days. Account deletion immediately ends account access and schedules removal of account records; it does not delete local projects or cancel store purchases. Encrypted Apple revocation data is kept until revocation succeeds. Order and payment records needed for purchase support, refunds and applicable record-keeping obligations are retained separately. Technical server logs are kept briefly for security and operation.
- Support email: for as long as needed to handle your request and a reasonable period after.
- Sent invoices: our sending service keeps no invoice content. The identifier and delivery status of a sent invoice, and the record of sending actions, are kept for 400 days; your business registration at the provider is kept while you use the subscription. The providers keep the invoice for as long as their role in the network and the law require.
Tondo sync uploads and revision history remain until account deletion. Disabling sync or deleting a project does not permanently erase them. Removed community content becomes eligible for scheduled permanent erasure after 90 days. Photos of posts deleted by their author are erased immediately. Moderation audit identifiers remain for 730 days (2 years). Account deletion in the app immediately revokes access and queues erasure of sync and community data. Local copies remain; the separate payment, audit and support retention rules above still apply. Reports and rights claims may remain after the reported content or account is deleted; you can ask us to erase them.
8 Your rights (GDPR)
You have the right to access, rectify, erase, restrict and object to processing of your personal data, and to data portability.
For your app content, you already hold these rights directly: you can use the app’s controls to view, edit or delete local content and, where available, export it. For relayed messages and photos, use the deletion controls while the relevant remote game is still stored on your device. To exercise your rights for reports, support correspondence or other data we process, write to privacy@oomny.eu to exercise any right.
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the authority in your own EU/EEA country.
10 Children
Rookaby is designed for children aged 2 to 6. It stores progress on the device and uses no advertising, accounts or analytics. Purchases and external links are protected by a parental gate. This website is intended for parents and other adults. We do not knowingly collect personal data from children under 16. If you believe a child has given us data, contact us and we will delete it.
Tondo has a store age rating of 13+. Community participation requires declaring that you are at least 16 and accepting the rules. Please report suspected underage community use to us.
11 Changes
If we change this policy we will update this page and the date at the top. Material changes will be made clear.